Jobs · Information Technology · North Carolina

Research Security Specialist

North Carolina State University · Raleigh-Durham-Chapel Hill Area · 2 wk ago
Information Technology$130k–$150k/yrFull-time

Posting Number PG194797EP

About the Role

The Security & Compliance Unit (S&C) within the Office of Information Technology (OIT) oversees the cybersecurity of the University’s systems and data in a manner consistent with industry best practices and the University’s IT compliance and IT risk management obligations. S&C develops and ensures compliance with cybersecurity policies, regulations, and procedures, supports and oversees implementation of strategic information security initiatives, provides operational security services, and provides campus-wide vendor risk and license management. S&C is also the functional lead for the university’s identity and access management program.

The Information Security Risk and Assurance (ISRA) team within the Office of Information Technology (OIT) Security & Compliance unit is a central point for managing university cyber, data, IT risk, and compliance activities, including but not limited to: DMCA, FERPA, GLBA, HEOA, HIPAA, ISO 27002, NC ID Theft Act, PCI-DSS, NIST 800-171, and Red Flags Rule. The team assists with IT strategic planning and cybersecurity service development and is primarily responsible for the implementation, guidance, and maintenance of the following services:

  • Security Consulting and Education
  • Data Management
  • IT Risk Management
  • Security Awareness and Training
  • Security Liaison Team Program Management
  • Security Policy and Compliance
  • Data/System Access Reviews
  • Internal & External OIT Audit Coordination
  • Litigation Holds/eDiscovery and Records Retention
  • Research Data Security Consultation & Evaluation
  • Security Compliance Program Development, Management, and Continuous Assessment
  • Security Policy, Regulations, Rules, and SOP Development
  • Identity & Access Management Data Steward
  • Strategic and Tactical Planning
  • Business Analyst for IAM services (SAR, Password Self-Service, OIM, etc.)

Responsibilities

The IT Security Professional provides technical implementations and daily monitoring of the university’s complex IT environment in accordance with best practices and standards such as NIST 800-171, CMMC, CUI, NIST 800-53, PCI DSS, DMCA, FERPA, GLBA, HIPAA, etc. Responsibilities include cybersecurity reviews, risk assessments, risk management, data management, policies/standards and guidelines, cybersecurity awareness and training, audit coordination, and project management.

Security Operations, Risk Management, and Compliance

This position reviews, coordinates, and monitors information technology security controls that protect confidentiality, integrity, and availability of the organization’s controlled secure research data in accordance with contractual, legal, regulatory, and institutional requirements. The position is responsible for ensuring that users with access to secure research data receive appropriate training. The position consults with faculty/researchers, college/unit IT staff, applicable OIT staff, applicable Office of Research and Innovation (ORI) staff, and other subject matter experts to ensure technology solutions and compliance standards are in line with contract requirements.

Moreover, the position will ensure appropriate auditing and documentation, providing guidance and recommendations to the research community in areas of data security, from award negotiation through project close-out. This position will work closely with ORI Sponsored Programs & Regulatory Compliance to assist with monitoring the secure research environment setups, conducting follow-up reviews, and ensuring contract terms and conditions are in line with NC State standards for data security.

This position serves as the formal Information Systems Security Manager (ISSM) for the university’s Secure University Research Environment (SURE), which is the university’s C3PAO CMMC Level 2 certified environment. The overall duties are as follows:

  • Serve as the bridge between IT, information security, and research requirements
  • Lead the maintenance and growth of the existing NIST 800-171 security and compliance program, especially in the research context
  • Assist OIT, ORI, and campus stakeholders on maintaining compliance with CMMC 2.0 level 1 and 2
  • Serve as the SURE Information Systems Security Manager (ISSM)
  • Assist the ISRA staff with processing cybersecurity requests, such as ITPC items that require a security review / risk assessment
  • Explore opportunities for the use of AI and their impacts on cybersecurity, data usage, and compliance
  • Participate in programs to improve the university’s cybersecurity awareness and outreach
  • Assist the ISRA staff with GRC project strategies, project tasks, and testing of the service
  • Assist in the enhancement of existing PRRs and the construction of needed procedures across OIT and campus IT

This position involves access to information, items, or technology controlled under the International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR). To comply with federal export control laws, candidates must be a “U.S. Person” as defined by 22 C.F.R. 120.62 (e.g., U.S. Citizen, U.S. Lawful Permanent Resident / Green Card Holder, Refugee or Asylee status under 8 U.S.C. 1324b(a)(3)).

Requirements

Minimum Education and Experience

  • A minimum of 5 years of cybersecurity or related information technology skills (IT risk management, information auditor, etc.)
  • Graduation from an accredited four-year college or university with a major in information technology, computer science, a closely related field, or equivalent years of experience.

