Senior Director of Research Information Security

Texas Tech UniversityLubbock, TX

About The Position

Manages and directs the day to day operations of a research center/institute or medium sized department. Plans, coordinates and supervises the operation and activities of the center/institute/department. Develops and implements policies and procedures, administers the budget, organizes tasks and sets priorities. Own TTU’s research CUI/CMMC program charter, roadmap, and annual plan; maintain a governance framework reusable for other regulated research environments; chair a cross-functional Research CUI/CMMC Working Group with OR&I, TTU IT, and Legal/Office of General Counsel: define and maintain CUI policies/standards (identification, marking, storage, transmission, sharing, decontrol) aligned to the CUI Registry and institutional policy. Establish and maintain a Responsible Accountable Consulted Informed (RACI) model across ORS, OESC, departmental IT, lab managers, and central IT and a documented escalation path for decision-making and prioritization: define hold/release criteria for onboarding projects into CUI-scoped environments and recommend stop-work/temporary suspension actions through the jointly defined governance process when material noncompliance or unacceptable risk is identified. Interpret/tailor controls; map award/contract terms to TTU standards and policies; approve SSPs; control implementation statements, network diagrams, and data-flow maps; maintain POA&Ms with risk-based prioritization. Lead self-assessments against NIST 800-171A/CMMC; compute/maintain SPRS DoD Assessment scores with objective evidence; coordinate third-party assessments and customer/prime audits; track remediation to closure. With ORS/Contracts, review solicitations/awards for CUI/CMMC clauses; advise on flowdowns and budgeted compliance costs in coordination with TTU IT. Build role-based training (initial + annual) for PIs, research staff, departmental IT, and student workers (integrating state + federal requirements); publish quick-start guides, handling checklists, and PI onboarding materials; maintain a TTU research-security web hub & FAQs. Define continuous monitoring requirements and evidence expectations for CUI/CMMC-scoped research environments consistent with CIO/CISO standards; partner with TTU IT Security and designated system owners to implement and operation monitoring capabilities; coordinate periodic access recertification. Maintain/exercise a research-focused IR plan aligned to CIO/CISO incident response processes, including contractual timelines (including 72-hour reporting when required by contract); during incidents affecting CUI-scoped research, serve as the research program lead to coordinate scope, contractual obligations, and sponsor communications while TTU IT Security leads technical triage/forensics and containment; lead after-action reviews for research CUI incidents; ensure corrective actions are captured in Plan of Action and Milestones (POAMs) and tracked to closure. Embed CUI/CMMC checkpoints into proposal → Just In Time (JIT) → award setup → onboarding → project changes → closeout → retention/decontrol; support Data Management Plans/Data Use Agreements, Trade Agreement Acts/Manufacturing License Agreements (with Export Control), visiting-researcher onboarding, facility access controls. Define Key Performance Indicators and report quarterly to the Office of Research & Innovation and the CIO/CISO: control coverage; open POAMs by severity/age; assessment/SPRS score trend; training completion; incident Mean Time To Repair (MTTR); enclave uptime.

Requirements

  • Bachelor's degree required.
  • Six years progressively responsible management experience.
  • Additional education beyond Bachelor's may substitute for experience on a year for year basis.
  • Must possess the ability to obtain and maintain a security clearance from the Department of Defense.
  • This includes having U.S. citizenship and undergoing a background check and fingerprint clearance process by a separate agency.
  • This position is designated as involving access to critical infrastructure systems and/or research, as defined by Texas Executive Order GA-48.
  • As such, candidates must successfully complete a comprehensive background check prior to employment.
  • Employees are required to comply with all applicable state and federal regulations related to the protection of critical infrastructure.
  • Ongoing employment is dependent upon maintaining eligibility for access and successfully passing periodic security and compliance reviews.

Responsibilities

  • Own TTU’s research CUI/CMMC program charter, roadmap, and annual plan.
  • Maintain a governance framework reusable for other regulated research environments.
  • Chair a cross-functional Research CUI/CMMC Working Group with OR&I, TTU IT, and Legal/Office of General Counsel.
  • Define and maintain CUI policies/standards (identification, marking, storage, transmission, sharing, decontrol) aligned to the CUI Registry and institutional policy.
  • Establish and maintain a Responsible Accountable Consulted Informed (RACI) model across ORS, OESC, departmental IT, lab managers, and central IT and a documented escalation path for decision-making and prioritization.
  • Define hold/release criteria for onboarding projects into CUI-scoped environments and recommend stop-work/temporary suspension actions through the jointly defined governance process when material noncompliance or unacceptable risk is identified.
  • Interpret/tailor controls; map award/contract terms to TTU standards and policies; approve SSPs; control implementation statements, network diagrams, and data-flow maps; maintain POA&Ms with risk-based prioritization.
  • Lead self-assessments against NIST 800-171A/CMMC; compute/maintain SPRS DoD Assessment scores with objective evidence; coordinate third-party assessments and customer/prime audits; track remediation to closure.
  • Review solicitations/awards for CUI/CMMC clauses; advise on flowdowns and budgeted compliance costs in coordination with TTU IT.
  • Build role-based training (initial + annual) for PIs, research staff, departmental IT, and student workers (integrating state + federal requirements).
  • Publish quick-start guides, handling checklists, and PI onboarding materials.
  • Maintain a TTU research-security web hub & FAQs.
  • Define continuous monitoring requirements and evidence expectations for CUI/CMMC-scoped research environments consistent with CIO/CISO standards.
  • Partner with TTU IT Security and designated system owners to implement and operation monitoring capabilities; coordinate periodic access recertification.
  • Maintain/exercise a research-focused IR plan aligned to CIO/CISO incident response processes, including contractual timelines (including 72-hour reporting when required by contract).
  • Serve as the research program lead during incidents affecting CUI-scoped research to coordinate scope, contractual obligations, and sponsor communications while TTU IT Security leads technical triage/forensics and containment.
  • Lead after-action reviews for research CUI incidents.
  • Ensure corrective actions are captured in Plan of Action and Milestones (POAMs) and tracked to closure.
  • Embed CUI/CMMC checkpoints into proposal → Just In Time (JIT) → award setup → onboarding → project changes → closeout → retention/decontrol.
  • Support Data Management Plans/Data Use Agreements, Trade Agreement Acts/Manufacturing License Agreements (with Export Control), visiting-researcher onboarding, facility access controls.
  • Define Key Performance Indicators and report quarterly to the Office of Research & Innovation and the CIO/CISO: control coverage; open POAMs by severity/age; assessment/SPRS score trend; training completion; incident Mean Time To Repair (MTTR); enclave uptime.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service