Security Admin/CMMC Research Tech Analyst (#0096679T)

University of HawaiiHonolulu, HI
Onsite

About The Position

As a member of the UH Information Security team, this role oversees, manages, and maintains the UH information security data protection, risk management, and compliance program. The position serves as the primary Research SRE (Secure Research Enclave) Technical Analyst, providing technical expertise to ensure research productivity while maintaining the integrity of controlled technology environments related to Cybersecurity Maturity Model Certification (CMMC) and other international, federal, and state research compliance regulations. The role is responsible for the design, implementation, and oversight of security frameworks required for federally funded research, ensuring university infrastructure and specific secure research enclaves (SREs) meet the requirements of CMMC, NIST SP 800-171, NIST SP 800-53, HIPAA, and other applicable federal regulations. The analyst will work directly with researchers to aid the adoption and application of secure cloud resources (AWS, GCP, Azure) and participate in the architecture, design, and capacity planning for Secure Research Data Enclaves on commercial clouds. This includes conducting 'computational intake' interviews, guiding researchers in selecting appropriate cloud services, and assisting with the implementation and enforcement of policies for handling restricted data. The analyst will also educate researchers on compliance, assist in deploying compliant environments, review third-party cloud service implementations, and respond to help requests. Collaboration with compliance analysts to map controls and remediate gaps, organizing workshops, developing documentation, and directing student employees are also key responsibilities. Additionally, the role assists grant writers with proposal sections and provides technical cost estimates for grant budgeting, operates and monitors secure cloud systems, conducts vulnerability assessments, and works with stakeholders on incident reporting and response.

Requirements

  • Possession of a pertinent baccalaureate educational degree in Computer Sciences or Information Security or related field and 5 years of progressively responsible professional information technology experience with responsibilities for information security, of which 2 years of the experience must have been comparable in scope and complexity to the next lower pay band in the University of Hawaii broadband system; or any equivalent combination of education and/or professional work experience which provides the required education, knowledge, skills and abilities as indicated.
  • Considerable working knowledge of information security as demonstrated by the broad knowledge and understanding of the full range of pertinent standard and evolving information technology concepts, principles and methodologies.
  • Considerable working knowledge and understanding of the broad technology, systems, hardware and software associated with information security.
  • Demonstrated ability to recognize a wide range of intricate problems, use reasoning and logic to determine accurate causes, and apply principles and practices to determine, evaluate, integrate, and implement practical and thorough solutions in an effective and timely manner.
  • Proven ability to comprehend, interpret and implement administrative directives and guidance to ensure IT operations align with organizational standards and industry best practices.
  • Demonstrated ability to interpret and present information and ideas clearly and accurately in writing, verbally and by preparation of reports and other materials.
  • Demonstrated ability to establish and maintain effective working relationships with internal and external organizations, groups, team leaders and members, and individuals.
  • If applicable, for supervisory work, demonstrated ability to lead subordinates, manage work priorities and projects, and manage employee relations.
  • Ability to translate complex federal rules, regulations and requirements into actionable steps.
  • Ability to apply information technology concepts, principles and methodologies to a broad range of research projects and environments.
  • Considerable working knowledge and experience with NIST 800-171 and NIST 800-53 including SSPs and POAMs.
  • Functional knowledge of information security principles and familiarity with frameworks such as NIST 800-171, HIPAA, or CMMC.
  • Strong understanding of IT service management, cybersecurity principles, risk management, and compliance requirements.
  • Demonstrated experience implementing and maintaining IT best practices, standards, and governance.
  • Considerable knowledge of international, federal, state and local laws, rules, regulations related to information security, privacy and higher education.
  • Considerable working knowledge of current information security technologies and tools.
  • Considerable work experience in cloud computing or research computing.
  • Knowledge of basic computing paradigms, software installation, and commercial cloud platforms (AWS, GCP, Azure).
  • Understanding of virtual networks, identity management, compute and storage solutions within a commercial cloud context.
  • Working knowledge of computer forensics and investigative techniques.
  • Experience with systems, systems administration, and network hardware and administration.
  • Demonstrated ability to develop effective training materials.
  • Demonstrated ability to develop and conduct effective in-person training/workshops.
  • Demonstrated ability to combine and apply skill sets from many areas of IT.
  • Demonstrated ability to speak, read, comprehend, interpret and write fluently in English.
  • Demonstrated ability to learn and apply new technologies independently and in a timely manner using books, manuals, online research, and other resources.
  • Working knowledge of common Internet protocols (such as TCP/IP) and applications.
  • Working knowledge of one or more programming or scripting language.
  • Ability to manage multiple projects.
  • Ability to travel out-of-state.
  • Ability to work a variable work schedule; and work outside normally scheduled work hours including day, night, weekend and/or holiday hours as directed.

