Information Security Assessment and Analysis Team Lead

University of Connecticut

$95K — $123K *
Education, Government & Non-Profit
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in related field or equivalent experience; advanced degree preferred
  • 6+ years of experience in information security or IT; 4+ years in security assessment
  • 1+ year of leading or supervising a cybersecurity team
  • Expertise in enterprise security assessments and cybersecurity risk
  • Experience with security policies, standards, and compliance frameworks
  • Demonstrated skills in project management, communication, and team development

Responsibilities

  • Lead the University's Information Security Assessment and Analysis programs
  • Direct day-to-day operations of the assessment team, including workload management
  • Develop strategic roadmaps for security and compliance initiatives
  • Serve as technical authority for assessment methodologies and risk analysis
  • Participate in senior leadership to establish strategic direction
  • Oversee team development and adapt to emerging security disciplines

Benefits

  • Defined contribution retirement options with employer match
  • Affordable healthcare options
  • 35-hour work week promoting work-life balance
  • 22 paid vacation days and 13 paid holidays per year
  • Employee and dependent tuition waiver programs
  • Supportive and desirable work environment
Full Job Description
Information Security Assessment and Analysis Team Lead

Search #: 499811
Work type: Full-time
Location: UConn Storrs
Categories: Information Technology

JOB SUMMARY

Under the general direction of the Chief Information Security Officer, the Information Security Assessment and Analysis Team Lead is responsible for leading the University's Security Assessment and Security Analysis programs in support of the University of Connecticut Information Security Office.

The Information Security Assessment and Analysis Team Lead works regularly with other senior members of the Information Security Office and serves as a member of the CISO's senior leadership team.

This position serves in a dual capacity as both a technical subject matter expert and the supervisor of a functional team. The incumbent provides strategic and operational leadership for the University's security assessment; vulnerability management; cyber security program reviews; governance, risk, and compliance; vendor risk management; and data security programs while actively participating in complex security assessments, technical reviews, and enterprise risk analysis. This position currently has three direct FTE reports, with team growth envisioned, as well as oversight of student workers.

The Security Assessment and Analysis Team Lead manages a multidisciplinary team of cybersecurity professionals responsible for Vulnerability Management; Security Policy, Risk, and Compliance; Application and Systems Security; Data Security; Third-Party Risk Management; and Security Assessments. The function and nature of the team is expected to evolve and keep pace with the changing technology and threat landscape. The team is designed to grow over time to include Cloud Security and Artificial Intelligence Security functions.

The Team Lead establishes strategic direction, operational priorities, standards, assessment methodologies, and technical guidance that improve the University's overall security posture across academic, research, and administrative environments.

The Team Lead collaborates closely with University leadership, Information Technology Services, Enterprise Applications, Research IT, Enterprise Infrastructure, Counsel, Compliance, Privacy, Internal Audit, Procurement, Research Compliance, and other stakeholders to integrate cybersecurity risk management throughout the institution.

The Security Assessment and Analysis Team Lead is responsible for continuously improving the University's cybersecurity maturity through comprehensive security assessments, governance, risk management, vulnerability management, technical standards development, and staff development.

SALARY

  • Information Security Assessment and Analysis Team Lead (Information Technology Team Lead 2 - UCP 7): $95,066 to $123,585

Note: All minimum qualifications must be met to be eligible for consideration. Salary will be commensurate with experience within the established range.

BENEFITS INCLUDE

  • Defined contribution with employer match or defined benefit program retirement options
  • Excellent and affordable healthcare options
  • 35 hour work week
  • 22 paid vacation days per year
  • Paid sick leave
  • 13 paid holidays
  • Employee and dependent tuition waiver programs
  • A highly desirable work environment and work-life balance

DUTIES AND RESPONSIBILITIES

Leadership and Program Management

  • Lead the University's Information Security Assessment and Security Analysis programs under the oversight of the Chief Information Security Officer.
  • Direct day-to-day operations of the Information Security Assessment and Analysis Team, including prioritization of work, workload management, coaching, mentoring, performance management, and career development.
  • Develop strategic roadmaps for security assessment, governance, risk management, vulnerability management, application security, data security, and third-party risk.
  • Serve as the University's senior technical authority for security assessment methodologies and cybersecurity risk analysis.
  • Participate as a member of the CISO's senior leadership team in establishing strategic direction for the Information Security Office.
  • Develop staffing plans and future organizational capabilities, including expansion into emerging disciplines such as AI Security and Cloud Security.

