Information Security Administrator
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
Key Skills for This Role
Full Job Posting
About the Department
Delaware County Community College (DCCC), located outside of the Philadelphia Metro area, is looking for a dynamic and dedicated Information Security Administrator to join our team of higher education technology professionals who are committed to student success. Candidates who subscribe to the notion of becoming a student-ready college and meeting students where they are, DCCC has a place for you! The Information Security Administrator is responsible for the day-to-day operation of the College's information security program. This is a hands-on operational role responsible for security monitoring and incident response, vulnerability management, SIEM detection engineering, security platform administration, and security reporting. Reporting to the IT Project & Technical Service Delivery Manager, the Information Security Administrator works alongside systems, network, applications, and support engineers and serves asa primary technical point of contact for the College's vCISO, managed detection services, penetration testers, auditors, cyber insurance carrier, and incident-response partners. Protecting College information and systems in accordance with FERPA, GLBA and the FTC Safeguards Rule, PCIDSS, applicable law, and College policy is a core responsibility. The position holds privileged access across College systems and requires discretion, disciplined use of access, clear documentation, and participationinchangemanagement.Thepositionrecommendsandimplementssecuritycontrolsandremediation;institutional risk acceptance and security policy approval remain with the Vice President, Information Technology.
Delaware County Community College (DCCC), located outside of the Philadelphia Metro area, is looking for a dynamic and dedicated Information Security Administrator to join our team of higher education technology professionals who are committed to student success. Candidates who subscribe to the notion of becoming a student-ready college and meeting students where they are, DCCC has a place for you!
The Information Security Administrator is responsible for the day-to-day operation of the College's information security program. This is a hands-on operational role responsible for security monitoring and incident response, vulnerability management, SIEM detection engineering, security platform administration, and security reporting. Reporting to the IT Project & Technical Service Delivery Manager, the Information Security Administrator works alongside systems, network, applications, and support engineers and serves asa primary technical point of contact for the College's vCISO, managed detection services, penetration testers, auditors, cyber insurance carrier, and incident-response partners. Protecting College information and systems in accordance with FERPA, GLBA and the FTC Safeguards Rule, PCIDSS, applicable law, and College policy is a core responsibility.
The position holds privileged access across College systems and requires discretion, disciplined use of access, clear documentation, and participationinchangemanagement.Thepositionrecommendsandimplementssecuritycontrolsandremediation;institutional risk acceptance and security policy approval remain with the Vice President, Information Technology.
Position Duties
- Monitor security telemetry and serve as a first responder for detections and reported events; triage alerts, investigate threats, coordinate containment and recovery, and escalate incidents in accordance with the College's Incident Response Plan. Perform recurring security operations across endpoint, identity, data, email, and network telemetry; integrate and maintain threat-intelligence feeds using MISP, STIX/TAXII, External Dynamic Lists (EDLs), APIs, and other supported methods; and translate relevant MS-ISAC, REN-ISAC, CISA, vendor, and other threat intelligence into automated or analyst-driven detection, blocking, investigation, and remediation activity. Run the vulnerability management lifecycle, including internal, external, and authenticated scanning; validation and risk-based prioritization; direct remediation where within the position’s area of responsibility; coordination and assignment of remediation to the responsible system owner or vendor; hands-on technical assistance with remediation when needed; tracking to closure; and verification through rescan. Develop and maintain SIEM and detection capabilities, including correlation rules, searches, dashboards, alerting workflows, log-source integrations, parsing, field extraction, and ingestion-health monitoring. Administer and support security platforms and controls across end point detection and response, data security and governance, identity and MFA, email security, next-generation firewalls, DNS/web filtering, and vulnerability scanning. Support identity and privileged-access security, including access reviews, privileged-account controls, Conditional Access and MFA policy, onboarding and offboarding verification, device trust, and least-privilege enforcement. Develop custom detections, scripts, API integrations, and automation using Power Shell, Python, Bash, and other appropriate tools. Apply approved artificial intelligence tools to security analysis, investigation, detection