HRTMS Job Description Management
| Senior Unit Information Security Specialist IT SCRTY ANL 4 TX (006365) UCPath Position ID: 40064977 | | |
Position Description History/Status | Approved Date: | 9/2/2026 3:35:02 PM | Date Last Edited: | 9/2/2026 3:34:57 PM | Last Action Effective Date: | 10/1/2024 | Organization Details | Business Unit (Location): | LACMP | Organization Code: | 5000O | Organization: | ADMINISTRATIVE VICE CHANCELLOR | Division Code: | 5901D | Division: | ADMINISTRATION | Department: | 455400 - IT SERVICES | Position Details | UCPath Position Number: | 40064977 | Position Description ID | 230598 | UC Payroll Title: | IT SCRTY ANL 4 TX (006365) | Personnel Program | Management and Senior Professional (MSP) | Salary Grade: | STEPS | Job Code FLSA: | Exempt | Union Code (Collective Bargaining Unit): | 99: Non-Represented (PPSM) | Employee Relations Code: | E: All Others - Not Confidential | Employee Class (Appt Type): | 2 - Staff: Career | Full-Time Equivalent (FTE) | 1 | SUPERVISION | UCPath Reports to Position Number: | 41068509 | Reports to Payroll Title: | IT SCRTY MGR 2 | UCPath Department Head Position Number: | 40068309 | Department Head Payroll Title: | INFO SYS MGR 4 | | | |
Level of Supervision Received | GENERAL SUPERVISION - Indicates that the incumbent develops procedures for performance of variety of duties; or performs complex duties within established policy guidelines. |
POSITION SUMMARY | The UCLA Office of Information Security has established a program to collaborate with the campus community and organizations to implement information security best-practices, technologies, and initiatives that modernize and elevate our information security programs that protect our institution. The Senior Unit Information Security Specialist will collaborate with assigned organizations and the Assistant Chief Information Security Officer (ACISO) to analyze organizational information security needs, define programs, processes and practices that conform with campus security standards, and to provide guidance and support with the implementation of technologies and services that will protect institutional data. Additionally, the Senior Unit Information Security Specialist will ensure effective communication with assigned organizations regarding policies, initiatives and procedures are thoughtfully implemented within assigned organizations. The Senior Unit Information Security Specialist will coordinate with assigned customer groups and within the Digital & Technology Solutions (DTS) organization to deliver services and capabilities that align with security programs and policies. The Senior UISS will positively impact UCLA's operations and culture by protecting University stakeholders' information and data in service of the institution's academic mission. This team member will advance the University's mission by delivering exceptional security services comprehensively and consistently for faculty, staff, and students. This role will execute UCLA's vision while modeling UCLA's culture and values. | | | |
Department Summary | The UCLA Office of Information Security enables UCLA’s goals by providing leadership assuring the confidentiality, integrity, and availability of its information resources. The Information Security Office enables efficient incident response planning and notification procedures. In addition, the office aims to implement risk assessment strategies to identify vulnerabilities and threats to departmental information resources and enterprise systems. This includes executing a comprehensive UCLA IT security plan, which involves proposing, delivering, and enforcing administrative, technical, and physical security measures to tackle identified risks based on their sensitivity or criticality. |
Key Responsibilities and Essential Functions | Function | Responsibilities | % Time | IT Security | 1.Act as the central contact regarding Information Security and provide tactical oversight and execution of advanced and highly complex Information Security capabilities for unit(s). 2.Foster strong communication and collaboration between OCISO and unit(s), acting as the liaison to enable alignment with University policies and procedures. 3.Facilitate development, implementation, and maintenance of robust security strategies, policies, and best practices within unit(s), aligned with organizational standards. | 15% | IT Security | 1.Respond to stakeholder inquiries and concerns regarding Information Security, providing clear and concise information and guidance to ensure stakeholder satisfaction. 2.Acts as lead for assigned unit(s) with adherence to internal and external minimum Information Security requirements (e.g., track exceptions, draft security strategies for remediation). 