Information Security Assessment

  • Lead enterprise security assessments of infrastructure, applications, cloud services, research environments, and business processes.
  • Develop and maintain assessment methodologies, technical standards, security baselines, and review procedures.
  • Conduct or oversee security reviews for enterprise technology initiatives.
  • Review security implications of new technologies, enterprise platforms, and major IT projects.

Vulnerability Management

  • Oversee staff operating, and individually participate in, the University's enterprise vulnerability management program.
  • Establish vulnerability assessment methodologies, remediation priorities, and enterprise reporting.
  • Develop metrics and dashboards measuring organizational vulnerability reduction and remediation effectiveness.
  • Oversee the coordination of remediation activities with infrastructure, application, research, cloud, and distributed IT teams.

Policy, Risk and Compliance

  • Oversee staff developing, and individually participate in development of, cybersecurity governance, policy development, risk management, and compliance activities.
  • Oversee the development and maintenance of University information security policies, standards, procedures, and guidelines.
  • Oversee staff operating the exception management processes. Apply standardized risk tolerance and acceptance criterial to exception requests, evaluate and recommend exception criteria for novel or unique justifiable business use cases.
  • Coordinate security compliance efforts supporting FERPA, HIPAA, PCI DSS, CMMC, NIST 800-171, CJIS, GLBA, research security requirements, and other applicable regulations.
  • Support audits, assessments, and regulatory reviews.

Application and Systems Security

  • Oversee staff conducting, and individually participate in, application security assessments, secure code development initiatives, penetration testing coordination, and secure SDLC guidance.
  • Collaborate with development teams to integrate security through-out software development lifecycles.

Data Security

  • Oversee data security initiatives including data classification, protection, encryption, data loss prevention, and secure handling of sensitive institutional information.
  • Develop security strategies to protect regulated information, research data, and institutional intellectual property.

Third Party Risk Management

  • Oversee staff conducting, and individually participate in, security assessments of vendors, cloud providers, research collaborators, and third-party service providers.
  • Develop third-party security assessment standards and risk evaluation methodologies.
  • Coordinate procurement security reviews and vendor remediation activities.

Strategic Leadership

  • Develop enterprise cybersecurity metrics, dashboards, executive reports, and key performance indicators.
  • Evaluate emerging technologies, security tools, and vendor solutions.
  • Develop long-term improvement plans aligned with University strategic objectives.
  • Maintain awareness of evolving threats, vulnerabilities, technologies, regulations, and industry best practices.
  • Represent the Information Security Office on institutional committees and strategic initiatives.
  • Participate in after-hours incident response and operational escalations as required.
  • Other related duties as assigned.

RELATED SKILLS AND COMPETENCIES

  • Leadership - Demonstrates the ability to lead, motivate, coach, and develop highly skilled technical professionals. Creates a collaborative, service-oriented culture focused on operational excellence and continuous improvement.
  • Security Assessment Expertise - Demonstrates expert knowledge of: Security architecture; Risk assessment; Vulnerability management; Application security; Cloud security; Data security; Governance, Risk, and Compliance (GRC); Third-party risk management; Enterprise cybersecurity frameworks.
  • Strategic Thinking - Develops long-term security strategies, evaluates emerging technologies, aligns cybersecurity initiatives with institutional priorities, and balances security with business objectives.
  • Communication - Communicates effectively with executive leadership, technical teams, auditors, researchers, faculty, legal counsel, vendors, and external partners. Produces clear technical documentation and executive-level reporting.
  • Project Management - Plans and manages multiple strategic initiatives while balancing operational responsibilities and organizational priorities.
  • Physical Demands - This position involves extended periods of sitting and extensive use of computers and office equipment.