development, scripting, automation, research, triage, and documentation; evaluate AI-assisted security capabilities where appropriate and validate outputs before operational use in accordance with College AI and data-handling requirements. Serve as technical point of contact for the vCISO, penetration testers, managed detection and incident-response providers, auditors, cyber insurance partners, and other external security engagements, coordinate evidence and scope and track findings through remediation. Manage third-party security risk by operating the vendor-risk monitoring platform, reviewing HECVATs and security questionnaires, evaluating exposure findings, and tracking vendor remediation during procurement and renewal. Administer the security-awareness and phishing-simulation program, design campaigns ,manage remedial assignments and completion reporting, and develop and deliver security training and communications. Support investigations and maintain incident documentation, evidence and chain of custody, legal holds, after-action reviews, runbooks, metrics, and reporting for OIT leadership, auditors, and the Board. Produce technical findings without drawing conduct or disciplinary conclusions. Validate backup coverage, immutability, and recoverability through scheduled test restores; maintain recovery documentation and runbooks; participate in disaster-recovery and business-continuity testing; and work directly with OIT teams on hardening, patching, remediation, and cross-functional security troubleshooting. Participate in scheduled after-hours systems maintenance approximately two times per month,the24/7 on-call rotation, night, and weekend incident response as required. Perform other duties as assigned. The successful candidate must be an engaging, effective, innovative, dynamic individual who is strategic and thrives in a team environment. This individual will be able to demonstrate the use of best practice strategies associated IT Security as well as Cybersecurity. The successful individual will demonstrate the spirit of an independent problem-solver and collaborative team member with a strong understanding of the College’s mission and goals for our technical support processes.
- Monitor security telemetry and serve as a first responder for detections and reported events; triage alerts, investigate threats, coordinate containment and recovery, and escalate incidents in accordance with the College's Incident Response Plan.
- Perform recurring security operations across endpoint, identity, data, email, and network telemetry; integrate and maintain threat-intelligence feeds using MISP, STIX/TAXII, External Dynamic Lists (EDLs), APIs, and other supported methods; and translate relevant MS-ISAC, REN-ISAC, CISA, vendor, and other threat intelligence into automated or analyst-driven detection, blocking, investigation, and remediation activity.
- Run the vulnerability management lifecycle, including internal, external, and authenticated scanning; validation and risk-based prioritization; direct remediation where within the position’s area of responsibility; coordination and assignment of remediation to the responsible system owner or vendor; hands-on technical assistance with remediation when needed; tracking to closure; and verification through rescan.
- Develop and maintain SIEM and detection capabilities, including correlation rules, searches, dashboards, alerting workflows, log-source integrations, parsing, field extraction, and ingestion-health monitoring.
- Administer and support security platforms and controls across end point detection and response, data security and governance, identity and MFA, email security, next-generation firewalls, DNS/web filtering, and vulnerability scanning.
- Support identity and privileged-access security, including access reviews, privileged-account controls, Conditional Access and MFA policy, onboarding and offboarding verification, device trust, and least-privilege enforcement.
- Develop custom detections, scripts, API integrations, and automation using Power Shell, Python, Bash, and other appropriate tools. Apply approved artificial intelligence tools to security analysis, investigation, detection development, scripting, automation, research, triage, and documentation; evaluate AI-assisted security capabilities where appropriate and validate outputs before operational use in accordance with College AI and data-handling requirements.
- Serve as technical point of contact for the vCISO, penetration testers, managed detection and incident-response providers, auditors, cyber insurance partners, and other external security engagements, coordinate evidence and scope and track findings through remediation.
- Manage third-party security risk by operating the vendor-risk monitoring platform, reviewing HECVATs and security questionnaires, evaluating exposure findings, and tracking vendor remediation during procurement and renewal.
- Administer the security-awareness and phishing-simulation program, design campaigns ,manage remedial assignments and completion reporting, and develop and deliver security training and communications.
- Support investigations and maintain incident documentation, evidence and chain of custody, legal holds, after-action reviews, runbooks, metrics, and reporting for OIT leadership, auditors, and the Board. Produce technical findings without drawing conduct or disciplinary conclusions.
