We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Sr. User Security & Access Analyst - Hybrid - 140754

University of California - San Diego Medical Centers
United States, California, San Diego
Sep 16, 2026

Reassignment Applicants: Eligible Reassignment clients should contact their Disability Counselor for assistance.

This position has recently been accreted by UPTE TX and will be a part of that union moving forward.

This position will work a hybrid schedule which includes a combination of working both onsite at Towne Centre Drive (San Diego, CA) and remote.

DESCRIPTION

The User Security & Access Analyst IV is an advanced individual contributor and recognized subject matter expert responsible for leading highly complex and high-impact identity, access management, Epic security, and access governance initiatives. This position provides advanced technical direction, leads complex security analysis and process improvements, influences enterprise access standards, and serves as a trusted technical resource for leadership and cross-functional stakeholders.

Primary Responsibilities:

  • Lead analysis and resolution of highly complex, high-impact, or cross-functional access and security issues.
  • Serve as a technical lead for enterprise identity platforms, including SailPoint, Okta, Microsoft Entra ID (Azure AD), and Active Directory, ensuring system reliability, integration effectiveness, and alignment with standards.
  • Develop and enhance access management processes, role-based security models, provisioning workflows, and governance controls while providing advanced troubleshooting, risk assessment, and guidance on complex identity and access matters.
  • Evaluate complex or unprecedented access requirements and develop secure, sustainable solutions when existing processes do not adequately address the need.
  • Lead security analysis involving multiple applications, departments, workflows, or organizational areas.
  • Evaluate technical, operational, compliance, and security risks associated with access decisions.
  • Lead efforts to identify and remediate excessive, conflicting, outdated, or unnecessarily complex access structures.
  • Provide advanced guidance regarding Epic roles, security templates, provisioning models, and access standardization.
  • Lead or serve as the security subject matter expert for major projects and enterprise initiatives.
  • Develop and recommend improvements to security standards, procedures, governance, and access-management practices.
  • Lead strategic process-improvement and automation initiatives with broader organizational impact.
  • Partner with leadership, application owners, compliance, risk, HR, IT, and operational stakeholders on complex security matters.
  • Lead audit-readiness activities and assist in developing sustainable remediation strategies.
  • Expected to mentor and provide technical guidance to junior analysts on complex security and access matters.
  • Support leadership in the development, implementation, and continuous improvement of procedures, standards, documentation, and technical training programs.
  • Identify emerging security, operational, and access-management risks and recommend appropriate solutions.
  • Provide technical recommendations to management when matters require broader policy, organizational, or strategic decisions.
  • 7/24 On Call for User Security and Access Team rotation.

Decision Making & Independence

Operates with a high degree of independence and professional judgment. Develops recommendations and solutions for complex situations where precedent may not exist or established procedures may require enhancement. Provides expert technical recommendations while appropriately engaging the Supervisor or Manager for matters requiring management authority, policy decisions, organizational direction, or significant risk acceptance.

Technical Knowledge

Expert or highly advanced knowledge of:

  • Identity and Access Management (IAM)
  • Epic security architecture and provisioning
  • SailPoint, Okta, Microsoft Entra ID (Azure AD), and Epic Security
  • Role-Based Access Control and least privilege
  • Access governance and lifecycle management
  • Security risk assessment
  • Regulatory and compliance requirements
  • Audit controls and remediation
  • Enterprise provisioning strategies
  • Process automation and standardization
  • Security policy and governance frameworks

Technical Leadership

Provides technical leadership rather than people management. The role is expected to mentor junior analysts, lead technical work, coordinate complex initiatives, and serve as an escalation resource based on expertise. The position does not replace the Supervisor or Manager as the team's formal leadership or final organizational decision-making authority.

MINIMUM QUALIFICATIONS
  • Nine (9) years of related experience, education/training, OR a Bachelor's degree in related area plus five (5) years of related experience/training.

  • Advanced interpersonal skills sufficient to work effectively with both technical and non-technical personnel at various levels in the organization.

  • Advanced experience using IT security systems and tools.

  • Knowledge of department processes and procedures.

  • Demonstrated skills applying security controls to computer software and hardware.

  • Demonstrated skill at administering complex security controls and configurations to computer hardware, software and networks.

  • Advanced knowledge of data encryption technologies and experience selecting and applying appropriate data encryption technologies.

  • Advanced knowledge of IT security.

  • Broad knowledge of other areas of IT.

  • Demonstrated knowledge of secure hardware, software and network design techniques.

  • Demonstrated skill at analyzing and preventing security incidents of high complexity.

  • In-depth knowledge of computer hardware, software and network security issues and approaches.

  • Advanced experience in incident response and digital forensics including reporting.

PREFERRED QUALIFICATIONS
  • 7+ years of progressively responsible experience in Identity and Access Management (IAM), Epic Security, information security, or enterprise access management.

  • Advanced experience with Epic Security and enterprise identity platforms, such as SailPoint, Okta, Microsoft Entra ID, and Active Directory.

  • Advanced knowledge of RBAC, least privilege, identity lifecycle management, access governance, provisioning, and security risk assessment.

  • Demonstrated experience leading resolution of highly complex or high-impact access issues and developing secure, scalable solutions.

  • Experience leading access governance, role/template optimization, audit remediation, process improvement, or automation initiatives, preferably in a healthcare environment.

  • Demonstrated ability to serve as a technical SME, provide technical guidance and mentorship, and communicate recommendations to leadership and cross-functional stakeholders.

  • Epic Security, IAM, or related security certification/training.

SPECIAL CONDITIONS
  • 7/24 On Call for User Security and Access Team rotation.

  • Must be able to work various hours and locations based on business needs.

  • Employment is subject to a criminal background check and pre-employment physical.

Pay Transparency Act

Annual Full Pay Range: Unclassified - No data available (will be prorated if the appointment percentage is less than 100%)

Hourly Equivalent: Unclassified - No data available

Factors in determining the appropriate compensation for a role include experience, skills, knowledge, abilities, education, licensure and certifications, and other business and organizational needs. The Hiring Pay Scale referenced in the job posting is the budgeted salary or hourly range that the University reasonably expects to pay for this position. The Annual Full Pay Range may be broader than what the University anticipates to pay for this position, based on internal equity, budget, and collective bargaining agreements (when applicable).

Applied = 0

(web-665cd84569-9dvqq)