Research Security Analyst
About the Role
The Privacy / Data Protection Analyst II monitors, analyzes, and reports on university compliance with internal policies, institutional business practices, and external government regulations regarding personal data, data privacy laws, and research security. This role provides operational support to ensure the university's compliance with applicable laws regulating research security (e.g., foreign business relationships, foreign travel, and data security). Working under moderate supervision with latitude for independent judgment, the Analyst reviews university business practices, conducts data privacy audits, identifies areas of non-compliance, and assists in creating and implementing data protection plans to safeguard sensitive university assets and intellectual property.
Responsibilities
- Data Privacy Screening & Workflow Monitoring: Provides operational assistance with Restricted Party Screenings (RPS) and dynamic screening alerts through Visual Compliance to protect institutional data integrity. Reviews disclosures made through the University's Business Relationship Reporting (BRR) system to identify data privacy risks and collaborates with the Office of Research Information Systems (ORIS) on BRR data process improvement and metric tracking in Tableau.
- Incident Investigation & System Disclosures: Manages the identification, submission, and resolution of data policy variances or non-compliance issues within BRR, ERICA, or associated disclosure systems. Manages the research security email account to address data inquiries and validates or rejects potential data privacy alerts routed from partnering entities (including OSP, TLO, OGC, and ARUP).
- Inter-Departmental Consultations & Process Streamlining: Coordinates data privacy and foreign influence consultations received from the Office of Global Health (OGH) and the Office of Global Engagement (OGE). Streamlines restricted party screening workflows and assists in securely transitioning internal offices to submission platforms within the university's Electronic Research Integrity and Compliance Application (ERICA).
- Institutional Regulatory Reporting: Compiles, validates, and manages sensitive information to ensure timely and accurate institutional reporting of foreign contributions and research security metrics (e.g., Section 117, NSF FFDR). Works with University Advancement and OSP to maintain required portal access, execute scheduled reporting timelines, and process data corrections or back-reporting, as necessary.
- Privacy Training & Educational Development: Supports the development and implementation of educational programs, guidelines, and training materials in conjunction with the Office of Research Education (REd). Promotes robust data privacy awareness, data minimization, and regulatory compliance regarding foreign influence and export control programs for faculty, staff, and students.
- Scope of Work: Evaluates future operating systems for institutional research to ensure alignment with data protection and privacy needs. Conducts work assignments of increasing complexity utilizing a moderate skill set, with defined latitude for independent judgment under moderate supervision. Identifies and participates in relevant professional development opportunities.
Minimum Qualifications
Requires a bachelor's degree (or equivalency) plus 4 years of directly related work experience, OR a master's degree (or equivalency) plus 2 years of directly related work experience. Equivalency: 1 year of higher education can be substituted for 1 year of directly related work experience (e.g., bachelor's degree = 4 years of directly related work experience).
Preferred Qualifications
- Leveraged open-source intelligence (OSINT) and specialized data tools to evaluate foreign affiliations, unstated financial ties, and malign foreign talent recruitment program participation, directly supporting institutional compliance with NSPM-33 disclosure and conflict-of-commitment requirements.
Pay
$65,000 - $80,000
Schedule
8am – 5pm, Monday – Friday