MINIMUM QUALIFICATIONS

  1. Must meet and maintain eligibility requirements to work with CUI/CTI data, as determined by the Facility Security Officer and the Office of Export Control.
  2. Bachelor's degree and six (6) years of related experience in information security or information technology; OR Associate's degree and eight (8) years of related experience; OR ten (10) years of related experience.
  3. Four (4) or more years of experience must be specifically in security assessment, vulnerability management, governance/risk/compliance, application security, or related cybersecurity disciplines.
  4. One or more years of experience leading or supervising a technical cybersecurity team or serving as a technical team lead supervising direct reports.
  5. Demonstrated experience conducting enterprise security assessments and cybersecurity risk analyses.
  6. Demonstrated Experience with vulnerability management platforms and enterprise vulnerability assessment, prioritization, and remediation methodologies.
  7. Demonstrated Experience developing security policies, standards, procedures, and governance documentation.
  8. Demonstrated Experience supporting enterprise compliance initiatives involving frameworks and standards such as NIST CSF, NIST 800-53, NIST 800-171, CIS Controls, ISO 27001, PCI DSS, HIPAA, FERPA, CJIS, CMMC, or comparable standards.
  9. Experience performing vendor security assessments and third-party risk analysis.
  10. Demonstrated experience in the management, evaluation, and development of cyber security professional team members.
  11. Demonstrated leadership, analytical, organizational, communication, and project management skills.

PREFERRED QUALIFICATIONS

  1. Master's degree in Cybersecurity, Computer Science, Information Assurance, Information Systems or a related field.
  2. Experience leading enterprise Governance, Risk, and Compliance (GRC) programs.
  3. Experience in higher education information security.
  4. Experience with application security testing, secure software development, or DevSecOps.
  5. Experience with cloud security architecture and cloud governance.
  6. Experience operating, assessing, evaluating and documenting security exceptions.
  7. Experience implementing enterprise data protection and data governance initiatives.
  8. Experience supporting research security, export controls, and Controlled Unclassified Information (CUI) environments.
  9. Experience conducting executive cybersecurity risk reporting and board-level presentations.
  10. Experience developing enterprise security metrics and maturity models.
  11. Experience evaluating cybersecurity technologies and vendor solutions.
  12. CISSP, CISM, CRISC, CCSP, CSSLP, or comparable advanced cybersecurity certifications.

APPOINTMENT TERMS

This is a full-time, permanent position located at the Storrs Campus in Storrs, CT. The University offers a competitive salary, and outstanding benefits, including employee and dependent tuition waivers at UConn, and a highly desirable work environment.

This position is on-site. THIS IS NOT A REMOTE POSITION. The position may be eligible for a hybrid work schedule under applicable bargaining agreements, management approval, and not less than an annual review. This position may require you to travel in-state and you may be required to work irregular hours to support operational or security activities and initiatives.

Other rights, terms, and conditions of employment are contained in the collective bargaining agreement between the University of Connecticut and the University of Connecticut Professional Employees Association (UCPEA).

TO APPLY

Please apply online at Faculty and Staff Positions, Search #4999811 to upload a resume, cover letter, and contact information for three (3) professional references. Applicants must clearly demonstrate how they meet the stated minimum qualifications, and any preferred qualifications they may possess, in their application materials.

This job posting is scheduled to be removed at 11:55 p.m. Eastern time on September 11, 2026.

A

Similar Jobs

More Jobs at University of Connecticut

  • Finance Manager
    $80K — $95K *
    Storrs Mansfield, CT 06268 (Capitol County)
    Finance & Insurance
    In-Person
  • Director of Engineering Student Engagement
    $80K — $95K *
    Storrs Mansfield, CT 06268 (Capitol County)
    Education, Government & Non-Profit
    In-Person
  • Enterprise PHP Developer
    $88K — $105K *
    Storrs Mansfield, CT 06268 (Capitol County)
    Enterprise Technology
    In-Person
  • Identity Developer 2 or 3
    $95K — $115K *
    Storrs Mansfield, CT 06268 (Capitol County)
    Education, Government & Non-Profit
    In-Person
  • Systems Administrator 2
    $80K — $95K *
    Storrs Mansfield, CT 06268 (Capitol County)
    Education, Government & Non-Profit
    In-Person

More Education, Government & Non-Profit Jobs

Find similar Information Security Assessment and Analysis Team Lead jobs: