Research Cybersecurity Analyst
Job Description
San Diego State University seeks a Research Cybersecurity Analyst to turn cybersecurity, contractual, regulatory, and sponsor requirements into secure, compliant safeguards for research environments.
Responsibilities
- Review research proposals, solicitations, contracts, subcontracts, awards, and data-use agreements to identify cybersecurity, privacy, data-handling, and reporting requirements.
- Perform risk, gap, and control readiness assessments; recommend security approaches, remediation strategies, and risk-treatment options.
- Partner with researchers, research administration, IT, research computing, and privacy, legal, export control, and compliance teams to interpret and implement applicable requirements.
- Interpret sponsor and contractual cybersecurity requirements, including flow-down clauses, reporting obligations, data-handling restrictions, security milestones, and assessment expectations.
- Translate contract and regulatory requirements into controls, responsible parties, evidence, and remediation plans.
- Assess research data, systems, and workflows to identify indicators of CUI, FCI, PHI, PII, export-controlled information, or other restricted data.
- Define and document the scope and boundaries of research environments, including users, cloud services, third-party providers, endpoints, networks, and research equipment.
- Explain cybersecurity requirements in practical terms to researchers and research-support personnel.
- Coordinate, support, and validate security controls across cloud and on-premises research environments.
- Assess security architectures and configurations, including identity and access management, network segmentation, encryption, endpoint protection, logging, vulnerability management, and secure configuration.
- Identify security gaps and coordinate remediation.
- Support the design, review, and ongoing maintenance of secure research environments and research enclaves.
- Develop and maintain SSPs, POA&Ms, inventories, procedures, diagrams, and compliance evidence.
- Support sponsor inquiries, audits, and assessments, including CMMC readiness.
- Support vulnerability monitoring, remediation, and research-focused incident readiness.
- Maintain documentation and processes that demonstrate continued compliance and operational effectiveness after initial assessment or authorization.
Requirements
- Experience implementing or assessing NIST SP 800-171, CMMC, NIST SP 800-53, or comparable security frameworks, including developing or maintaining SSPs, POA&Ms, control evidence, and assessment documentation.
- Experience securing Windows, Linux, cloud, or research computing environments, including identity and access management, encryption, network segmentation, secure configuration, logging, and vulnerability management.
- Ability to conduct security risk, gap, and control assessments, identify remediation or risk-treatment options, and support audit or assessment readiness.
- Ability to translate sponsor, contractual, regulatory, and security requirements into technical and procedural controls and communicate them effectively to researchers, technology teams, and leadership.
- Working knowledge of research-security requirements, including learning and applying requirements related to CUI/FCI, privacy, federal research awards, HIPAA-regulated information, export controls, and controlled-access research data.
- Experience assessing cloud, vendor, and third-party security, including shared-responsibility models and contractual security requirements.
- Strong communication, collaboration, and project management skills for managing multiple initiatives across technical, research, administrative, and compliance teams.
- Ability to handle confidential, regulated, and sensitive information and adapt to evolving technologies and security requirements.
Technologies
- NIST SP 800-171
- CMMC
- NIST SP 800-53
- HIPAA Security Rule
- CUI, FCI, PHI, PII
- SSPs, POA&Ms
- Windows, Linux
- Cloud (Azure, AWS, Google Cloud)
- Identity and access management, network segmentation, encryption
- Endpoint protection, logging, vulnerability management, secure configuration
- CISSP, CISM, CCSP, Security+, CySA+, GIAC
Benefits
- 15 paid holidays, vacation, and sick leave
- CalPERS pension plan with retiree healthcare and reciprocal agreements with other California public retirement systems, including the UC
- Medical, dental, and vision options at low or no cost
- CSU tuition fee waiver for employees and eligible dependents
- FlexCash
- Life and disability insurance
- Legal and pet plans
- Access to the library, campus events, employee groups, and volunteer and social activities
Position Information
- Full-time (1.0 time-base), benefits-eligible, permanent/probationary position
- Exempt under FLSA; not eligible for overtime compensation
- Standard work hours: Monday–Friday, 8:00 a.m. to 4:30 p.m., with variation based on operational needs
- Eligible for telecommuting up to 3 days per week after a training period requiring on-site presence
Education and Experience
- Equivalent to a bachelor’s degree in a related field and four years of relevant experience
- Additional experience demonstrating acquired and successfully applied knowledge and abilities may substitute for required education on a year-for-year basis
- An advanced degree in a related field may substitute for required experience on a year-for-year basis
Preferred Qualifications
- Advanced degree in cybersecurity, information security, computer science, information systems, engineering, or a related field and/or additional progressively responsible cybersecurity experience
- Experience supporting higher education or research environments, including secure research environments, CUI/FCI, CMMC readiness, HIPAA-regulated research, or cloud platforms such as Azure, AWS, or Google Cloud
- Relevant cybersecurity, cloud, audit, or compliance certifications completed or in progress (CISSP, CISM, CCSP, Security+, CySA+, GIAC, CMMC, or comparable)
Application and Supplemental Information
- Apply by October 18, 2026 for full consideration; later applications reviewed on an as-needed basis; position remains open until filled
- Mandated reporter under California Child Abuse and Neglect Reporting Act; required to comply with CSU Executive Order 1083
- SDSU is not a sponsoring agency for staff or management positions (e.g., H-1B); applicants must be authorized to work in the United States full-time
- Employment contingent upon documents demonstrating identity and authorization to work in the United States (consistent with Immigration Reform and Control Act)
- Education Code 89521 requirements: disclose sexual harassment final administrative or judicial decision within the last 7 years only after minimum qualifications are met and before an offer
- Final-stage applicants must sign a release authorizing CSU to request information from current and/or former employers regarding substantiated misconduct allegations
- Background check (including criminal records check) required; conditional offers may be rescinded if disqualifying information is found or if information was knowingly withheld or falsified
- SDSU is a smoke-free campus
- Reasonable accommodations available for qualified applicants who request an accommodation by contacting Livia Peeples at [email protected]
Location: San Diego, CA (hybrid). Salary: USD 7,284–10,611 per monthly. Minimum Experience: 4 years. Education: Bachelor’s degree equivalent in a related field.