Other Required Qualifications

  • Strong experience with implementing security controls in one or more of the following areas:
    • Network administration
    • System administration
    • Software development
    • Cybersecurity administration
  • Advanced understanding of technical IT security controls relating to the university network, servers, workstations, cloud services, and other end-user devices.
  • Knowledge and awareness of the key attributes of applicable federal regulations, state laws, and other external requirements and their impact on cybersecurity, privacy, and compliance such as:
    • FERPA – Family Education Rights and Privacy Act
    • GLBA – Gramm-Leach-Bliley Act
    • HIPAA – Health Insurance Portability and Accountability Act of 1996
    • ISO/IEC 27000 series – International Organization for Standardization & International Electrotechnical Commission
    • NIST FIPS PUB 800-53 and 800-171 – National Institute of Standards & Technology
    • FAR/DFARs/CMMC (Federal and Defense Federal Acquisition Regulation Supplement, Cybersecurity Maturity Model Certification)
    • PCI/DSS – Payment Card Industry Data Security Standard
    • FTC (Federal Trade Commission) Red Flags Rule
    • SSAE16 (Statement on Auditing Standards No. 70) and SOC 1 & 2 (Service Organization Controls)
    • HEOA – Higher Education Opportunity Act
    • DMCA – Digital Millennium Copyright Act
  • Ability to interpret various hardware, software, procedural, and policy manuals and other technical and complex documentation
  • Advanced experience working with System Security Plans (SSPs) and Plan of Actions and Milestones (POAMs)
  • Advanced experience conducting risk/security assessments, particularly of cloud service vendors
  • Proven ability to enhance and/or implement an enterprise-wide cybersecurity education and awareness program
  • Effective communication skills with various types of audiences such as research administration, compliance, faculty, IT support, and information security team members
  • Experience working as an effective team member and team lead
  • Experience in project management methodologies

Preferred Qualifications

  • Five (5) or more years of experience in the information security field.
  • In-depth knowledge of cybersecurity principles, information auditing principles, cybersecurity policy and compliance, and IT risk management
  • Experience in cybersecurity and data governance practices within an academic environment.
  • Experience working with data classification systems and implementing solutions to track and monitor the respective classifications and any relevant compliance obligations.
  • Strong technical writing skills and experience with the development of business, technical, and procedural documentation.
  • Detailed knowledge of NIST 800-171, NIST 800-53, and CMMC.
  • Strong working knowledge of IT standards and IT-related internal control frameworks (such as NIST, ISO/IEC, COBIT, etc.)
  • Strong working knowledge of federal, state government laws, and regulations.
  • Experience using ServiceNow or a similar call tracking system and providing Tier 1 customer support.
  • Advanced troubleshooting skills.
  • Familiarity in the use of tools to improve security such as anti-malware, EDR, vulnerability assessments and remediation, intrusion detection and prevention systems (IDS/IPS), log monitoring/correlation, security incident tracking, internal and external penetration testing, forensics, advanced firewall and other network protection, endpoint workstation security protection, cloud technology, or encryption.
  • Experience in developing and implementing strategies and/or solutions to address security issues and providing administrative, physical, and technical security advice to various clients
  • Experience conducting and managing IT risk assessments and providing IT risk advisory services
  • ISACA, ISC2, or GIAC certification is preferred.
  • Other SANS or vendor-specific certifications in security topics are a plus.

Pay

$130,000 - $150,000

Schedule

8:00 am - 5:00 pm; with additional hours as needed; on-call rotation is required

Benefits

As a Pack member, you can enjoy exclusive perks designed to enhance your personal and professional well-being:

  • Medical, Dental, and Vision
  • Flexible Spending Account
  • Retirement Programs
  • Disability Plans
  • Life Insurance
  • Accident Plan
  • Paid Time Off and Other Leave Programs
  • 12 Holidays Each Year
  • Tuition and Academic Assistance
  • Childcare benefits
  • Wellness & Recreation Membership

Similar jobs

Research Security Specialist

Research Compliance Office at the Texas A&M University SystemCollege Station, TX· 1 mo ago
Information Technology$4k–$5k/moapply on tamus.wd1.myworkdayjobs.com

Research Security Specialist

Texas A&M University SystemCollege Station, TX· 1 mo ago
Information Technology$4k–$5k/moapply on tamus.wd1.myworkdayjobs.com

Research Security Manager

Georgia Institute of TechnologyCobb County, GA· 2 mo ago
Information Technology$106k–$180k/yrapply on careers.hprod.onehcm.usg.edu