Research Information Security & Compliance Manager
Listed on 2026-06-26
-
IT/Tech
Cybersecurity, Information Security, IT Consultant
Position Number: 004509
Department: Div of Research (Adm)
Employment Type: Permanent - Full-time
Months Per Year: 12
Essential Duties and ResponsibilitiesThe Research Information Security & Compliance Manager reports to the Assistant Vice Chancellor for Research Protections and Integrity in the Division of Research. This position ensures the university's compliance with federal law, state government statutes, university system standards, and UNC Charlotte's internal policies, regulations, procedures, and contractual obligations in the area of information security and privacy. Appropriate frameworks, policies, regulations, guidelines, procedures, and assurance processes are developed for security, privacy, and protection of the university's information assets, including research data.
The overall duties are as follows:
- UNC Charlotte Data Sensitivity Framework
- UNC System Security Framework/Baseline based on ISO 27001/2:2013
- NIST Cybersecurity Framework and Special Publications series 800 (e.g., 800-53, 800-171)
- Cybersecurity Maturity Model Certification (CMMC) Framework
- FISMA (Federal Information Security Management Act of 2002)
- HIPAA (Health Insurance Portability and Accountability Act of 1996);
- European GDPR (General Data Protection Regulation)
- Applicable State and Federal Laws/Regulations
- Supervise and assist temporary staff or graduate assistants as needed.
- Performs other duties as assigned
Bachelor's degree with two years of related experience, or an equivalent combination of education/experience.
Preferred Education Skills and Experience Education & Experience- Bachelor's degree in CS, IT, Engineering, or a related technical field.
- 2+ years in information security, ideally within an academic research environment.
- CISSP or GIAC certifications preferred; SANS or vendor-specific security certifications are a plus.
- Proficiency with EDR, IDS/IPS, vulnerability scanners, anti-malware, forensics, and SIEM technology (e.g., Splunk).
- Practical experience with Cloud (AWS, Azure, GCP), on-premise, and hybrid environments.
- Expertise in advanced firewalls, encryption, and workstation security.
- Skilled in security risk assessments, penetration testing, and incident tracking/remediation.
- Strong knowledge of NIST 800-171, NIST 800-53, and CMMC compliance.
- Familiarity with state government rules and regulations regarding data security.
- Proven ability to develop security solutions and provide technical advice to diverse stakeholders (faculty, IT, and administration).
- Experience implementing cross-functional security solutions in a team environment.
- Strong technical writing skills for procedural documentation and the ability to present complex info to non-technical audiences.
- Advanced troubleshooting abilities and a strict commitment to maintaining confidentiality.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).