- Validate backup coverage, immutability, and recoverability through scheduled test restores; maintain recovery documentation and runbooks; participate in disaster-recovery and business-continuity testing; and work directly with OIT teams on hardening, patching, remediation, and cross-functional security troubleshooting.
- Participate in scheduled after-hours systems maintenance approximately two times per month,the24/7 on-call rotation, night, and weekend incident response as required.
- Perform other duties as assigned.
- The successful candidate must be an engaging, effective, innovative, dynamic individual who is strategic and thrives in a team environment. This individual will be able to demonstrate the use of best practice strategies associated IT Security as well as Cybersecurity. The successful individual will demonstrate the spirit of an independent problem-solver and collaborative team member with a strong understanding of the College’s mission and goals for our technical support processes.
Minimum Qualifications
- Qualified candidates will have three-plus (3+) years of related information security or IT infrastructure experience, including hands-on incident response and vulnerability management. Experience operating SIEM/EDR, identity and MFA, email security, data security, security-awareness, and vulnerability-management technologies is required. Scripting or automation experience is required; experience working with external security partners or in higher education is preferred. An Associate degree from an accredited college or university in Information Technology, Computer Science, or other related field of study or equivalent combination of education and experience. Relevant certifications such as CompTIA CySA+ or an approved equivalent must be obtained within 12 months of employment. The College will provide appropriate professional-development support and fund approved certification and renewal costs. Preferred Qualifications : Experience with technologies such as Crowd Strike Falcon and Next-Gen SIEM, Cisco Duo, Microsoft EntraI D, Varonis, Abnormal Security, KnowBe4, Up Guard, and Veeam; CompTIA Security+,CySA+,Security X or Sec AI+,GIAC credentials, CISSP ,CISM, CCSP, or other relevant cyber security certifications; Higher education or public-sector information security experience.
Other Qualifications
- Background Clearances: Act 153 Clearances (Act 34 PA Criminal Background History, Act 151 PA Child Abuse History, Act 114 FBI Clearance); Verification of educational credentials Delaware County Community College strongly encourages applications from members of traditionally under-represented groups. DCCC promotes an organizational culture and structure that honors diversity through integration of the principles of access, inclusion and most importantly equality. For immediate consideration, interested candidates can apply online at https://www.schooljobs.com/careers/dccc DCCC offers a great competitive salary, with an outstanding benefits package which includes: Medical, Dental, Vision, and Prescription Drug for all benefit eligible employees; College Paid Disability and Life Insurance; Flexible Spending Accounts; 403(b) Defined Contribution Retirement Plans (5% Employee Mandatory Contribution and a 10% Match by the College); Generous PTO, Holiday and Winter Break Schedule; Tuition Waiver & Tuition Reimbursement; and a Compressed Four (4) Day Work Week Each Summer; Professional Development Opportunities; and a Supportive Work/Life Balance Campus Environment. DCCC fosters a work environment and a learning community focused on student success by delivering quality, affordable, and responsive educational opportunities in a technologically rich and supportive environment. We celebrate differences and commit to an “open door” policy for individuals with varying levels of knowledge, skills, experiences, and needs. By embracing diverse collegial perspectives, we seek to make inclusivity, teamwork, and respect the foundation for our students to reach their academic goals and on staff to thrive professionally. DCCC is an equal employment opportunity employer, valuing diversity, equity, and inclusion .
Benefits
- Delaware County Community College provides a generous benefits package including medical, dental, vision, life and LTD insurances, and a 403(b).
Supplemental Questions
Yes
No
Required Question
About Delaware County Community College
Public two-year community college serving Delaware and Chester County residents with affordable academic and workforce programs.
Visit company websiteJobs and hiring trendsApply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at Delaware County Community College
Executive Director, Enterprise Applications & Digital Transformation
, USA
Administrative Assistant - SEC
Media, USA
Temporary Scribe (Accessibility Support Assistant)
, USA
Adjunct Theatre Studies (Stagecraft) Instructors
, USA
Assistant Director, Admissions (Chester County)
Downingtown, USA
Assessment Administrative Assistant
, USA
Men's Basketball Assistant Coach
, USA
Temporary Athletics Support Assistant
, USA