|
Position Summary
San Diego State University is seeking a Research Cybersecurity Analyst to help faculty and research teams and campus partners securely conduct research involving sensitive, regulated, and contractually restricted information. Working within SDSU’s Information Technology Security Office, the Research Cybersecurity Analyst will translate cybersecurity, contractual, regulatory, and sponsor requirements, including NIST SP 800-171, CMMC, NIST SP 800-53, and the HIPAA Security Rule and related requirements, into practical technical, administrative, and procedural safeguards. You’ll assess research environments, help implement security requirements, maintain compliance documentation, coordinate remediation, and help prepare research projects for sponsor inquiries, audits, and formal assessments. The position will work collaboratively with researchers, research administration, research computing, central IT, privacy, legal, export control, compliance, and other campus partners to help research teams meet security obligations while maintaining an effective and usable research environment.
What You’ll Do:
Research Security & Consultation
- Review research proposals, solicitations, contracts, subcontracts, awards, and data-use agreements to identify cybersecurity, privacy, data-handling, and reporting requirements.
- Conduct risk, gap, and control readiness assessments and recommend practical security approaches, remediation strategies, and risk-treatment options.
- Work with researchers, research administration, IT teams, research computing, and privacy, legal, export control, and compliance partners to interpret and implement applicable requirements.
- Interpret contractual and sponsor cybersecurity requirements, including flow-down clauses, reporting obligations, data-handling restrictions, security milestones, and assessment expectations.
- Map contract and regulatory requirements to applicable controls, responsible parties, evidence, and remediation plans.
- Assess research data, systems, and workflows for indicators of CUI, FCI, PHI, PII, export-controlled information, or other restricted data.
- Establish and document the scope and boundaries of research environments, including users, cloud services, third-party providers, endpoints, networks, and research equipment.
- Explain cybersecurity requirements in practical terms to researchers and research-support personnel who may not have a cybersecurity background.
Security Controls & Research Environments
- Coordinate, support, and validate security controls across cloud and on-premises research environments.
- Assess security architectures and configurations involving identity and access management, network segmentation, encryption, endpoint protection, logging, vulnerability management, and secure configuration.
- Evaluate security gaps and coordinate appropriate remediation.
- Support the design, review, and maintenance of secure research environments and research enclaves.
Compliance & Readiness
- Develop and maintain SSPs, POA&Ms, inventories, procedures, diagrams, and compliance evidence.
- Help prepare research environments for sponsor inquiries, audits, and assessments, including CMMC readiness.
- Support vulnerability monitoring, remediation, and research-focused incident readiness.
- Maintain documentation and processes needed to demonstrate continued compliance and operational effectiveness after an initial assessment or authorization.
What We’re Looking For:
We are looking for a cybersecurity professional who can evaluate security requirements, understand how they apply to research environments, identify practical safeguards, and work collaboratively with technical and nontechnical stakeholders to implement and document those safeguards.
The successful candidate may have developed this experience through cybersecurity operations, governance, risk, and compliance work, IT auditing, cloud security, systems administration, research computing, compliance consulting, or a related area.
Experience in the following areas is especially valuable:
- NIST SP 800-171, CMMC, NIST SP 800-53, or similar security frameworks
- Security controls, assessments, and compliance documentation
- SSPs, POA&Ms, or audit/assessment readiness
- Windows, Linux, cloud, or enterprise environments
- Identity and access management, encryption, vulnerability management, or network security
- Communicating technical or compliance requirements to different audiences
Experience working in a higher-education, research, healthcare, government, defense, or other highly regulated environment is a plus.
Why Join Us?
- Support research securely – Help researchers meet cybersecurity requirements while moving their work forward.
- Work across cybersecurity and compliance – Gain exposure to technical controls, risk assessments, documentation, and assessment readiness.
- Collaborate across SDSU – Work with researchers, IT professionals, and compliance partners on a variety of research security needs.
- Solve different security challenges – Support research projects with varying technologies, data, sponsors, and security requirements.
As part of the California State University (CSU) system, San Diego State University helps power one of the largest and most impactful public university systems in the nation. See what it’s like to work at the CSU—watch our video and imagine your future here: Working at the CSU.
|
|
Key Qualifications
- Experience implementing or assessing NIST SP 800-171, CMMC, NIST SP 800-53, or comparable security frameworks, including developing or maintaining SSPs, POA&Ms, control evidence, and assessment documentation.
