Research Cybersecurity Analyst (Information Security Analyst III)Job no: 562498
Work type: Staff
Location: San Diego
Categories: Unit 9 - CSUEU - Technical Support Services, Probationary, Full Time, Information Systems & Technology, Telecommute eligible (work onsite as scheduled and/or as requested and telecommute as scheduled)
Position SummarySan Diego State University is seeking a
Research Cybersecurity Analyst to help faculty and research teams and campus partners securely conduct research involving sensitive, regulated, and contractually restricted information. Working within SDSU's Information Technology Security Office, the Research Cybersecurity Analyst will translate cybersecurity, contractual, regulatory, and sponsor requirements, including
NIST SP 800-171, CMMC, NIST SP 800-53, and the HIPAA Security Rule and related requirements, into practical technical, administrative, and procedural safeguards. You'll assess research environments, help implement security requirements, maintain compliance documentation, coordinate remediation, and help prepare research projects for sponsor inquiries, audits, and formal assessments.
The position will work collaboratively with researchers, research administration, research computing, central IT, privacy, legal, export control, compliance, and other campus partners to help research teams meet security obligations while maintaining an effective and usable research environment.What You'll Do:Research Security & Consultation- Review research proposals, solicitations, contracts, subcontracts, awards, and data-use agreements to identify cybersecurity, privacy, data-handling, and reporting requirements.
- Conduct risk, gap, and control readiness assessments and recommend practical security approaches, remediation strategies, and risk-treatment options.
- Work with researchers, research administration, IT teams, research computing, and privacy, legal, export control, and compliance partners to interpret and implement applicable requirements.
- Interpret contractual and sponsor cybersecurity requirements, including flow-down clauses, reporting obligations, data-handling restrictions, security milestones, and assessment expectations.
- Map contract and regulatory requirements to applicable controls, responsible parties, evidence, and remediation plans.
- Assess research data, systems, and workflows for indicators of CUI, FCI, PHI, PII, export-controlled information, or other restricted data.
- Establish and document the scope and boundaries of research environments, including users, cloud services, third-party providers, endpoints, networks, and research equipment.
- Explain cybersecurity requirements in practical terms to researchers and research-support personnel who may not have a cybersecurity background.
Security Controls & Research Environments- Coordinate, support, and validate security controls across cloud and on-premises research environments.
- Assess security architectures and configurations involving identity and access management, network segmentation, encryption, endpoint protection, logging, vulnerability management, and secure configuration.
- Evaluate security gaps and coordinate appropriate remediation.
- Support the design, review, and maintenance of secure research environments and research enclaves.
Compliance & Readiness- Develop and maintain SSPs, POA&Ms, inventories, procedures, diagrams, and compliance evidence.
- Help prepare research environments for sponsor inquiries, audits, and assessments, including CMMC readiness.
- Support vulnerability monitoring, remediation, and research-focused incident readiness.
- Maintain documentation and processes needed to demonstrate continued compliance and operational effectiveness after an initial assessment or authorization.
What We're Looking For:We are looking for a cybersecurity professional who can evaluate security requirements, understand how they apply to research environments, identify practical safeguards, and work collaboratively with technical and nontechnical stakeholders to implement and document those safeguards.
The successful candidate may have developed this experience through cybersecurity operations, governance, risk, and compliance work, IT auditing, cloud security, systems administration, research computing, compliance consulting, or a related area.
Experience in the following areas is especially valuable:
- NIST SP 800-171, CMMC, NIST SP 800-53, or similar security frameworks
- Security controls, assessments, and compliance documentation
- SSPs, POA&Ms, or audit/assessment readiness
- Windows, Linux, cloud, or enterprise environments
- Identity and access management, encryption, vulnerability management, or network security
- Communicating technical or compliance requirements to different audiences
Experience working in a higher-education, research, healthcare, government, defense, or other highly regulated environment is a plus.
Position Information- This is a full-time (1.0 time-base), benefits-eligible, permanent/probationary position.
