CybersecurityJobs.io
← Back to all jobs

Job Description

San Diego State University seeks a Research Cybersecurity Analyst to turn cybersecurity, contractual, regulatory, and sponsor requirements into secure, compliant safeguards for research environments.

Responsibilities

  • Review research proposals, solicitations, contracts, subcontracts, awards, and data-use agreements to identify cybersecurity, privacy, data-handling, and reporting requirements.
  • Perform risk, gap, and control readiness assessments; recommend security approaches, remediation strategies, and risk-treatment options.
  • Partner with researchers, research administration, IT, research computing, and privacy, legal, export control, and compliance teams to interpret and implement applicable requirements.
  • Interpret sponsor and contractual cybersecurity requirements, including flow-down clauses, reporting obligations, data-handling restrictions, security milestones, and assessment expectations.
  • Translate contract and regulatory requirements into controls, responsible parties, evidence, and remediation plans.
  • Assess research data, systems, and workflows to identify indicators of CUI, FCI, PHI, PII, export-controlled information, or other restricted data.
  • Define and document the scope and boundaries of research environments, including users, cloud services, third-party providers, endpoints, networks, and research equipment.
  • Explain cybersecurity requirements in practical terms to researchers and research-support personnel.
  • Coordinate, support, and validate security controls across cloud and on-premises research environments.
  • Assess security architectures and configurations, including identity and access management, network segmentation, encryption, endpoint protection, logging, vulnerability management, and secure configuration.
  • Identify security gaps and coordinate remediation.
  • Support the design, review, and ongoing maintenance of secure research environments and research enclaves.
  • Develop and maintain SSPs, POA&Ms, inventories, procedures, diagrams, and compliance evidence.
  • Support sponsor inquiries, audits, and assessments, including CMMC readiness.
  • Support vulnerability monitoring, remediation, and research-focused incident readiness.
  • Maintain documentation and processes that demonstrate continued compliance and operational effectiveness after initial assessment or authorization.

Requirements

  • Experience implementing or assessing NIST SP 800-171, CMMC, NIST SP 800-53, or comparable security frameworks, including developing or maintaining SSPs, POA&Ms, control evidence, and assessment documentation.
  • Experience securing Windows, Linux, cloud, or research computing environments, including identity and access management, encryption, network segmentation, secure configuration, logging, and vulnerability management.
  • Ability to conduct security risk, gap, and control assessments, identify remediation or risk-treatment options, and support audit or assessment readiness.
  • Ability to translate sponsor, contractual, regulatory, and security requirements into technical and procedural controls and communicate them effectively to researchers, technology teams, and leadership.
  • Working knowledge of research-security requirements, including learning and applying requirements related to CUI/FCI, privacy, federal research awards, HIPAA-regulated information, export controls, and controlled-access research data.
  • Experience assessing cloud, vendor, and third-party security, including shared-responsibility models and contractual security requirements.
  • Strong communication, collaboration, and project management skills for managing multiple initiatives across technical, research, administrative, and compliance teams.
  • Ability to handle confidential, regulated, and sensitive information and adapt to evolving technologies and security requirements.

Technologies

  • NIST SP 800-171
  • CMMC
  • NIST SP 800-53
  • HIPAA Security Rule
  • CUI, FCI, PHI, PII
  • SSPs, POA&Ms
  • Windows, Linux
  • Cloud (Azure, AWS, Google Cloud)
  • Identity and access management, network segmentation, encryption
  • Endpoint protection, logging, vulnerability management, secure configuration
  • CISSP, CISM, CCSP, Security+, CySA+, GIAC

Benefits

  • 15 paid holidays, vacation, and sick leave
  • CalPERS pension plan with retiree healthcare and reciprocal agreements with other California public retirement systems, including the UC
  • Medical, dental, and vision options at low or no cost
  • CSU tuition fee waiver for employees and eligible dependents
  • FlexCash
  • Life and disability insurance
  • Legal and pet plans
  • Access to the library, campus events, employee groups, and volunteer and social activities

Position Information

  • Full-time (1.0 time-base), benefits-eligible, permanent/probationary position
  • Exempt under FLSA; not eligible for overtime compensation
  • Standard work hours: Monday–Friday, 8:00 a.m. to 4:30 p.m., with variation based on operational needs
  • Eligible for telecommuting up to 3 days per week after a training period requiring on-site presence

Education and Experience

  • Equivalent to a bachelor’s degree in a related field and four years of relevant experience
  • Additional experience demonstrating acquired and successfully applied knowledge and abilities may substitute for required education on a year-for-year basis
  • An advanced degree in a related field may substitute for required experience on a year-for-year basis

Preferred Qualifications

  • Advanced degree in cybersecurity, information security, computer science, information systems, engineering, or a related field and/or additional progressively responsible cybersecurity experience
  • Experience supporting higher education or research environments, including secure research environments, CUI/FCI, CMMC readiness, HIPAA-regulated research, or cloud platforms such as Azure, AWS, or Google Cloud
  • Relevant cybersecurity, cloud, audit, or compliance certifications completed or in progress (CISSP, CISM, CCSP, Security+, CySA+, GIAC, CMMC, or comparable)

Application and Supplemental Information

  • Apply by October 18, 2026 for full consideration; later applications reviewed on an as-needed basis; position remains open until filled
  • Mandated reporter under California Child Abuse and Neglect Reporting Act; required to comply with CSU Executive Order 1083
  • SDSU is not a sponsoring agency for staff or management positions (e.g., H-1B); applicants must be authorized to work in the United States full-time
  • Employment contingent upon documents demonstrating identity and authorization to work in the United States (consistent with Immigration Reform and Control Act)
  • Education Code 89521 requirements: disclose sexual harassment final administrative or judicial decision within the last 7 years only after minimum qualifications are met and before an offer
  • Final-stage applicants must sign a release authorizing CSU to request information from current and/or former employers regarding substantiated misconduct allegations
  • Background check (including criminal records check) required; conditional offers may be rescinded if disqualifying information is found or if information was knowingly withheld or falsified
  • SDSU is a smoke-free campus
  • Reasonable accommodations available for qualified applicants who request an accommodation by contacting Livia Peeples at [email protected]

Location: San Diego, CA (hybrid). Salary: USD 7,284–10,611 per monthly. Minimum Experience: 4 years. Education: Bachelor’s degree equivalent in a related field.

Similar Jobs