Job Details

San Diego State University
  • Position Number: 9877589
  • Location: San Diego, United States
  • Position Type: Computer and Information Technology


Research Cybersecurity Analyst (Information Security Analyst III)

Job No: 562498
Work Type: Staff
Locations: Southern California: San Diego
Categories: Bargaining Unit: Unit 9 - CSUEU - Technical Support Services, Appointment Type: Probationary, Time Basis: Full Time, Job Search Category/Discipline: Information Systems & Technology, Workplace Type (Exclude Inst Fac): Telecommute eligible (work onsite as scheduled and/or as requested and telecommute as scheduled)

Position Summary

San Diego State University is seeking a Research Cybersecurity Analyst to help faculty and research teams and campus partners securely conduct research involving sensitive, regulated, and contractually restricted information. Working within SDSU's Information Technology Security Office, the Research Cybersecurity Analyst will translate cybersecurity, contractual, regulatory, and sponsor requirements, including NIST SP 800-171, CMMC, NIST SP 800-53, and the HIPAA Security Rule and related requirements, into practical technical, administrative,  and procedural safeguards. You'll assess research environments, help implement security requirements, maintain compliance documentation, coordinate remediation, and help prepare research projects for sponsor inquiries, audits, and formal assessments. The position will work collaboratively with researchers, research administration, research computing, central IT, privacy, legal, export control, compliance, and other campus partners to help research teams meet security obligations while maintaining an effective and usable research environment.

What You'll Do:

Research Security & Consultation

  • Review research proposals, solicitations, contracts, subcontracts, awards, and data-use agreements to identify cybersecurity, privacy, data-handling, and reporting requirements.
  • Conduct risk, gap, and control readiness assessments and recommend practical security approaches, remediation strategies, and risk-treatment options.
  • Work with researchers, research administration, IT teams, research computing, and privacy, legal, export control, and compliance partners to interpret and implement applicable requirements.
  • Interpret contractual and sponsor cybersecurity requirements, including flow-down clauses, reporting obligations, data-handling restrictions, security milestones, and assessment expectations.
  • Map contract and regulatory requirements to applicable controls, responsible parties, evidence, and remediation plans.
  • Assess research data, systems, and workflows for indicators of CUI, FCI, PHI, PII, export-controlled information, or other restricted data.
  • Establish and document the scope and boundaries of research environments, including users, cloud services, third-party providers, endpoints, networks, and research equipment.
  • Explain cybersecurity requirements in practical terms to researchers and research-support personnel who may not have a cybersecurity background.

Security Controls & Research Environments

  • Coordinate, support, and validate security controls across cloud and on-premises research environments.
  • Assess security architectures and configurations involving identity and access management, network segmentation, encryption, endpoint protection, logging, vulnerability management, and secure configuration.
  • Evaluate security gaps and coordinate appropriate remediation.
  • Support the design, review, and maintenance of secure research environments and research enclaves.

Compliance & Readiness

  • Develop and maintain SSPs, POA&Ms, inventories, procedures, diagrams, and compliance evidence.
  • Help prepare research environments for sponsor inquiries, audits, and assessments, including CMMC readiness.
  • Support vulnerability monitoring, remediation, and research-focused incident readiness.
  • Maintain documentation and processes needed to demonstrate continued compliance and operational effectiveness after an initial assessment or authorization.

What We're Looking For:

We are looking for a cybersecurity professional who can evaluate security requirements, understand how they apply to research environments, identify practical safeguards, and work collaboratively with technical and nontechnical stakeholders to implement and document those safeguards.

The successful candidate may have developed this experience through cybersecurity operations, governance, risk, and compliance work, IT auditing, cloud security, systems administration, research computing, compliance consulting, or a related area.

Experience in the following areas is especially valuable:

  • NIST SP 800-171, CMMC, NIST SP 800-53, or similar security frameworks
  • Security controls, assessments, and compliance documentation
  • SSPs, POA&Ms, or audit/assessment readiness
  • Windows, Linux, cloud, or enterprise environments
  • Identity and access management, encryption, vulnerability management, or network security
  • Communicating technical or compliance requirements to different audiences

Experience working in a higher-education, research, healthcare, government, defense, or other highly regulated environment is a plus.

Why Join Us?

