Job Summary/Basic Function: |
This position implements Boise State University’s controlled data policy by developing, executing, and maintaining a controlled data governance program. This program monitors, responds to, and mitigates risks associated with controlled data, research information security, and cybersecurity. Additionally, the role supports programs and processes related to export control, undue foreign influence, conflicts of interest, and research security. This position is remote or hybrid-eligible.
|
Essential Functions: |
95% of the Time the Position must: ● Serve as a key member of the research security team, coordinating with the university’s CISO team to align with cybersecurity standards. ● Assess, document, and improve the university’s compliance, privacy, security, and risk posture for controlled data and research assets in relation to information technology. ● Promote the university’s controlled data program by fostering collaboration and ensuring regulatory compliance and best practices across campus organizations and individuals. ● Participate in developing regulatory compliance guidance and IT security architectures, contributing to technical discussions on design, monitoring tools, anomaly detection, threat mitigation, cloud configurations, and enclave use. ● Analyze, document, and suggest enhancements in IT process designs for research regulatory compliance, identifying proactive solutions and improvement opportunities in systems and processes. ● Create reports and documentation to support compliance requirements in the research environment, utilizing analytical tools to monitor a range of research storage resources. ● Support the development and implementation of training programs and communications to increase awareness and understanding of ethics, integrity, privacy, security, and compliance policies, procedures, and best practices. ● Implement and evaluate technology deployments, integration testing, and information security products, services, and procedures to enhance research productivity and effectiveness while upholding security, privacy, and compliance. ● Support security, privacy, and compliance throughout the controlled data lifecycle, from inception to disposal, ensuring controlled data access is managed in line with rigorous security, engineering, governance, and risk management principles. ● Work closely with researchers to help them understand university-provided systems, technology, and controls to protect research data. ● Provide consultations to researchers, developing solutions, documentation, timelines, and research data management workflows that meet regulatory and funding agency requirements. ● Guide researchers through the data use agreement compliance process and data governance practices, as required by regulatory, privacy, and security policies and protocols. ● Develop technology control plans for research and researchers to outline how data and assets are protected, handled, stored, and transferred. ● Offer guidance on best practices for controlled data collection, ensuring compliance and consistency in controlled data handling.
5% Perform other duties as assigned, primarily those necessary to support ethics, integrity, privacy, security, and compliance matters related to research activities.
|
Knowledge, Skills, Abilities: |
● Knowledge of generally accepted information/cyber security principles and practices with the ability to apply that knowledge to perform complex and non-routine specialized functions such as troubleshooting, advanced analysis, research, and problem-solving. ● Excellent analytical, judgment, and organization skills. ● Ability to communicate effectively, both in writing and orally. ● Ability to independently work and self-regulate multiple priorities/tasks. ● Demonstrated problem-solving skills, independent thinking, and a strong sense of curiosity. ● Ability to establish and maintain effective working relationships with researchers, information technology staff, compliance and security staff, and other stakeholders. ● Ability to accurately harmonize complex information and perform work with an attention to detail. ● Ability to work independently and in collaboration with others. ● Ability to proactively identify and work towards solutions in an agile manner while exhibiting high ethical standards.
|
Minimum Qualifications: |
● Bachelor’s Degree in Computer Science, Engineering, Data Science, Mathematics, or equivalent plus 5 years of experience. ● Experience overseeing or implementing compliance and security related to research using regulatory standards such as NIST 800-171, NIST 800-53, Cybersecurity Maturity Model Certification (CMMC), HIPAA/HITECH, DFARS, or the like.
|