- This position is designated as exempt under FLSA and is not eligible for overtime compensation.
- Standard SDSU work hours are Monday - Friday, 8:00 a.m. to 4:30 p.m., but may vary based on operational needs.
- This position is eligible for telecommuting up to 3 days per week, following a training period during which on-site presence is required.
Department SummaryThe Information Technology Security Office (ITSO), reporting to the Chief Information Officer (CIO), is part of the Information Technology Division. ITSO provides campus-wide core technology and security services, collaborating with university departments, external auxiliary organizations, and the CSU Chancellor's Office to support core technology and security services across the campus.
For more information regarding the Information Technology Security Office (ITSO), click here.
Education and ExperienceAn equivalent to bachelor's degree in a related field and four years of relevant experience. Additional experience which demonstrates acquired and successfully applied knowledge and abilities shown above may be substituted for the required education on a year-for-year basis. An advanced degree in a related field may be substituted for the required experience on a year-for-year basis.
Key Qualifications- Experience implementing or assessing NIST SP 800-171, CMMC, NIST SP 800-53, or comparable security frameworks, including developing or maintaining SSPs, POA&Ms, control evidence, and assessment documentation.
- Experience securing Windows, Linux, cloud, or research computing environments, including controls such as identity and access management, encryption, network segmentation, secure configuration, logging, and vulnerability management.
- Ability to conduct security risk, gap, and control assessments, identify appropriate remediation or risk-treatment options, and support audit or assessment readiness.
- Ability to translate sponsor, contractual, regulatory, and security requirements into practical technical and procedural controls and communicate them effectively to researchers, technology teams, and leadership.
- Working knowledge of research-security requirements and the ability to learn and apply requirements related to CUI/FCI, privacy, federal research awards, HIPAA-regulated information, export controls, and controlled-access research data.
- Experience assessing cloud, vendor, and third-party security, including shared-responsibility models and contractual security requirements.
- Strong communication, collaboration, and project management skills, with the ability to manage multiple security initiatives and work effectively across technical, research, administrative, and compliance teams.
- Ability to appropriately handle confidential, regulated, and sensitive information and adapt to evolving technologies and security requirements.
- Preferred Qualifications
- Advanced degree in cybersecurity, information security, computer science, information systems, engineering, or a related field and/or additional progressively responsible cybersecurity experience.
- Experience supporting higher education or research environments, including secure research environments, CUI/FCI, CMMC readiness, HIPAA-regulated research, or cloud platforms such as Azure, AWS, or Google Cloud.
- Relevant cybersecurity, cloud, audit, or compliance certification, completed or in progress, such as CISSP, CISM, CCSP, Security+, CySA+, GIAC, CMMC, or another comparable certification.
Compensation and BenefitsSan Diego State University offers competitive compensation and a comprehensive benefits package designed to support your well-being and professional growth.
Compensation:
Step placement will be determined based on relevant qualifications and professional experience, in alignment with the department's budget and equity guidelines.
- Initial step placement is not expected to exceed Step 10 ($8,705/month).
- Salary step placement for internal applicants will follow the CSUEU Collective Bargaining Agreement.
- CSU Classification Salary Range: $7,284-$10,611 per month (Step 1-Step 20).
- Future increases, including step advancements, are subject to contract negotiations.
Full Benefits Package Includes:
- Generous Time Off: 15 paid holidays, vacation, and sick leave.
- Retirement: CalPERS pension plan with retiree healthcare, and reciprocal agreements with other California public retirement systems, including the UC.
- Health Coverage: Medical, dental, and vision options at low or no cost.
- Education Support: CSU tuition fee waiver for employees and eligible dependents.
- Optional Offerings: FlexCash, life and disability insurance, legal and pet plans.
- Campus & Community: Access to the library, campus events, employee groups, and volunteer and social activities.
Our benefits are a significant part of total compensation. Learn more at the SDSU Benefits Overview.