  • Support research securely -- Help researchers meet cybersecurity requirements while moving their work forward.
  • Work across cybersecurity and compliance -- Gain exposure to technical controls, risk assessments, documentation, and assessment readiness.
  • Collaborate across SDSU -- Work with researchers, IT professionals, and compliance partners on a variety of research security needs.
  • Solve different security challenges -- Support research projects with varying technologies, data, sponsors, and security requirements.

As part of the California State University (CSU) system, San Diego State University helps power one of the largest and most impactful public university systems in the nation. See what it's like to work at the CSU---watch our video and imagine your future here: Working at the CSU.

Position Information

  • This is a full-time (1.0 time-base), benefits-eligible, permanent/probationary position.
  • This position is designated as exempt under FLSA and is not eligible for overtime compensation.
  • Standard SDSU work hours are Monday -- Friday, 8:00 a.m. to 4:30 p.m., but may vary based on operational needs. 
  • This position is eligible for telecommuting up to 3 days per week, following a training period during which on-site presence is required.

Department Summary

The Information Technology Security Office (ITSO), reporting to the Chief Information Officer (CIO), is part of the Information Technology Division. ITSO provides campus-wide core technology and security services, collaborating with university departments, external auxiliary organizations, and the CSU Chancellor's Office to support core technology and security services across the campus.

For more information regarding the Information Technology Security Office (ITSO), click here.

Education and Experience

An equivalent to bachelor's degree in a related field and four years of relevant experience. Additional experience which demonstrates acquired and successfully applied knowledge and abilities shown above may be substituted for the required education on a year-for-year basis. An advanced degree in a related field may be substituted for the required experience on a year-for-year basis.

Key Qualifications

  • Experience implementing or assessing NIST SP 800-171, CMMC, NIST SP 800-53, or comparable security frameworks, including developing or maintaining SSPs, POA&Ms, control evidence, and assessment documentation.
  • Experience securing Windows, Linux, cloud, or research computing environments, including controls such as identity and access management, encryption, network segmentation, secure configuration, logging, and vulnerability management.
  • Ability to conduct security risk, gap, and control assessments, identify appropriate remediation or risk-treatment options, and support audit or assessment readiness.
  • Ability to translate sponsor, contractual, regulatory, and security requirements into practical technical and procedural controls and communicate them effectively to researchers, technology teams, and leadership.
  • Working knowledge of research-security requirements and the ability to learn and apply requirements related to CUI/FCI, privacy, federal research awards, HIPAA-regulated information, export controls, and controlled-access research data.
  • Experience assessing cloud, vendor, and third-party security, including shared-responsibility models and contractual security requirements.
  • Strong communication, collaboration, and project management skills, with the ability to manage multiple security initiatives and work effectively across technical, research, administrative, and compliance teams.
  • Ability to appropriately handle confidential, regulated, and sensitive information and adapt to evolving technologies and security requirements.
  • Preferred Qualifications
    • Advanced degree in cybersecurity, information security, computer science, information systems, engineering, or a related field and/or additional progressively responsible cybersecurity experience.
    • Experience supporting higher education or research environments, including secure research environments, CUI/FCI, CMMC readiness, HIPAA-regulated research, or cloud platforms such as Azure, AWS, or Google Cloud.
    • Relevant cybersecurity, cloud, audit, or compliance certification, completed or in progress, such as CISSP, CISM, CCSP, Security+, CySA+, GIAC, CMMC, or another comparable certification.

Compensation and Benefits

San Diego State University offers competitive compensation and a comprehensive benefits package designed to support your well-being and professional growth.

Compensation:
Step placement will be determined based on relevant qualifications and professional experience, in alignment with the department's budget and equity guidelines.

  • Initial step placement is not expected to exceed Step 10 ($8,705/month).
  • Salary step placement for internal applicants will follow the CSUEU Collective Bargaining Agreement.
  • CSU Classification Salary Range: $7,284-$10,611 per month (Step 1-Step 20).
  • Future increases, including step advancements, are subject to contract negotiations.

Full Benefits Package Includes:

  • Generous Time Off: 15 paid holidays, vacation, and sick leave.
  • Retirement: CalPERS pension plan with retiree healthcare, and reciprocal agreements with other California public retirement systems, including the UC.
  • Health Coverage: Medical, dental, and vision options at low or no cost.
  • Education Support: CSU tuition fee waiver for employees and eligible dependents.
  • Optional Offerings: FlexCash, life and disability insurance, legal and pet plans.
  • Campus & Community: Access to the library, campus events, employee groups, and volunteer and social activities.

Our benefits are a significant part of total compensation. Learn more at the SDSU Benefits Overview.

