Join the Pack! A community with nearly 8,000 faculty and staff, and 30,000 students. NC State is one of the largest employers in North Carolina, offering a large range of career opportunities. Visit us at https://jobs.hr.ncsu.edu/.
Location
Raleigh, NC
Essential Job Duties
Professional Knowledge
- The IT Security Professional provides technical implementations and daily monitoring of the university's complex IT environment in accordance with best practices and standards such as NIST 800-171, CMMC, CUI, NIST 800-53, PCI DSS (Payment Card Industry Data Security Standards), DMCA, FERPA, GLBA, HIPAA, etc. Responsibilities include cybersecurity reviews, risk assessments, risk management, data management, policies/standards and guidelines, cybersecurity awareness and training, audit coordination and project management.
Security Operations, Risk Management and Compliance
- Specifically, this position reviews, coordinates and monitors information technology security controls that protect confidentiality, integrity and availability of the organization's controlled secure research data in accordance with contractual, legal, regulatory and institutional requirements. The position is responsible for ensuring that users with access to secure research data receive appropriate training.
The position consults with faculty/researchers, college/unit IT staff, applicable OIT staff, applicable Office of Research and Innovation (ORI) staff, and other subject matter experts to ensure technology solutions and compliance standards are in line with contract requirements. Moreover, the position will ensure appropriate auditing and documentation, providing guidance and recommendations to the research community in areas of data security, from award negotiation through project close-out.
This position will work closely with ORI Sponsored Programs & Regulatory Compliance to assist with monitoring the secure research environment setups, conducting follow-up reviews, and ensuring contract terms and conditions are in line with NC State standards for data security. This position serves as the formal Information Systems Security Manager (ISSM) for the university's Secure University Research Environment (SURE), which is the university's C3PAO CMMC Level 2 certified environment.
The overall duties are as follows:
- Serve as the bridge between IT, information security and research requirements
- Lead the maintenance and growth of the existing NIST 800-171 security and compliance program, especially in the research context.
- Assist OIT, ORI and campus stakeholders on maintaining compliance with CMMC 2.0 level 1 and 2
- Serve as the SURE Information Systems Security Manager (ISSM)
- Assist the ISRA staff with processing cybersecurity requests, such as ITPC items that require a security review / risk assessment
- Explore opportunities for the use of AI and their impacts on cybersecurity, data usage and compliance
- Participate in programs to improve the university's cybersecurity awareness and outreach
- Assist the ISRA staff with GRC project strategies, project tasks and testing of the service
- Assist in the enhancement of existing PRRs and the construction of needed procedures across OIT and campus IT
This position involves access to information, items, or technology controlled under the International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR). To comply with federal export control laws, candidates must be a "U.S. Person" as defined by 22 C.F.R. § 120.62 (e.g., U.S. Citizen, U.S. Lawful Permanent Resident / Green Card Holder, Refuged or Asylee status under 8 U.S.C. 1324b(a)(3)).
Other Work/Responsibilities
- Other duties will be assigned as needed.
Minimum Experience/Education
- A minimum of 5 years of cybersecurity or related information technology skills (IT risk management, information auditor, etc.)
- Graduation from an accredited four-year college or university with a major in information technology, computer science, a closely related field, or equivalent years of experience.
Required Qualifications
- Strong experience with implementing security controls in one or more of the following areas:
- Network administration
- System administration
- Software development
- Cybersecurity administration
- Advanced understanding of technical IT security controls relating to the university network, servers, workstations, cloud services and other end user devices.
- Knowledge and an awareness of the key attributes of applicable federal regulations, state laws, and other external requirements and their impact on cybersecurity, privacy and compliance such as the following:
- FERPA - Family Education Rights and Privacy Act
- GLBA - Gramm-Leach-Bliley Act
- HIPAA - Health Insurance Portability and Accountability Act of 1996
- ISO/IEC 27000 series - International Organization for Standardization & International Electrotechnical Commission
- NIST FIPS PUB 800-53 and 800-171 - National Institute of Standards & Technology
- FAR/DFARs/CMMC (Federal and Defense Federal Acquisition Regulation Supplement, Cybersecurity Maturity Model Certification
- PCI/DSS - Payment Card Industry Data Security Standard
- FTC (Federal Trade Commission) Red Flags Rule
- SSAE16 (Statement on Auditing Standards No. 70) and SOC 1 & 2 (Service Organization Controls)
- HEOA - Higher Education Opportunity Act
- DMCA - Digital Millennium Copyright Act
- Ability to interpret various hardware, software, procedural, and policy manuals and other technical and complex documentation
- Advanced experience working with System Security Plans (SSPs) and Plan of Actions and Milestones (POAMs)
- Advanced experience conducting risk/security assessments, particularly of cloud service vendors
- Proven ability to enhance and/or implement an enterprise-wide cybersecurity education and awareness program
- Effective communication skills with various types of audiences such as research administration, compliance, faculty; IT support; information security team members
- Experience working as an effective team member and team lead
- Experience in project management methodologies.
Preferred Qualifications
- Five (5) or more years of experience in the information security field.
- In-depth knowledge of cybersecurity principles, information auditing principles, cybersecurity policy and compliance and IT risk management
- Experience in cybersecurity and data governance practices within an academic environment.
- Experience working with data classification systems and implementing solutions to track and monitor the respective classifications and any relevant compliance obligations.
- Strong technical writing skills and experience with the development of business, technical and procedural documentation.
- Detailed knowledge of NIST 800-171, NIST 800-53, and CMMC.
- Strong working knowledge of IT standards and IT related internal control frameworks (such as NIST, ISO/IEC, COBIT, etc.)
- Strong working knowledge of federal, state government laws and regulations.
- Experience using ServiceNow or a similar call tracking system and providing Tier 1 customer support.
- Advanced troubleshooting skills.
- Familiarity in the use of tools to improve security such as anti-malware, EDR, vulnerability assessments and remediation, intrusion detection and prevention systems (IDS/IPS), log monitoring/correlation, security incident tracking, internal and external penetration testing, forensics, advanced firewall and other network protection, endpoint workstation security protection, cloud technology or encryption.
- Experience in developing and implementing strategies and/or solutions to address security issues and providing administrative, physical and technical security advice to various clients
- Experience conducting and managing IT risk assessments and providing IT risk advisory services
- ISACA, ISC2 or GIAC certification is preferred
- Other SANS or vendor specific certifications in security topics are a plus.
Required License or Certification
N/A
AA/EEO Statement
NC State University is an equal opportunity employer. All qualified applicants will receive equal opportunities for employment without regard to age, color, disability, gender identity, genetic information, national origin, race, religion, sex (including pregnancy), sexual orientation, and veteran status. The University encourages all qualified applicants, including protected veterans and individuals with disabilities, to apply. Individuals with disabilities requiring disability-related accommodations in the application and interview process are welcome to contact 919-513-0574 to speak with a representative of the Office of Equal Opportunity.
If you have general questions about the application process, you may contact Human Resources at (919) 515-2135 or workatncstate@ncsu.edu.
Final candidates are subject to criminal & sex offender background checks. Some vacancies also require credit or motor vehicle checks. Degree(s) must be obtained prior to start date in order to meet qualifications and receive credit.
NC State University participates in E-Verify. Federal law requires all employers to verify the identity and employment eligibility of all persons hired to work in the United States.
This is a Preview Listing…
You must sign in to see the full job description, and to apply.
Manage / Upgrade this job to a Full Job Listing.
Find Your Best Opportunity
Tell them AcademicJobs.com sent you!







