University of Wisconsin - Madison logo

University of Wisconsin - Madison

Cybersecurity Analyst

🇺🇸 Hybrid - Madison, Wisconsin 🕑 Full-Time 💰 $55K 💻 Cybersecurity 🗓️ September 26th, 2026
Cyber Security HIPAA Higher Ed

Edtech.com's Summary

University of Wisconsin - Madison is hiring a Cybersecurity Analyst to protect HIPAA-regulated patient data and the School of Medicine and Public Health's $1B+ research enterprise. The analyst pairs proactive risk assessment with primary leadership of incident response across research and clinical infrastructure.

  • Lead cybersecurity risk assessments to harden research and clinical infrastructure before threats arrive.
  • Spearhead incident response, coordinating with the medical school, campus, and third-party vendors.
  • Help identify, develop, and facilitate training opportunities for unit staff.
  • Provide basic procedural and technical guidance to unit staff on technology usage and management.
  • Assist with basic data analysis, reporting, and business intelligence systems, and with mapping business processes and recommending technology solutions.
  • Bring hands-on experience with security operations tools such as SIEM, EDR/XDR, and vulnerability scanners to monitor environments, triage alerts, and track remediation.
  • Know cybersecurity frameworks and regulations such as HIPAA/HITECH, NIST SP 800-53 / 800-171, ISO 27001, or CIS Controls, and document security processes and remediation validation.
  • Preferred: a bachelor's degree, 2+ years of cybersecurity experience, and a certification such as CompTIA CySA+, Security+, GIAC, or CISA.
  • Starting salary of $55,000 annually, negotiable by experience, plus generous vacation, holidays, sick leave, insurances, savings accounts, and retirement benefits.
  • Hybrid arrangement with some in-person work at a designated campus location and some remote work.

Cybersecurity Analyst Full Description

Job summary:

The Cybersecurity Analyst serves as a strategic collaborator, uniquely bridging the gap between proactive risk management and real-time emergency response. Unlike traditional siloed roles, this position is responsible for the integrated threat lifecycle: you will lead cybersecurity risk assessments to enforce secure environments, while simultaneously serving as the primary lead for incident response when threats emerge. This role is fundamental to protecting the integrity of our HIPAA-regulated patient data and ensuring that the School's $1B+ research enterprise remains resilient against an increasingly sophisticated global threat landscape.
This position may require some work to be performed in-person, onsite, at a designated campus work location. Some work may be performed remotely, at an offsite, non-campus work location.

Key job responsibilities:
  • Assists in the identification, development, and facilitation of unit staff training opportunities
  • Performs cybersecurity risk assessments to pre-emptively harden research and clinical infrastructure, while simultaneously spearheading incident response to ensure collaboration across SMPH, campus, and third-party vendors
  • Performs basic data analyses and reporting
  • Assists in mapping business processes using basic mapping methodologies
  • Assists in making recommendations for the selection of technology solutions to align with business strategies
  • Assists in the design, development, and implementation of data reporting and business intelligence systems
  • Provides basic procedural and technical guidance to unit staff regarding technology usage and management

Department:
School of Medicine and Public Health, Office of Information Technology, Cybersecurity.

Compensation:
The starting salary for the position is $55,000 annually, but is negotiable based on experience and qualifications.
Employees in this position can expect to receive benefits such as generous vacation, holidays, and sick leave; competitive insurances and savings accounts; retirement benefits.

Required qualifications:
  • Demonstrated experience conducting cybersecurity risk assessments to identify and document risks across business processes, cloud/IT systems, and research workflows.
  • Hands-on experience using security operations tools (e.g., SIEM, EDR/XDR, vulnerability scanners) to monitor enterprise environments, triage alerts, and track remediation.
  • Working knowledge of cybersecurity frameworks and regulations, including HIPAA/HITECH, NIST SP 800-53 / 800-171, ISO 27001, or CIS Controls.
  • Proven ability to document information security processes, procedures, and validation of remediation
  • Strong written and verbal communication skills, with the ability to translate complex security risks to non-technical business partners, clinical leads, and researchers.

Preferred qualifications:
  • 2 or more years of experience with cybersecurity
  • Detailed understanding of network design, security controls, and system administration with excellent analytical and problem-solving skills
  • Proven experience in cybersecurity governance, risk management, and compliance
  • Experience executing project management skills including design review, threat modeling, and risk profiling while working across a large, complex, distributed, organization
  • Experience writing or updating technical documentation, security procedures, and compliance reporting artifacts.
  • Active industry certification: CompTIA CySA+, Security+, GIAC (GSEC/GCIH), CISA, or equivalent certification.

Education:
Bachelor's degree preferred

University sponsorship is not available for this position, including transfers of sponsorship and TN visas.

Employment may require a criminal background check.
The University of Wisconsin-Madison is an Equal Opportunity Employer.