SDSU Values

At SDSU, our diversity gives us power and benefits every single member of our community.  Consistent with California law and federal civil rights laws, SDSU provides equal opportunity for all in education and employment.  We encourage all members of our community to purposefully learn from one another through open and respectful dialogue and responsible engagement. We strongly preserve the right to free expression and encourage difficult conversations that help lead to improved individual and community learning and cohesion.

Principles of Community

At San Diego State University, we are a community of diverse individuals who have and represent many perspectives, beliefs, and identities. This diversity lends our community strength, and we commit to creating and sustaining an inclusive and intellectually vibrant environment that benefits all members of our university. 

SDSU's Principles of Community is an aspirational statement that is intended to evolve over time. The statement reflects the ideals we are encouraged to uphold in our interactions with one another. 

Equal Opportunity and Excellence in Education and Employment

All university programs and activities are open and available to all regardless of race, sex, color, ethnicity or national origin. Consistent with California law and federal civil rights laws, San Diego State University (SDSU) provides equal opportunity in education and employment without unlawful discrimination or preferential treatment based on race, sex, color, ethnicity, or national origin. Our commitment to equal opportunity means ensuring that every student and employee has access to the resources and support they need to thrive and succeed in a university environment and in their communities. SDSU complies with Title VI of the Civil Rights Act of 1964, Title IX of the Education Amendments of 1972, the Americans with Disabilities Act (ADA), Section 504 of the Rehabilitation Act, the California Equity in Higher Education Act, California's Proposition 209 (Art. I, Section 31 of the California Constitution), other applicable state and federal anti-discrimination laws, and CSU's Nondiscrimination Policy. We prohibit discriminatory preferential treatment, segregation based on race or any other protected status, and all forms of discrimination, harassment, and retaliation in all university programs, policies, and practices. 

SDSU is a diverse community of individuals who represent many perspectives, beliefs and identities, committed to fostering an inclusive, respectful, and intellectually vibrant environment. We cultivate a culture of open dialogue, mutual respect, and belonging to support educational excellence and student success. Through academic programs, student organizations and activities, faculty initiatives, and community partnerships, we encourage meaningful engagement with diverse perspectives. As a higher education institution, we are dedicated to advancing knowledge and empowering individuals to reach their full potential by prioritizing inclusive curriculum development, faculty and staff training, student mentorship, and comprehensive support programs. At SDSU, excellence is built on merit, talent, diversity, accessibility, and equal opportunity for all.

Supplemental Information

Apply by October 18, 2026, to ensure full consideration. Applications submitted after this date will be reviewed on an as-needed basis, and the position will remain open until filled.

The person holding this position is considered a 'mandated reporter' under the California Child Abuse and Neglect Reporting Act and is required to comply with the requirements set forth in CSU Executive Order 1083 as a condition of employment. 

San Diego State University is not a sponsoring agency for staff or management positions (e.g., H-1B visa). Applicants must currently be authorized to work in the United States on a full-time basis. Offers of employment are contingent upon the presentation of documents that demonstrate a person's identity and authorization to work in the United States, which are consistent with the provisions of the Immigration Reform and Control Act. 

Education Code 89521 Requirements: Applicants will be required to disclose whether they have received a final administrative decision or final judicial decision determining that they have committed sexual harassment within the last 7 years only after a determination is made that they meet the minimum qualifications for the position, and before an offer of employment is extended.  Applicants who reach the final stages of the application process must also sign a release form that authorizes the release of information by the applicant's current and/or former employers to the CSU concerning any substantiated allegations of misconduct.

A background check (including a criminal records check) must be completed satisfactorily and is required for employment. SDSU will make a conditional offer of employment, which may be rescinded if the background check reveals disqualifying information, and/or it is discovered that the candidate knowingly withheld or falsified information. Failure to satisfactorily complete the background check may affect the continued employment of a current SDSU employee who was conditionally offered the position.

SDSU is a smoke-free campus. For more information, please click here.

Reasonable accommodations will be provided for qualified applicants with disabilities who request an accommodation by contacting Livia Peeples at lpeeples@sdsu.edu.



Advertised:
Applications Close:

To apply, visit https://careers.sdsu.edu/en-us/job/562498







Copyright 2025 Jobelephant.com Inc. All rights reserved.

Posted by the FREE value-added recruitment advertising agency


je-9f8b0a6a8a3c4a16a9dd552d263bfcd5