Salary: See Position Description
Location : UH Manoa, Honolulu, HI
Job Type: Full-Time Temporary
Job Number:Department: Information Technology Services System
Division: Office of the VP for Information Technology and Chief Information Officer
Opening Date: 08/26/2026
Closing Date: 9/24/2026 11:59 PM Hawaii
Position Number:: 0096679T
DescriptionTitle: Security Admin/CMMC Research Tech Analyst
Position Number: 0096679T
Hiring Unit: Information Technology Services, OVPIT & CIO
Location: UH System Offices, Manoa Campus
Date Posted: August 26, 2026
Closing Date: September 24, 2026
Band: B
Salary :
Full Time/Part Time: Full-time
Month: 11-month
Temporary/Permanent: Temporary
Duties and Responsibilities (* denotes essential functions):- *As a member of the UH Information Security team, oversees, manages & maintains the UH information security data protection, risk management, and compliance program. Serves as the primary Research SRE (Secure Research Enclave) Technical Analyst. Provides technical expertise to ensure research productivity while maintaining the integrity of controlled technology environments related to Cybersecurity Maturity Model Certification (CMMC) and other international, federal, state research compliance regulations.
- *Responsible for the design, implementation, and oversight of security frameworks required for federally funded research. This includes ensuring that the university infrastructure and specific secure research enclaves (SREs) meet the requirements of CMMC, NIST SP 800-171 (Protecting Controlled Unclassified Information), NIST SP 800-53 (Federal Information Systems), HIPAA and other applicable federal regulations.
- *Works directly with individual researchers and research groups to aid adoption and application of secure cloud resources (AWS, GCP, Azure) to support research.
- *Participates in the architecture, design, and capacity planning for Secure Research Data Enclaves on commercial clouds in cooperation with ITS Research Cyber Infrastructure (RCI) group, ITS Technology Infrastructure (TI) group and other teams and the Information Security Compliance Analyst.
- *Conducts "computational intake" interviews to translate research goals into technical cloud architectures. Guides researchers in selecting the appropriate cloud services (IaaS, PaaS, SaaS) and resource types for their specific workloads.
- *Assists with the implementation and enforcement of policies regarding the handling, use, and storage of restricted, Federal Contraction Information (FCI), Controlled Unclassified Information (CUI), and HIPAA data within cloud environments.
- *Educates and advises researchers on approaches for ensuring compliance with relevant security regulations in cloud and local environments.
- *Assists researchers in deploying environments that adhere to System Security Plans (SSPs), ensuring that technical controls (e.g., MFA, encryption, log management) are operational and compliant with NIST 800-171/CMMC requirements.
- *Reviews third-party cloud services implementations intended for use in regulated research projects to ensure alignment with relevant federal and other security standards.
- *Responds to help requests and works with the Research Cyberinfrastructure (RCI) and InfoSec teams to find solutions that support the researcher while maintaining compliance.
- *Collaborates with the Research Security Compliance Analyst to map existing technical controls in cloud deployments to appropriate CMMC levels and remediate gaps.
- *Organizes workshops and training materials for secure cloud resources, specifically tailored for researchers handling regulated data.
- *Develops documentation and tutorials on how to provision and utilize secure cloud resources effectively and securely.
- *Directs student employees to work with research projects to document and organize the artifacts (evidence that shows all of the requirements of regulations) for the required security rules and regulations.
- *Assist grant writers with the "Facilities, Equipment, and Other Resources" and "Data Management Plan" (DMP) sections of grant proposals (NSF, NIH, DoD, etc.) and provide technical cost estimates for grant budgeting to ensure research projects are sustainably funded in the cloud.
- * Assists in operating and monitoring the integrity of secure cloud systems (virtual machines, storage, networks) and conducts cloud infrastructure administration duties to keep up with the pace of complex research problems and ensure security compliance.
- *Assists with vulnerability assessments of deployed research environments to identify deficiencies in security.
- *Work with Principal Investigators, Office of Research Compliance, Office of General Counsel, Information Security Team, and other stakeholders to ensure that incidents involving FCI, CUI, HIPAA, and other regulated data are reported to federal agencies within required timelines. Implement and maintain appropriate processes for reporting security violations to appropriate reporting authorities. Participates in security incident responses & investigations, including any emergency situations, and provides remediation support.
- Attend regional or national multi-day trainings, meetings or conferences.
- *Follows and implements directives and guidance related to best practices from University of Hawai'i System Information Technology Services.
- *Ensures the consistent adoption, implementation, and enforcement of recommendations issued through University of Hawai'i System Information Technology Service.
- *Keeps abreast of recommendations issued through University of Hawai'i System Information Technology Service, and takes timely action as needed.
