Professional Knowledge
- The IT Security Professional provides technical implementations and daily monitoring of the university’s complex IT environment in accordance with best practices and standards such as NIST 800-171, CMMC, CUI, NIST 800-53, PCI DSS (Payment Card Industry Data Security Standards), DMCA, FERPA, GLBA, HIPAA, , etc. Responsibilities include cybersecurity reviews, risk assessments, risk management, data management, policies/standards and guidelines, cybersecurity awareness and training, audit coordination and project management.
Security Operations, Risk Management and Compliance
-
Specifically, this position reviews, coordinates and monitors information technology security controls that protect confidentiality, integrity and availability of the organization’s controlled secure research data in accordance with contractual, legal, regulatory and institutional requirements. The position is responsible for ensuring that users with access to secure research data receive appropriate training.
The position consults with faculty/researchers, college/unit IT staff, applicable OIT staff, applicable Office of Research and Innovation (ORI) staff, and other subject matter experts to ensure technology solutions and compliance standards are in line with contract requirements. Moreover, the position will ensure appropriate auditing and documentation, providing guidance and recommendations to the research community in areas of data security, from award negotiation through project close-out.
This position will work closely with ORI Sponsored Programs & Regulatory Compliance to assist with monitoring the secure research environment setups, conducting follow-up reviews, and ensuring contract terms and conditions are in line with NC State standards for data security. This position serves as the formal Information Systems Security Manager (ISSM) for the university’s Secure University Research Environment (SURE), which is the university’s C3PAO CMMC Level 2 certified environment.
The overall duties are as follows:
- Serve as the bridge between IT, information security and research requirements
- Lead the maintenance and growth of the existing NIST 800-171 security and compliance program, especially in the research context.
- Assist OIT, ORI and campus stakeholders on maintaining compliance with CMMC 2.0 level 1 and 2
- Serve as the SURE Information Systems Security Manager (ISSM)
- Assist the ISRA staff with processing cybersecurity requests, such as ITPC items that require a security review / risk assessment
- Explore opportunities for the use of AI and their impacts on cybersecurity, data usage and compliance
- Participate in programs to improve the university’s cybersecurity awareness and outreach
- Assist the ISRA staff with GRC project strategies, project tasks and testing of the service
- Assist in the enhancement of existing PRRs and and the construction of needed procedures across OIT and campus IT
This position involves access to information, items, or technology controlled under the International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR). To comply with federal export control laws, candidates must be a “U.S. Person” as defined by 22 C.F.R. § 120.62 (e.g., U.S. Citizen, U.S. Lawful Permanent Resident / Green Card Holder, Refuged or Asylee status under 8 U.S.C. 1324b(a)(3)).