Security Admin/CMMC Research Analyst (#0081494T)

University of HawaiiHonolulu, HI
Onsite

About The Position

As a member of the UH Information Security team, this role oversees, manages, and maintains the UH information security data protection, risk management, and compliance program. The position serves as the primary Research Security Compliance Analyst, providing advice on regulatory/legal/compliance requirements related to Cybersecurity Maturity Model Certification (CMMC) and other international, federal, and state research compliance regulations. The role is responsible for the design, implementation, and oversight of security frameworks required for federally funded research, ensuring university infrastructure and specific secure research enclaves (SREs) meet requirements of CMMC, NIST SP 800-171, NIST SP 800-53, HIPAA, and other applicable federal regulations. This includes consulting with Principal Investigators (PIs) during the pre-award phase, developing and maintaining System Security Plans (SSPs) and Plan Of Action and Milestones (POAMs), mapping NIST 800-171 controls to CMMC levels, and serving as a point of contact for external auditors. The role also involves educating, advising, and training staff on compliance and security, developing online educational materials, conducting assessments, providing risk reports, assisting with policy implementation, managing self-assessment scores in SPRS, and participating in security incident responses.

Requirements

  • Possession of a pertinent baccalaureate educational degree in Computer Sciences or Information Security or related field and 5 years of progressively responsible professional information technology experience with responsibilities for information security, of which 2 years of the experience must have been comparable in scope and complexity to the next lower pay band in the University of Hawaii broadband system; or any equivalent combination of education and/or professional work experience which provides the required education, knowledge, skills and abilities as indicated.
  • Considerable working knowledge of information security as demonstrated by the broad knowledge and understanding of the full range of pertinent standard and evolving information technology concepts, principles and methodologies.
  • Considerable working knowledge and understanding of the broad technology, systems, hardware and software associated with information security.
  • Demonstrated ability to recognize a wide range of intricate problems, use reasoning and logic to determine accurate causes, and apply principles and practices to determine, evaluate, integrate, and implement practical and thorough solutions in an effective and timely manner.
  • Proven ability to comprehend, interpret and implement administrative directives and guidance to ensure IT operations align with organizational standards and industry best practices.
  • Demonstrated ability to interpret and present information and ideas clearly and accurately in writing, verbally and by preparation of reports and other materials.
  • Demonstrated ability to establish and maintain effective working relationships with internal and external organizations, groups, team leaders and members, and individuals.
  • If applicable, for supervisory work, demonstrated ability to lead subordinates, manage work priorities and projects, and manage employee relations.
  • Ability to translate complex federal rules, regulations and requirements into actionable steps.
  • Ability to apply information technology concepts, principles and methodologies to a broad range of research projects and environments.
  • Considerable working knowledge and experience with NIST 800-171 and NIST 800-53 including SSPs and POAMs.
  • Strong understanding of IT service management, cybersecurity principles, risk management, and compliance requirements.
  • Demonstrated experience implementing and maintaining IT best practices, standards, and governance.
  • Considerable knowledge of information security related standards.
  • Considerable knowledge of international, federal, state and local laws, rules, regulations related to information security, privacy and higher education.
  • Considerable working knowledge of current information security technologies and tools.
  • Considerable knowledge of establishing/managing a Governance, Risk, and Compliance (GRC) program for a large, decentralized organization.
  • Working knowledge of computer forensics and investigative techniques.
  • Experience with systems, systems administration, and network hardware and administration.
  • Demonstrated ability to develop effective training materials.
  • Demonstrated ability to develop and conduct effective in-person training/workshops.
  • Demonstrated ability to combine and apply skill sets from many areas of IT.
  • Demonstrated ability to speak, read, comprehend, interpret and write fluently in English.
  • Demonstrated ability to learn and apply new technologies independently and in a timely manner using books, manuals, online research, and other resources.
  • Working knowledge of common Internet protocols (such as TCP/IP) and applications.
  • Working knowledge of one or more programming or scripting language.
  • Ability to manage multiple projects.
  • Ability to travel out-of-state.
  • Ability to work a variable work schedule; and work outside normally scheduled work hours including day, night, weekend and/or holiday hours as directed.