- Experience securing Windows, Linux, cloud, or research computing environments, including controls such as identity and access management, encryption, network segmentation, secure configuration, logging, and vulnerability management.
- Ability to conduct security risk, gap, and control assessments, identify appropriate remediation or risk-treatment options, and support audit or assessment readiness.
- Ability to translate sponsor, contractual, regulatory, and security requirements into practical technical and procedural controls and communicate them effectively to researchers, technology teams, and leadership.
- Working knowledge of research-security requirements and the ability to learn and apply requirements related to CUI/FCI, privacy, federal research awards, HIPAA-regulated information, export controls, and controlled-access research data.
- Experience assessing cloud, vendor, and third-party security, including shared-responsibility models and contractual security requirements.
- Strong communication, collaboration, and project management skills, with the ability to manage multiple security initiatives and work effectively across technical, research, administrative, and compliance teams.
- Ability to appropriately handle confidential, regulated, and sensitive information and adapt to evolving technologies and security requirements.
- Preferred Qualifications
- Advanced degree in cybersecurity, information security, computer science, information systems, engineering, or a related field and/or additional progressively responsible cybersecurity experience.
- Experience supporting higher education or research environments, including secure research environments, CUI/FCI, CMMC readiness, HIPAA-regulated research, or cloud platforms such as Azure, AWS, or Google Cloud.
- Relevant cybersecurity, cloud, audit, or compliance certification, completed or in progress, such as CISSP, CISM, CCSP, Security+, CySA+, GIAC, CMMC, or another comparable certification.
|
|
SDSU Values
At SDSU, our diversity gives us power and benefits every single member of our community. Consistent with California law and federal civil rights laws, SDSU provides equal opportunity for all in education and employment. We encourage all members of our community to purposefully learn from one another through open and respectful dialogue and responsible engagement. We strongly preserve the right to free expression and encourage difficult conversations that help lead to improved individual and community learning and cohesion.
Principles of Community
At San Diego State University, we are a community of diverse individuals who have and represent many perspectives, beliefs, and identities. This diversity lends our community strength, and we commit to creating and sustaining an inclusive and intellectually vibrant environment that benefits all members of our university.
SDSU’s Principles of Community is an aspirational statement that is intended to evolve over time. The statement reflects the ideals we are encouraged to uphold in our interactions with one another.
Equal Opportunity and Excellence in Education and Employment
All university programs and activities are open and available to all regardless of race, sex, color, ethnicity or national origin. Consistent with California law and federal civil rights laws, San Diego State University (SDSU) provides equal opportunity in education and employment without unlawful discrimination or preferential treatment based on race, sex, color, ethnicity, or national origin. Our commitment to equal opportunity means ensuring that every student and employee has access to the resources and support they need to thrive and succeed in a university environment and in their communities. SDSU complies with Title VI of the Civil Rights Act of 1964, Title IX of the Education Amendments of 1972, the Americans with Disabilities Act (ADA), Section 504 of the Rehabilitation Act, the California Equity in Higher Education Act, California’s Proposition 209 (Art. I, Section 31 of the California Constitution), other applicable state and federal anti-discrimination laws, and CSU’s Nondiscrimination Policy. We prohibit discriminatory preferential treatment, segregation based on race or any other protected status, and all forms of discrimination, harassment, and retaliation in all university programs, policies, and practices.
SDSU is a diverse community of individuals who represent many perspectives, beliefs and identities, committed to fostering an inclusive, respectful, and intellectually vibrant environment. We cultivate a culture of open dialogue, mutual respect, and belonging to support educational excellence and student success. Through academic programs, student organizations and activities, faculty initiatives, and community partnerships, we encourage meaningful engagement with diverse perspectives. As a higher education institution, we are dedicated to advancing knowledge and empowering individuals to reach their full potential by prioritizing inclusive curriculum development, faculty and staff training, student mentorship, and comprehensive support programs. At SDSU, excellence is built on merit, talent, diversity, accessibility, and equal opportunity for all.
|