3.Lead collection and reporting of Information Security metrics and measurements. | 15% | IT Security | 1.Facilitate coordination between OCISO and unit(s) to drive highly complex Information Security risk management and third-party risk management activities (e.g., self-assessments, third-party intake, security assessments, onboarding, periodic review, certifications). 2.Proactively identify, report, and mitigate potential security risks, threats, and vulnerabilities within the unit(s), leveraging team expertise and resources. 3.Collaborate with teams across OCISO and Information Technology Services (ITS) to design and execute advanced Information Security programs and services tailored to unit(s) needs. | 15% | IT Security | 1.Lead incident response and remediation efforts, working closely with other IT Security teams to address security breaches or incidents effectively. 2.Lead the assessment and communication of data classification levels for unit(s) information and IT assets. Guides unit(s) stakeholders in enforcing classification levels across assets and maintain asset inventory. 3.Facilitate user access lifecycle activities (e.g., provisioning/ deprovisioning, user access reviews) for unit(s) and collaborate with OCISO for to facilitate identity and access management controls. | 15% | Problem Solving | 1.Work closely with leadership to identify, implement, and support cost-effective, leading solutions for systemwide IT security. | 10% | Continuous Improvement | 1.Stays informed on industry trends, emerging threats, and best practices in information security, applying this knowledge to drive innovation and improvement across the university. 2.Provides advanced knowledge and expertise to guide and support units in the selection and implementation of cutting-edge security tools, technologies, and solutions to enhance overall university security. | 5% | Project Planning & Management | 1.Leads the planning and execution of IT security projects, including defining project scope, goals, timelines, and resource requirements, and ensuring projects are delivered on time, within budget, and with the desired outcomes and impact on the University’s overall security plans. | 5% | Communications & Training | 1.Provide timely security communications to unit stakeholders, technical staff, and management as required. Communicates and reports on unit(s) security incidents and training non-compliance to University and IT leaders. 2.Lead the deployment of educational materials and training to staff within unit(s) on security awareness, protocols, and adherence to established policies. 3.Mentor, train, and support University stakeholders, promoting a culture of security awareness and adherence to established protocols. | 15% | Other | Actively contributes to promoting equity, diversity, and inclusion across the organization and UCLA’s campus. Actively promotes the organization’s core values and consistently integrates innovation, employee fulfillment, teamwork, respect, excellence, integrity, service, and accountability into each aspect of their work. | 5% | | | | | |
Other Requirements - Applies to all Positions | • | Performs other duties as assigned. | • | Complies with all policies and standards. | • | Complies with the University of California, Los Angeles (UCLA) Principles of Community. | • | This position description is not intended to be a complete list of all responsibilities, duties or skills required for the job and is subject to review and change at any time, with or without notice, in accordance with the needs of the organization. | | | |
Educational Requirements | Education Level | Education Details | Required/ Preferred | And/Or | Bachelor's Degree | in one or more of the following fields: information technology, computer science, business administration, communications or equivalent combination of experience and training. | Required | | | | | | | | |
Experience Requirements | Experience | Experience Details | Required/ Preferred | And/Or | Five years | experience working in one or more of the following fields: cybersecurity, information technology, computer science, computer information systems, etc. | Required | | | Proven experience using IT systems and tools. | Required | | | Experience working in a project-based environment using leading project management practices including schedule management, status reporting, and communication of project risks and issues. | Required | | | Experience participating in activities to advance an inclusive environment that values equity, diversity, inclusion and belonging. | Required | | Seven or more years | experience working in one or more of the following fields: cybersecurity, information technology, computer science, computer information systems, etc. | Preferred | | | | | | | | |
Licenses, Certifications and Professional Affiliations | One or more of the following: CISSP, CISA, Security+, CEH, CISM, or equivalent certification | | Preferred | | | | | | | | |
