Back to jobs
University of Arizona Police Department

Information Security Analyst, Senior

USPosted 4 days ago
onsite

Job Description

Cybersecurity Framework Alignment and Program Documentation Ensure the University’s enterprise security program maintains documented, defensible alignment with recognized cybersecurity frameworks. Lead ongoing alignment with NIST SP 800-53 Revision 5, monitor framework updates, and assess their applicability to University systems and processes. Maintain and manage crosswalks and mappings to additional regulatory and sponsor-driven frameworks, including CMMC, GLBA, HIPAA, NSF RIG, FDA Part 11, SCF, and emerging cybersecurity requirements. Research Cybersecurity Assurance Develop, maintain, and continuously improve cybersecurity assurance programs that demonstrate the maturity and adequacy of security controls supporting University research activities. Collaborate directly with Principal Investigators (PIs), research staff, and system administrators to ensure research workflows, systems, and data environments meet University baseline security standards and specific sponsor or regulatory cybersecurity requirements. Serve as a subject matter expert supporting inquiries related to research cybersecurity. GLBA Compliance Program Management In partnership with the University’s Qualified Individual (QI) and senior leadership through the GLBA Compliance Governance Committee, design, implement, and maintain the University’s comprehensive Written Information Security Program (WISP). Ensure the program includes appropriate administrative, technical, and physical safeguards to protect customer information. Support governance, risk management, documentation, and reporting activities to demonstrate ongoing GLBA compliance. Vendor and Contract Security Oversight Develop, implement, and sustain a University-wide vendor and contract security strategy to manage third‑party cybersecurity risk. Work closely with Supply Chain Services and the Office of Research Contracts Agreements to ensure downstream vendor security controls meet institutional requirements and upstream sponsor obligations are met. Provide strategic guidance on security-related contract language, review third‑party security documentation (e.g., SOC reports), and offer advisory services during contract negotiations and vendor management. Knowledge, Skills and Abilities: Knowledge of cybersecurity risk management frameworks, including NIST SP 800-53, and their application in large, complex organizations. Knowledge of regulatory and compliance requirements such as GLBA, HIPAA, CMMC, and research sponsor cybersecurity expectations (e.g., NSF, FDA). Knowledge of third‑party risk management concepts and vendor security assessment practices. Knowledge of research computing environments and the unique cybersecurity risks associated with academic research. Skill in developing and maintaining cybersecurity policies, standards, and formal program documentation. Skill in analyzing and mapping security controls across multiple regulatory and industry frameworks. Skill in reviewing contracts and third‑party security reports (e.g., SOC 2) and providing risk‑based recommendations. Skill in facilitating cross‑functional collaboration among technical staff, researchers, legal, procurement, and executive stakeholders. Ability to communicate complex cybersecurity and compliance concepts clearly to both technical and non‑technical audiences. Ability to handle confidential and sensitive information with discretion and professionalism. Ability to balance regulatory compliance, security risk, and operational needs in a research‑intensive academic environment. Ability to work independently, exercise sound judgment, and influence outcomes without direct authority.

See Your Match Score

Sign up and Renata will show you how this job matches your skills and experience.

Information Security Analyst, Senior at University of Arizona Police Department | Renata