Information Security Engineer
Listed on 2026-01-11
-
IT/Tech
Cybersecurity, Information Security
Details
Open Date 11/17/2025
Requisition Number PRN
43601B
Job Title Information Security Engineers
Working Title Information Security Engineer
Career Progression Track P00
Track Level
FLSA Code Computer Employee
Patient Sensitive Job Code? No
Standard Hours per Week 40.00
Full Time or Part Time? Full Time
Shift Day
Work Schedule Summary
VP Area President
Department 00954 - UIT Systems & Security
Location Campus
City Salt Lake City, UT
Type of Recruitment External Posting
Pay Rate Range 88,000 to 131,300
Close Date 02/17/2026
Priority Review Date (Note - Posting may close at any time)
Job SummaryThe Information Security Engineer position in the Information Security Office ( ISO ) is
responsible for leading and supporting security initiatives which mitigate risk and ensure system and data integrity at the University of Utah and University Health Care. This includes providing security guidance and technical risk assessments of new or ongoing projects, responding to and analyzing security incidents, and implementing new security technologies or processes. This is a highly collaborative position which requires strong analytical and communication skills.
This position is hybrid, requiring the selected candidate to either reside in or be willing to move to the Salt Lake City area.
ResponsibilitiesAssist the University in meeting Information Security compliance obligations.
Contribute to incident response procedures, participate in incident response activities, and help develop strategies to prevent future occurrences.
Analyze indicators of compromise from endpoints, servers, and cloud environments to identify the root cause of breaches, malware infections, or other security issues.
Provide security evaluations and guidance regarding new technologies or processes.
Assist in legal discovery, evidence acquisition, and preservation.
Support the Security Operations Center ( SOC ) with tools, data, and guidance.
Stay up-to-date concerning emerging threats, vulnerabilities, and security solutions through research and industry sources.
This job description is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to the job.
Minimum QualificationsEQUIVALENCY STATEMENT : 1 year of higher education can be substituted for 1 year of directly related work experience (Example: bachelor’s degree = 4 years of directly related work experience).
Department may hire employee at one of the following job levels:
Information Security Engineer, I: Requires a bachelor’s (or equivalency) + 2 years of directly related work experience or a master’s (or equivalency) degree.
Information Security Engineer, II: Requires a bachelor’s (or equivalency) + 4 years or a master’s (or equivalency) + 2 years of directly related work experience.
Information Security Engineer, III : Requires a bachelor’s (or equivalency) + 6 years or a master’s (or equivalency) + 4 years of directly related work experience.
Information Security Engineer, IV: Requires a bachelor’s (or equivalency) + 8 years or a master’s (or equivalency) + 6 years of directly related work experience.
Information Security Engineer, V: Requires a bachelor’s (or equivalency) + 10 years or a master’s (or equivalency) + 8 years of directly related work experience.
Information Security Engineer, VI: Requires a bachelor’s (or equivalency) + 12 years or a master’s (or equivalency) + 10 years of directly related work experience.
Information Security Engineer, VII : Requires a bachelor’s (or equivalency) + 14 years or a master’s (or equivalency) + 12 years of directly related work experience.
PreferencesA thorough understanding of security industry standards (i.e. NIST 800-53, ISO / IEC 27001, CIS Controls, etc.)
Experience with compliance standards including HIPAA , FISMA , PCI , and FERPA
Experience with information security in a higher-education or healthcare setting.
One or more security-specific certifications ( CISSP , CISA , etc.)
One or more of the following:
a.) Experience with Data Security Posture Management, both on-premises and Cloud/SaaS
b.) Microsoft Purview Sensitivity Labels, Email, SharePoint, and One Drive…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).