Research Security Cybersecurity Specialist (5271C) The Office of Research Administration & Compliance #88458
University of California, Berkeley · Berkeley, CA · 4 days ago
Engineering$112k/moFull-time
About the role
The Research Security Cybersecurity Specialist supports UC Berkeley's compliance with federal cybersecurity and data security requirements applicable to sponsored research. This role serves as the research security team's subject matter expert on cybersecurity standards, frameworks, and data protection regulations.
Responsibilities
- Evaluates the cybersecurity posture of individual research labs and PI computing environments against applicable federal standards (NIST 800-171, NIST 800-53, CMMC, FISMA, and evolving NSPM-33 requirements).
- Conducts gap analyses, identifies areas of potential non-compliance, and collaborates with PIs and IT service providers to develop clear, actionable remediation plans.
- Provides expert guidance on data security requirements associated with federally sponsored research, including HIPAA, FERPA, and controlled technical information requirements.
- Develops and implements standard operating procedures and controls for data security compliance across diverse research contexts.
- Helps build the compliance processes, procedures, and workflows needed to support research cybersecurity compliance as federal requirements continue to evolve.
- Maintains awareness of regulatory developments across federal agencies (NSF, DoD, DOE, NIH, and others) and assesses their implications for sponsored research.
- Collaborates with campus IT organizations to coordinate on compliance-related technical questions.
- Coordinates with relevant campus units during cybersecurity incident response efforts to assess compliance implications and ensure affected research environments are brought back into alignment with federal requirements.
- Fulfills the role of an independent compliance assessor of research computing environments while navigating a multi-stakeholder environment with professionalism and tact.
- Interfaces with federal sponsors regarding cybersecurity compliance inquiries or audit support.
- Develops and delivers targeted training and educational materials on cybersecurity compliance requirements for PIs, research staff, and graduate students.
Qualifications
- Strong working knowledge of NIST cybersecurity frameworks, particularly NIST 800-171 and NIST 800-53, with the ability to interpret, apply, and assess compliance against these standards.
- Ability to rapidly learn and apply new and evolving regulatory frameworks, federal requirements, and cybersecurity standards (e.g., CMMC, DFARS 252.204-7012, FISMA, NSPM-33, NIST 800-172, and agency-specific research security requirements).
- Exceptional written and verbal communication skills with a demonstrated ability to explain complex technical cybersecurity concepts clearly and patiently to non-technical audiences, including faculty, graduate students, and administrative staff.
- Strong interpersonal and consultative skills with the ability to build trust and credibility with researchers, guide them through compliance processes with patience and clarity, and maintain productive relationships even when delivering difficult or unwelcome requirements.
- Ability to work collaboratively within a complex, multi-stakeholder environment, navigating a decentralized organizational landscape with diplomacy and professionalism.
- Demonstrated ability to work independently with minimal technical supervision, exercise sound judgement, and manage a dynamic workload including urgent, time-sensitive requests alongside longer-term compliance projects.
- General familiarity with data security regulations (e.g., HIPAA, FERPA, controlled technical information) and the ability to quickly understand and advise on data protection requirements.
- Sufficient technical depth to credibly evaluate real-world computing environments and earn the trust of both researchers and campus IT professionals.
Benefits
The University of California, Berkeley offers a comprehensive benefits package that includes:
- At least 80 hours of paid time off per year
- Space for supportive colleague communities via numerous employee resource groups
- Professional development opportunities
- Flexible work arrangements (up to 5 days/week remote work within the United States)
- Comprehensive health, dental, and vision insurance
- Retirement savings plan with employer contributions
- Disability and life insurance
- Parental leave
- Employee assistance programs
- And more...