Job Description
Posting number: 2026-01866
Department: Information Technology Services System
Division: Office of the VP for Information Technology and Chief Information Officer
Job classification: INFORMATION TECHNOLOGY
Posting type: Open
Categories: IT and Computers, Security
Title: Security Admin/CMMC Research Analyst
Position Number: 0081494T
Hiring Unit: Information Technology Services, OVPIT & CIO
Location: UH System Offices, Manoa Campus
Date Posted: August 26, 2026
Closing Date: September 24, 2026
Band: B
Salary : salary schedules and placement information
Full Time/Part Time: Full-time
Month: 11-month
Temporary/Permanent: Temporary
Duties and Responsibilities (* denotes essential functions):
- *As a member of the UH Information Security team, oversees, manages & maintains the UH information security data protection, risk management, and compliance program. Serves as the primary Research Security Compliance Analyst. Provides advice on regulatory/legal/compliance requirements for related to Cybersecurity Maturity Model Certification (CMMC) and other international, federal, state research compliance regulations.
- *Responsible for the design, implementation, and oversight of security frameworks required for federally funded research. This includes ensuring that the university infrastructure and specific secure research enclaves (SREs) meet the requirements of CMMC, NIST SP 800-171 (Protecting Controlled Unclassified Information), NIST SP 800-53 (Federal Information Systems), HIPAA and other applicable federal regulations.
- *Consult with Principal Investigators during the pre-award phase to interpret security requirements in grants (e.g., Department of Defense, NIH, NASA).
- *Work with Principal Investigators and others to develop, maintain, and update System Security Plans (SSPs) and Plan Of Action and Milestones (POAM) for individual research projects, detailing how each technical and administrative control is met and how deficits will be remediated. Map existing NIST 800-171 controls to the appropriate CMMC Level and assist with planning to remediate gaps before formal certification.
- *Serves as a primary point of contact for external C3PAOs (CMMC Third-Party Assessment Organizations) and federal auditors.
- *Educates, advises and trains staff on approaches for ensuring compliance with relevant security regulations and the security of the university's networks, systems and data in both face-to-face settings and in distance-delivered environments. This includes, but is not limited to, the proper marking, storage, and dissemination of sensitive research data to prevent "spillage" into non-compliant systems.
- *Develop and maintain relevant online security and regulatory compliance education materials specifically tailored for researchers handling Controlled Unclassified Information (CUI), including development of web pages, video/audio recordings, managed instructional materials in a learning management system; includes providing materials/training for targeted audiences.
- *Conduct comprehensive assessments of existing research environments against NIST SP 800-171 and 800-53 controls and other applicable regulations to identify deficiencies.
- *Provides risk assessment reports on the operation and progress of compliance efforts.
- *Assists with implementation, dissemination, and enforcement of new existing policies and guidelines related to information technology security policies and practices, especially those regarding the handling, use, and storage of controlled unclassified information (CUI), and federal contract information (FCI) policies and procedures.
- *Manage the uploading and accuracy of the university’s NIST 800-171 self-assessment scores and CMMC scores into the Supplier Performance Risk System (SPRS) as required by project development, proposal and submission process.
- *Continually assesses and reports on computer systems, networks and data security risks within the University’s controlled technology environments. Regularly conduct compliance audits to ensure that technical controls (e.g., MFA, log management, FIPS-validated encryption) remain operational.
- *Work with Principal Investigators, Information Security Team, and other stakeholders to ensure that incidents involving FCI, CUI, and other regulated data are reported to federal agencies within required timelines. Implement and maintain appropriate processes for reporting security violations to appropriate reporting authorities.
- *Participates in the architecture and design, and capacity planning for new products and technologies associated with information security, Secure Research Enclaves, and CMMC-compliance in cooperation with other ITS teams. Review third-party software and cloud services intended for use in regulated research projects.
- *Consults and collaborates with other departments (e.g. Legal, Internal Audit, HR, treasury, data governance, etc.) to direct compliance issues to appropriate channels for clarification, guidance, investigation, and resolution.
- *Participates in security incident responses & investigations, including any emergency situations, and provides remediation support.
- *Direct student employees on writing and updating required policies, procedures and assisting with assessments and training
- Attend regional or national multi-day trainings, meetings or conferences.
- *Follows and implements directives and guidance related to best practices from University of Hawai'i System Information Technology Services.
- *Ensures the consistent adoption, implementation, and enforcement of recommendations issued through University of Hawai'i System Information Technology Service.
- *Keeps abreast of recommendations issued through University of Hawai'i System Information Technology Service, and takes timely action as needed.
- *Continuously monitor and lead initiatives to enhance system reliability, security, and operational efficiency. Supervise and mentor IT staff to assure that administrative directives and industry best practices are understood and followed.
- Other duties as assigned.
Minimum Qualifications
- Possession of a pertinent baccalaureate educational degree in Computer Sciences or Information Security or related field and 5 years of progressively responsible professional information technology experience with responsibilities for information security, of which 2 years of the experience must have been comparable in scope and complexity to the next lower pay band in the University of Hawai'i broadband system; or any equivalent combination of education and/or professional work experience which provides the required education, knowledge, skills and abilities as indicated.
