Research Cybersecurity Analyst (Information Security Analyst III)

San Diego State University•San Diego, CA
•$7,284 - $10,611•Hybrid

About The Position

San Diego State University is seeking a Research Cybersecurity Analyst to help faculty and research teams and campus partners securely conduct research involving sensitive, regulated, and contractually restricted information. Working within SDSU’s Information Technology Security Office, the Research Cybersecurity Analyst will translate cybersecurity, contractual, regulatory, and sponsor requirements, including NIST SP 800-171, CMMC, NIST SP 800-53, and the HIPAA Security Rule and related requirements, into practical technical, administrative, and procedural safeguards. You’ll assess research environments, help implement security requirements, maintain compliance documentation, coordinate remediation, and help prepare research projects for sponsor inquiries, audits, and formal assessments. The position will work collaboratively with researchers, research administration, research computing, central IT, privacy, legal, export control, compliance, and other campus partners to help research teams meet security obligations while maintaining an effective and usable research environment.

Requirements

  • Experience implementing or assessing NIST SP 800-171, CMMC, NIST SP 800-53, or comparable security frameworks, including developing or maintaining SSPs, POA&Ms, control evidence, and assessment documentation.
  • Experience securing Windows, Linux, cloud, or research computing environments, including controls such as identity and access management, encryption, network segmentation, secure configuration, logging, and vulnerability management.
  • Ability to conduct security risk, gap, and control assessments, identify appropriate remediation or risk-treatment options, and support audit or assessment readiness.
  • Ability to translate sponsor, contractual, regulatory, and security requirements into practical technical and procedural controls and communicate them effectively to researchers, technology teams, and leadership.
  • Working knowledge of research-security requirements and the ability to learn and apply requirements related to CUI/FCI, privacy, federal research awards, HIPAA-regulated information, export controls, and controlled-access research data.
  • Experience assessing cloud, vendor, and third-party security, including shared-responsibility models and contractual security requirements.
  • Strong communication, collaboration, and project management skills, with the ability to manage multiple security initiatives and work effectively across technical, research, administrative, and compliance teams.
  • Ability to appropriately handle confidential, regulated, and sensitive information and adapt to evolving technologies and security requirements.
  • An equivalent to bachelor’s degree in a related field and four years of relevant experience. Additional experience which demonstrates acquired and successfully applied knowledge and abilities shown above may be substituted for the required education on a year-for-year basis. An advanced degree in a related field may be substituted for the required experience on a year-for-year basis.
  • Applicants must currently be authorized to work in the United States on a full-time basis.

Nice To Haves

  • Advanced degree in cybersecurity, information security, computer science, information systems, engineering, or a related field and/or additional progressively responsible cybersecurity experience.
  • Experience supporting higher education or research environments, including secure research environments, CUI/FCI, CMMC readiness, HIPAA-regulated research, or cloud platforms such as Azure, AWS, or Google Cloud.
  • Relevant cybersecurity, cloud, audit, or compliance certification, completed or in progress, such as CISSP, CISM, CCSP, Security+, CySA+, GIAC, CMMC, or another comparable certification.

Responsibilities

  • Review research proposals, solicitations, contracts, subcontracts, awards, and data-use agreements to identify cybersecurity, privacy, data-handling, and reporting requirements.
  • Conduct risk, gap, and control readiness assessments and recommend practical security approaches, remediation strategies, and risk-treatment options.
  • Work with researchers, research administration, IT teams, research computing, and privacy, legal, export control, and compliance partners to interpret and implement applicable requirements.
  • Interpret contractual and sponsor cybersecurity requirements, including flow-down clauses, reporting obligations, data-handling restrictions, security milestones, and assessment expectations.
  • Map contract and regulatory requirements to applicable controls, responsible parties, evidence, and remediation plans.
  • Assess research data, systems, and workflows for indicators of CUI, FCI, PHI, PII, export-controlled information, or other restricted data.
  • Establish and document the scope and boundaries of research environments, including users, cloud services, third-party providers, endpoints, networks, and research equipment.
  • Explain cybersecurity requirements in practical terms to researchers and research-support personnel who may not have a cybersecurity background.
  • Coordinate, support, and validate security controls across cloud and on-premises research environments.
  • Assess security architectures and configurations involving identity and access management, network segmentation, encryption, endpoint protection, logging, vulnerability management, and secure configuration.
  • Evaluate security gaps and coordinate appropriate remediation.
  • Support the design, review, and maintenance of secure research environments and research enclaves.
  • Develop and maintain SSPs, POA&Ms, inventories, procedures, diagrams, and compliance evidence.
  • Help prepare research environments for sponsor inquiries, audits, and assessments, including CMMC readiness.
  • Support vulnerability monitoring, remediation, and research-focused incident readiness.
  • Maintain documentation and processes needed to demonstrate continued compliance and operational effectiveness after an initial assessment or authorization.

Benefits

  • Generous Time Off: 15 paid holidays, vacation, and sick leave.
  • Retirement: CalPERS pension plan with retiree healthcare, and reciprocal agreements with other California public retirement systems, including the UC.
  • Health Coverage: Medical, dental, and vision options at low or no cost.
  • Education Support: CSU tuition fee waiver for employees and eligible dependents.
  • Optional Offerings: FlexCash, life and disability insurance, legal and pet plans.
  • Campus & Community: Access to the library, campus events, employee groups, and volunteer and social activities.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service