We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

IT Security Risk and Compliance Analyst - Hybrid - 139800

UC San Diego
Unclassified - No data available
United States, California, San Diego
May 28, 2026

UCSD Layoff from Career Appointment: Apply by 05/26/26 for consideration with preference for rehire. All layoff applicants should contact their Employment Advisor.

Reassignment Applicants: Eligible Reassignment clients should contact their Disability Counselor for assistance.

This position has recently been accreted by UPTE TX union and will be a part of that union moving forward.

This position will work a hybrid schedule which includes a combination of working both onsite at Towne Centre Drive (San Diego, CA) and remote.

DESCRIPTION

The IT Security Risk and Compliance Analyst executes processes across the organization to conduct the required IT security risk assessment and compliance program to reduce information security risk, address threats and vulnerabilities to information assets, monitor compliance to policy, and improve the overall security posture of the University.

The role performs security risk assessments and internal security audits/reviews, supports external audits and accreditation activities, and operates the governance components of the vulnerability management program. This includes vulnerability analysis, risk based prioritization, remediation tracking, validation of remediation effectiveness, and documentation of risk acceptance where remediation is deferred. The position provides recommendations for security controls and ensures follow through through established governance processes to meet campus policy and regulatory requirements such as HIPAA, PCI, FERPA, and related standards.

The incumbent maintains clear, audit ready decision records and evidence artifacts that support internal and external audits, regulatory oversight, and legally mandated information requests. This includes documentation of risk assessments, vulnerability decisions, compensating controls, governance approvals, secure handling of sensitive data, access constraints, and defensible evidence production for legal hold and eDiscovery matters. These activities are required elements of HIPAA compliance and are used to prioritize remediation based on risk, including patient safety and operational resiliency impacts where applicable. Thorough, documented risk assessments and compliance programs are foundational components of the Information Security Program and drive security improvement activities across the organization.

MINIMUM QUALIFICATIONS
  • Seven (7) years of related experience, education/training, OR a Bachelor's degree in related area plus three (3) years of related experience/training. Related experience: experience performing security risk assessments and/or internal security reviews to ensure that security controls meet policy and/or regulatory requirements, including evaluating control design and effectiveness. This may include experience in areas such as IT security risk and compliance (GRC), IT audit, vendor/third-party risk assessments, security consulting or assessment roles, or technical security roles with responsibility for evaluating control effectiveness and producing audit-ready documentation.

  • Ability to follow department processes and procedures.

  • Interpersonal skills sufficient to work effectively with both technical and non-technical personnel at various levels in the organization.

  • Experience using IT security systems and tools.

  • Knowledge of data encryption techniques.

  • Knowledge of other areas of IT, department processes and procedures.

  • Demonstrated skills applying security controls to computer software and hardware.

  • Experience in incident response and digital forensics including data collection, examination and analysis.

  • Demonstrated skill at administering complex security controls and configurations to computer hardware, software and networks.

  • Knowledge of computer hardware, software and network security issues and approaches.

  • Demonstrated experience selecting and applying appropriate data encryption technologies.

PREFERRED QUALIFICATIONS
  • Exposure to vulnerability management programs, including risk based prioritization, remediation tracking, validation of remediation effectiveness, and documentation of risk acceptance.

  • Ability to apply security risk assessment practices to third party/vendor reviews, including evaluation of evidence, identification of risks, and documentation of findings and conditions.

  • Familiarity with legal hold and eDiscovery workflows, including secure handling of sensitive exports and defensible evidence production.

  • Familiarity with external security audits/accreditations and internal security audit/review processes.

  • Comfort operating in regulated environments (healthcare and/or research) and with applicable compliance drivers (e.g., HIPAA, PCI, FERPA, campus policy requirements).

  • Skilled in documenting risk exceptions/acceptances, compensating controls, and governance routing/approvals.

  • Strong cross functional advisory skills with technical and non technical stakeholders.

SPECIAL CONDITIONS
  • Must be able to work various hours and locations based on business needs.

  • Employment is subject to a criminal background check and pre-employment physical.

Pay Transparency Act

Annual Full Pay Range: Unclassified - No data available (will be prorated if the appointment percentage is less than 100%)

Hourly Equivalent: Unclassified - No data available

Factors in determining the appropriate compensation for a role include experience, skills, knowledge, abilities, education, licensure and certifications, and other business and organizational needs. The Hiring Pay Scale referenced in the job posting is the budgeted salary or hourly range that the University reasonably expects to pay for this position. The Annual Full Pay Range may be broader than what the University anticipates to pay for this position, based on internal equity, budget, and collective bargaining agreements (when applicable).

Applied = 0

(web-77cf7d65c7-z52c2)