Nice To Haves

  • Certifications related to the information security area (e.g. CISSP, GIAC/GSEC, CISM, etc.)
  • Experience with configuring and implementing technical security solutions.
  • Ability to supervise student employees.
  • Cybersecurity experience in or with higher education.

Responsibilities

  • Oversees, manages & maintains the UH information security data protection, risk management, and compliance program.
  • Serves as the primary Research SRE (Secure Research Enclave) Technical Analyst.
  • Provides technical expertise to ensure research productivity while maintaining the integrity of controlled technology environments related to Cybersecurity Maturity Model Certification (CMMC) and other international, federal, state research compliance regulations.
  • Responsible for the design, implementation, and oversight of security frameworks required for federally funded research.
  • Ensures that the university infrastructure and specific secure research enclaves (SREs) meet the requirements of CMMC, NIST SP 800-171 (Protecting Controlled Unclassified Information), NIST SP 800-53 (Federal Information Systems), HIPAA and other applicable federal regulations.
  • Works directly with individual researchers and research groups to aid adoption and application of secure cloud resources (AWS, GCP, Azure) to support research.
  • Participates in the architecture, design, and capacity planning for Secure Research Data Enclaves on commercial clouds in cooperation with ITS Research Cyber Infrastructure (RCI) group, ITS Technology Infrastructure (TI) group and other teams and the Information Security Compliance Analyst.
  • Conducts "computational intake" interviews to translate research goals into technical cloud architectures.
  • Guides researchers in selecting the appropriate cloud services (IaaS, PaaS, SaaS) and resource types for their specific workloads.
  • Assists with the implementation and enforcement of policies regarding the handling, use, and storage of restricted, Federal Contraction Information (FCI), Controlled Unclassified Information (CUI), and HIPAA data within cloud environments.
  • Educates and advises researchers on approaches for ensuring compliance with relevant security regulations in cloud and local environments.
  • Assists researchers in deploying environments that adhere to System Security Plans (SSPs), ensuring that technical controls (e.g., MFA, encryption, log management) are operational and compliant with NIST 800-171/CMMC requirements.
  • Reviews third-party cloud services implementations intended for use in regulated research projects to ensure alignment with relevant federal and other security standards.
  • Responds to help requests and works with the Research Cyberinfrastructure (RCI) and InfoSec teams to find solutions that support the researcher while maintaining compliance.
  • Collaborates with the Research Security Compliance Analyst to map existing technical controls in cloud deployments to appropriate CMMC levels and remediate gaps.
  • Organizes workshops and training materials for secure cloud resources, specifically tailored for researchers handling regulated data.
  • Develops documentation and tutorials on how to provision and utilize secure cloud resources effectively and securely.
  • Directs student employees to work with research projects to document and organize the artifacts (evidence that shows all of the requirements of regulations) for the required security rules and regulations.
  • Assist grant writers with the "Facilities, Equipment, and Other Resources" and "Data Management Plan" (DMP) sections of grant proposals (NSF, NIH, DoD, etc.) and provide technical cost estimates for grant budgeting to ensure research projects are sustainably funded in the cloud.
  • Assists in operating and monitoring the integrity of secure cloud systems (virtual machines, storage, networks) and conducts cloud infrastructure administration duties to keep up with the pace of complex research problems and ensure security compliance.
  • Assists with vulnerability assessments of deployed research environments to identify deficiencies in security.
  • Work with Principal Investigators, Office of Research Compliance, Office of General Counsel, Information Security Team, and other stakeholders to ensure that incidents involving FCI, CUI, HIPAA, and other regulated data are reported to federal agencies within required timelines.
  • Implement and maintain appropriate processes for reporting security violations to appropriate reporting authorities.
  • Participates in security incident responses & investigations, including any emergency situations, and provides remediation support.
  • Attend regional or national multi-day trainings, meetings or conferences.
  • Follows and implements directives and guidance related to best practices from University of Hawai'i System Information Technology Services.
  • Ensures the consistent adoption, implementation, and enforcement of recommendations issued through University of Hawai'i System Information Technology Service.
  • Keeps abreast of recommendations issued through University of Hawai'i System Information Technology Service, and takes timely action as needed.
  • Continuously monitor and lead initiatives to enhance system reliability, security, and operational efficiency.
  • Supervise and mentor IT staff to assure that administrative directives and industry best practices are understood and followed.
  • Other duties as assigned.

Benefits

  • Salary schedules and placement information
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service