- *Continuously monitor and lead initiatives to enhance system reliability, security, and operational efficiency. Supervise and mentor IT staff to assure that administrative directives and industry best practices are understood and followed.
- Other duties as assigned.
Minimum Qualifications - Possession of a pertinent baccalaureate educational degree in Computer Sciences or Information Security or related field and 5 years of progressively responsible professional information technology experience with responsibilities for information security, of which 2 years of the experience must have been comparable in scope and complexity to the next lower pay band in the University of Hawai'i broadband system; or any equivalent combination of education and/or professional work experience which provides the required education, knowledge, skills and abilities as indicated.
- Considerable working knowledge of information security as demonstrated by the broad knowledge and understanding of the full range of pertinent standard and evolving information technology concepts, principles and methodologies.
- Considerable working knowledge and understanding of the broad technology, systems, hardware and software associated with information security.
- Demonstrated ability to recognize a wide range of intricate problems, use reasoning and logic to determine accurate causes, and apply principles and practices to determine, evaluate, integrate, and implement practical and thorough solutions in an effective and timely manner.
- Proven ability to comprehend, interpret and implement administrative directives and guidance to ensure IT operations align with organizational standards and industry best practices.
- Demonstrated ability to interpret and present information and ideas clearly and accurately in writing, verbally and by preparation of reports and other materials.
- Demonstrated ability to establish and maintain effective working relationships with internal and external organizations, groups, team leaders and members, and individuals.
- If applicable, for supervisory work, demonstrated ability to lead subordinates, manage work priorities and projects, and manage employee relations.
- Ability to translate complex federal rules, regulations and requirements into actionable steps.
- Ability to apply information technology concepts, principles and methodologies to a broad range of research projects and environments.
- Considerable working knowledge and experience with NIST 800-171 and NIST 800-53 including SSPs and POAMs.
- Functional knowledge of information security principles and familiarity with frameworks such as NIST 800-171, HIPAA, or CMMC.
- Strong understanding of IT service management, cybersecurity principles, risk management, and compliance requirements. Demonstrated experience implementing and maintaining IT best practices, standards, and governance.
- Considerable knowledge of international, federal, state and local laws, rules, regulations related to information security, privacy and higher education.
- Considerable working knowledge of current information security technologies and tools.
- Considerable work experience in cloud computing or research computing.
- Knowledge of basic computing paradigms, software installation, and commercial cloud platforms (AWS, GCP, Azure).
- Understanding of virtual networks, identity management, compute and storage solutions within a commercial cloud context.
- Working knowledge of computer forensics and investigative techniques.
- Experience with systems, systems administration, and network hardware and administration.
- Demonstrated ability to develop effective training materials.
- Demonstrated ability to develop and conduct effective in-person training/workshops.
- Demonstrated ability to combine and apply skill sets from many areas of IT.
- Demonstrated ability to speak, read, comprehend, interpret and write fluently in English.
- Demonstrated ability to learn and apply new technologies independently and in a timely manner using books, manuals, online research, and other resources.
- Working knowledge of common Internet protocols (such as TCP/IP) and applications.
- Working knowledge of one or more programming or scripting language.
- Ability to manage multiple projects.
- Ability to travel out-of-state.
- Ability to work a variable work schedule; and work outside normally scheduled work hours including day, night, weekend and/or holiday hours as directed.
Desirable Qualifications - Certifications related to the information security area (e.g. CISSP, GIAC/GSEC, CISM, etc.)
- Experience with configuring and implementing technical security solutions.
- Ability to supervise student employees.
- Cybersecurity experience in or with higher education.
To Apply:Click on the "Apply" button on the top right corner of the screen to complete an application and attached required documents.
Note: If you have not previously applied for a position using NeoGov, you will need to create an account.
Applicants must submit the following:
- Cover letter to the selection committee indicating interest in the position and how the minimum and desirable qualifications are met,
- Resume,
- The names and contact information (telephone number and email addresses) of at least three (3) professional references, and
- Copies of educational transcripts are acceptable; however, original official transcripts will be required at time of hire. Diplomas and copies will NOT be accepted. Transcripts issued from an institution outside of the United States of America (USA) require a course-by-course analysis with an equivalency statement from an agency having membership with the National Association of Credential Evaluation Services, Inc., verifying the degree equivalency to that of an accredited institution within the USA. Expense of the evaluation shall be borne by the applicant.
Late or incomplete applications will not be considered. The application will be considered incomplete if any of the required documents/materials are not included or are unreadable.
Please redact references to social security numbers and birthdate on submitted documents.
Employment may be contingent on verification of credentials and other background information, including the completion of a criminal history check.
Inquiries:(808) 956-9098,
[email protected]