- Considerable working knowledge of information security as demonstrated by the broad knowledge and understanding of the full range of pertinent standard and evolving information technology concepts, principles and methodologies.
- Considerable working knowledge and understanding of the broad technology, systems, hardware and software associated with information security.
- Demonstrated ability to recognize a wide range of intricate problems, use reasoning and logic to determine accurate causes, and apply principles and practices to determine, evaluate, integrate, and implement practical and thorough solutions in an effective and timely manner.
- Proven ability to comprehend, interpret and implement administrative directives and guidance to ensure IT operations align with organizational standards and industry best practices.
- Demonstrated ability to interpret and present information and ideas clearly and accurately in writing, verbally and by preparation of reports and other materials.
- Demonstrated ability to establish and maintain effective working relationships with internal and external organizations, groups, team leaders and members, and individuals.
- If applicable, for supervisory work, demonstrated ability to lead subordinates, manage work priorities and projects, and manage employee relations.
- Ability to translate complex federal rules, regulations and requirements into actionable steps.
- Ability to apply information technology concepts, principles and methodologies to a broad range of research projects and environments.
- Considerable working knowledge and experience with NIST 800-171 and NIST 800-53 including SSPs and POAMs.
- Strong understanding of IT service management, cybersecurity principles, risk management, and compliance requirements. Demonstrated experience implementing and maintaining IT best practices, standards, and governance.
- Considerable knowledge of information security related standards.
- Considerable knowledge of international, federal, state and local laws, rules, regulations related to information security, privacy and higher education.
- Considerable working knowledge of current information security technologies and tools.
- Considerable knowledge of establishing/managing a Governance, Risk, and Compliance (GRC) program for a large, decentralized organization.
- Working knowledge of computer forensics and investigative techniques.
- Experience with systems, systems administration, and network hardware and administration.
- Demonstrated ability to develop effective training materials.
- Demonstrated ability to develop and conduct effective in-person training/workshops.
- Demonstrated ability to combine and apply skill sets from many areas of IT.
- Demonstrated ability to speak, read, comprehend, interpret and write fluently in English.
- Demonstrated ability to learn and apply new technologies independently and in a timely manner using books, manuals, online research, and other resources.
- Working knowledge of common Internet protocols (such as TCP/IP) and applications.
- Working knowledge of one or more programming or scripting language.
- Ability to manage multiple projects.
- Ability to travel out-of-state.
- Ability to work a variable work schedule; and work outside normally scheduled work hours including day, night, weekend and/or holiday hours as directed.
Desirable Qualifications
- Certifications related to the information security area (e.g. CISSP, GIAC/GSEC, CISM, etc.)
- Experience with configuring and implementing technical security solutions.
- Ability to supervise student employees.
- Cybersecurity experience in or with higher education.
To Apply:
Click on the "Apply" button on the top right corner of the screen to complete an application and attached required documents.
Note: If you have not previously applied for a position using NeoGov, you will need to create an account.
Applicants must submit the following:
- Cover letter to the selection committee indicating interest in the position and how the minimum and desirable qualifications are met,
- Resume,
- The names and contact information (telephone number and email addresses) of at least three (3) professional references, and
- Copies of educational transcripts are acceptable; however, original official transcripts will be required at time of hire. Diplomas and copies will NOT be accepted. Transcripts issued from an institution outside of the United States of America (USA) require a course-by-course analysis with an equivalency statement from an agency having membership with the National Association of Credential Evaluation Services, Inc., verifying the degree equivalency to that of an accredited institution within the USA. Expense of the evaluation shall be borne by the applicant.
Late or incomplete applications will not be considered. The application will be considered incomplete if any of the required documents/materials are not included or are unreadable.
Please redact references to social security numbers and birthdate on submitted documents.
Employment may be contingent on verification of credentials and other background information, including the completion of a criminal history check.
Inquiries:
(808) 956-9098, itsadmin@hawaii.edu
Examples of duties
The University of Hawai'i is an Equal Opportunity Institution and is committed to a policy of nondiscrimination in employment, including on the basis of veteran and disability status. For more information, visit: https://www.hawaii.edu/offices/eeo/policies/
Employment is contingent on satisfying employment eligibility verification requirements of the Immigration Reform and Control Act of 1986; reference checks of previous employers; and for certain positions, criminal history record checks.
In accordance with the Jeanne Clery Disclosure of Campus Security Policy and Campus Crime Statistics Act, annual campus crime statistics for the University of Hawai'i may be viewed at: https://www.hawaii.edu/titleix/help/campus-security/, or a paper copy may be obtained upon request from the respective UH Campus Security or Administrative Services Office.
In accordance with Article 10 of the unit 08 collective bargaining agreement, bargaining unit members receive priority consideration for APT job vacancies. As a result, external or non BU 08 applicants may not be considered for some APT vacancies. BU 08 members with re-employment rights or priority status are responsible for informing the hiring unit of their status.
Accommodation Request: The University of Hawai'i complies with the provisions of the Americans with Disabilities Act (ADA). Applicants requiring a reasonable accommodation for any part of the application and hiring process should contact the EEO coordinator directly. Determination on requests for reasonable accommodation will be made on a case-by-case basis. For further information, please refer to the following link: https://www.hawaii.edu/offices/eeo/accommodation-request/