Knowledge, Skills and Abilities | KSAs | Required/ Preferred | Strong understanding and working knowledge of Information Security fundamentals. | Required | Advanced knowledge of privacy and security regulations and best practices, including federal and state laws, policies, and standards relevant to higher education. Knowledge of data classification and ability to educate on data classification requirements. | Required | Advanced knowledge of the relationship between threat, vulnerability, and information value in the context of Information Security risk management. | Required | Ability to coordinate closely with other Information Security teams to effectively address security breaches or incidents. | Required | Understanding of user lifecycle access activities, as well as identity and access management controls. | Required | Strong written and verbal communication skills and is able to communicate complex technical ideas to a diverse community of colleagues and stakeholders. Can relay technical information to audiences of technical and non-technical stakeholders. | Required | Able to establish and advance positive working relationships and a strong rapport with a diverse community of colleagues including team members, stakeholders, and customers. | Required | Advanced organizational skills and is able to balance competing priorities and deliver concurrent projects to various stakeholder types. | Required | Advanced problem-solving skills; ability to uncover root of difficult problems and scope solutions based on knowledge of available resources and timelines as well as awareness of vision and strategy. Seeks information from multiple and diverse sources to inform solutions. | Required | Demonstrated ability to make decisions with integrity. | Required | Thinks creatively and introduces innovations such as the incorporation of new technologies or processes. Thrives in an ever-changing, fast-paced environment. | Required | | | |
SPECIAL REQUIREMENTS AND/OR CONDITIONS OF EMPLOYMENT |
Reporting and Background Check Requirements | Background Check: Continued employment is contingent upon the completion of a satisfactory background investigation. | Live Scan Background Check: A Live Scan background check must be completed prior to the start of employment. |
LOCATION AND PHYSICAL, ENVIRONMENTAL, MENTAL (PEM) REQUIREMENTS | Environment and Work Location Information | Environment Type: | Non-Clinical Setting | Location Setting: | Campus | Location: | UCLA Wilshire Center | | | |
Physical Requirements | The physical requirements described here are representative of those that must be met by an employee to successfully perform the essential functions of this position. | Physical Requirements | Never 0 Hours | Occasional Up to 3 Hours | Frequent 3 to 6 Hours | Continuous 6 to 8+ Hours | Is Essential | Standing/Walking | | | X | | | Sitting | | | X | | | Bending/Stooping | | X | | | | Squatting/Kneeling | | X | | | | Climbing | X | | | | | Lifting/Carrying/Push/Pull 0-25 lbs | | X | | | | Lifting/Carrying/Push/Pull 26-50 lbs | X | | | | | Lifting/Carrying/Push/Pull over 50 lbs | X | | | | | Physical requirements other | X | | | | | | | | | | | | | | | |
Environmental Requirements | The environmental requirements described here are representative of those that must be met by an employee to successfully perform the essential functions of this position. | Exposures | Never 0 Hours | Occasional Up to 3 Hours | Frequent 3 to 6 Hours | Continuous 6 to 8+ Hours | Is Essential | Chemicals, dust, gases, or fumes | X | | | | | Loud noise levels | X | | | | | Marked changes in humidity or temperature | X | | | | | Microwave/Radiation | X | | | | | Operating motor vehicles and/or equipment | X | | | | | Exposures other | X | | | | | | | | | | | | | | | |
Mental Requirements | The mental requirements described here are representative of those that must be met by an employee to successfully perform the essential functions of this position. | Exposures | Never 0 Hours | Occasional Up to 3 Hours | Frequent 3 to 6 Hours | Continuous 6 to 8+ Hours | Is Essential | Sustained attention and concentration | | | X | | X | Complex problem solving/reasoning | | | X | | X | Ability to organize & prioritize | | | X | | X | Communication skills | | | X | | X | Numerical skills | | X | | | X | Mental demands other | X | | | | | | | | | | | | | | | |
Blood/Fluid Exposure Risk | The exposure described here is what can be expected of an employee in performing the essential functions of this position. | X | Classification 3: Position in which exposure to blood, body fluids or tissues is not part of the position description. The normal routine task involves no exposure to blood, body fluids or tissues and the employee can decline to perform tasks which involve a perceived risk without retribution. | | | |
|