Nice To Haves

  • Certifications related to the information security area (e.g. CISSP, GIAC/GSEC, CISM, etc.)
  • Experience with configuring and implementing technical security solutions.
  • Ability to supervise student employees.
  • Cybersecurity experience in or with higher education.

Responsibilities

  • Oversees, manages & maintains the UH information security data protection, risk management, and compliance program.
  • Serves as the primary Research Security Compliance Analyst.
  • Provides advice on regulatory/legal/compliance requirements for related to Cybersecurity Maturity Model Certification (CMMC) and other international, federal, state research compliance regulations.
  • Responsible for the design, implementation, and oversight of security frameworks required for federally funded research.
  • Ensures that the university infrastructure and specific secure research enclaves (SREs) meet the requirements of CMMC, NIST SP 800-171 (Protecting Controlled Unclassified Information), NIST SP 800-53 (Federal Information Systems), HIPAA and other applicable federal regulations.
  • Consult with Principal Investigators during the pre-award phase to interpret security requirements in grants (e.g., Department of Defense, NIH, NASA).
  • Work with Principal Investigators and others to develop, maintain, and update System Security Plans (SSPs) and Plan Of Action and Milestones (POAM) for individual research projects, detailing how each technical and administrative control is met and how deficits will be remediated.
  • Map existing NIST 800-171 controls to the appropriate CMMC Level and assist with planning to remediate gaps before formal certification.
  • Serves as a primary point of contact for external C3PAOs (CMMC Third-Party Assessment Organizations) and federal auditors.
  • Educates, advises and trains staff on approaches for ensuring compliance with relevant security regulations and the security of the university's networks, systems and data in both face-to-face settings and in distance-delivered environments.
  • Develop and maintain relevant online security and regulatory compliance education materials specifically tailored for researchers handling Controlled Unclassified Information (CUI), including development of web pages, video/audio recordings, managed instructional materials in a learning management system; includes providing materials/training for targeted audiences.
  • Conduct comprehensive assessments of existing research environments against NIST SP 800-171 and 800-53 controls and other applicable regulations to identify deficiencies.
  • Provides risk assessment reports on the operation and progress of compliance efforts.
  • Assists with implementation, dissemination, and enforcement of new existing policies and guidelines related to information technology security policies and practices, especially those regarding the handling, use, and storage of controlled unclassified information (CUI), and federal contract information (FCI) policies and procedures.
  • Manage the uploading and accuracy of the university’s NIST 800-171 self-assessment scores and CMMC scores into the Supplier Performance Risk System (SPRS) as required by project development, proposal and submission process.
  • Continually assesses and reports on computer systems, networks and data security risks within the University’s controlled technology environments.
  • Regularly conduct compliance audits to ensure that technical controls (e.g., MFA, log management, FIPS-validated encryption) remain operational.
  • Work with Principal Investigators, Information Security Team, and other stakeholders to ensure that incidents involving FCI, CUI, and other regulated data are reported to federal agencies within required timelines.
  • Implement and maintain appropriate processes for reporting security violations to appropriate reporting authorities.
  • Participates in the architecture and design, and capacity planning for new products and technologies associated with information security, Secure Research Enclaves, and CMMC-compliance in cooperation with other ITS teams.
  • Review third-party software and cloud services intended for use in regulated research projects.
  • Consults and collaborates with other departments (e.g. Legal, Internal Audit, HR, treasury, data governance, etc.) to direct compliance issues to appropriate channels for clarification, guidance, investigation, and resolution.
  • Participates in security incident responses & investigations, including any emergency situations, and provides remediation support.
  • Direct student employees on writing and updating required policies, procedures and assisting with assessments and training.
  • Attend regional or national multi-day trainings, meetings or conferences.
  • Follows and implements directives and guidance related to best practices from University of Hawai'i System Information Technology Services.
  • Ensures the consistent adoption, implementation, and enforcement of recommendations issued through University of Hawai'i System Information Technology Service.
  • Keeps abreast of recommendations issued through University of Hawai'i System Information Technology Service, and takes timely action as needed.
  • Continuously monitor and lead initiatives to enhance system reliability, security, and operational efficiency.
  • Supervise and mentor IT staff to assure that administrative directives and industry best practices are understood and followed.
  • Other duties as assigned.

Benefits

  • salary schedules and placement information
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service