Lead Security Analyst, Research Computing: Office of Innovative Technologies - UTK

University of Tennessee, Knoxville

Knoxville (TN)

Hybrid

USD 100,000 - 110,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

University of Tennessee, Knoxville is seeking a Lead Security Analyst for Research Computing to oversee security operations, governance, and risk management within its research computing environments. The role partners with OIT, GRC, ORIED, researchers, and auditors to align with sponsor requirements and regulatory standards.

The position emphasizes leadership, incident response readiness, and the development of audit-ready security documentation while coordinating across multiple teams and

Qualifications

  • Bachelor's degree required in a relevant field.
  • 7+ years of relevant information security experience.
  • Knowledge of governance, frameworks, and risk assessment in research environments.
  • Familiarity with NIST 800-171, NIST 800-53, CMMC, HIPAA, FERPA, export controls.

Responsibilities

  • Provide leadership for the Research Computing Security team, including planning, direction, and performance management.
  • Lead projects to design, implement, and mature security controls across research computing environments.
  • Mentor team members on regulatory awareness, evidence quality, and security operations.

Skills

Security governance
Risk management
Compliance oversight
Security operations
Leadership
Stakeholder management
Regulatory awareness
Incident response

Education

Bachelor's degree in Computer Science, IT Management, IT Security, or related field

Job description

Job Description

The Lead Security Analyst - Research Computing is responsible for the operational delivery, governance, risk management, compliance, and assurance of cybersecurity services within the Office of Innovative Technologies' Research Computing environments. The role combines leadership, security operations, stakeholder management, and regulatory alignment. This role will work closely with OIT Security Operations, GRC, Office of Research Innovation & Economic Development (ORIED), researchers, faculty, auditors, and external stakeholders.

The role plans, builds, and implements appropriate security controls to protect against internal and external threats to OIT's research computing environments' information and assets. The role develops and maintains processes and procedures associated with security monitoring and uses cases to respond to potential security incidents and potential threats or attempts to compromise security controls. The role provides performance management and professional development for all members of the Research Computing Security team.

Responsibilities
Lead Research Computing Security Operations and Program Delivery
  • Provide leadership for the Research Computing Security team, including planning, direction, activity prioritization, performance management, and professional development.
  • Lead projects to design, implement, and mature security controls across research computing environments.
  • Mentor team members on regulatory awareness, evidence quality, customer-facing security operations, and research security best practices.
Drive Research Security Governance, Compliance, and Risk Management
  • Serve as a subject matter expert and trusted advisor to researchers, principal investigators, research computing staff, compliance partners, and central IT on research security matters.
  • Oversee compliance activities for sponsor, contractual, and regulatory frameworks such as NIST 800-171, NIST 800-53, CMMC, HIPAA, FERPA, and export control requirements.
  • Prepare and maintain artifacts for assessments, audits, attestations, and ongoing compliance reviews.
  • Stay current on emerging regulatory requirements and help evolve the research security program to meet changing expectations.
  • Direct and coordinate risk assessments, gap analyses, and periodic control reviews for research computing platforms, projects, and data environments.
  • Document findings, rate risk, recommend mitigation strategies, and support continuous monitoring and risk acceptance workflows.
  • Review contracts and agreements and provide guidance on export controls, sanctions, and research security compliance obligations.
  • Communicate requirements, assist with training and awareness, issue escalation, and reporting for research environments.
Strengthen Security Controls, Documentation, and Monitoring
  • Coordinate and validate the implementation of administrative, technical, and physical security controls for research computing environments handling controlled, restricted, or sensitive data.
  • Track remediation activities, exceptions, inherited controls, and supporting evidence with system owners and technical teams.
  • Maintain audit-ready security documentation, including system security plans, control narratives, procedures, implementation statements, inventories, diagrams, and plans of action and milestones.
  • Monitor, triage, and investigate security alerts affecting research computing systems and services.
Lead Incident Response Support and Readiness
  • Oversee escalation handling for security events affecting regulated research customers, ensuring timely, accurate, and compliant communications.
  • Serve as the subject matter expert for cybersecurity incident response activities within research computing environments.
  • Support cyber security incident response activities for other university departments, units, and colleges as needed.
  • Assist in the development of and participation in tabletop exercises and penetration testing activities.
Required Qualifications
  • Education: Bachelor’s degree in Computer Science, Information Technology Management, IT Security, or a related field.
  • Experience: Seven (7) years of relevant experience providing information security services for an organization of similar function and size.
  • Knowledge, Skills, and Abilities:
    • Extensive knowledge of cybersecurity governance, control frameworks, and risk assessment methodologies relevant to research environments.
    • Extensive knowledge of NIST 800-171, NIST 800-53, CMMC, HIPAA, FERPA, and common regulatory or sponsor requirements affecting research computing.
    • Skill in developing and maintaining control documentation, evidence repositories, diagrams, and audit-ready compliance artifacts.
    • Skill in analyzing technical and procedural controls, identifying gaps, and documenting practical risk mitigation plans.
    • Strong communication skills with the ability to clearly explain security requirements to researchers, technical staff, and non-technical stakeholders while managing multiple compliance efforts simultaneously.
    • Demonstrated ability to lead work, coordinate priorities, and contribute to security operations in complex, highly collaborative environments.

Applicants must be legally authorized to work in the United States on a full-time basis without need now or in the future for sponsorship for employment-based visa status.

Preferred Qualifications
  • Experience:
    • Ten (10) or more years of relevant experience providing information security services for an organization of similar function and size.
    • At least three (3) years of experience in a research computing environment.
    • Experience leading security or compliance efforts in higher education, research administration, or other regulated environments.
    • Relevant certifications such as Security+, CISSP, CISM, CISA, CGRC, or CAP
  • Knowledge, Skills, and Abilities:
    • Knowledge of higher education research administration, export control, and controlled unclassified information requirements.
    • Knowledge of cloud and hybrid research computing architectures, data classification, and secure enclave design.
    • Experience using governance, risk, and compliance tools, spreadsheets, and workflow systems to manage control status and POA&Ms.
    • Ability to interpret contract clauses and translate sponsor or regulatory requirements into operational security controls.
    • Knowledge with NIST 800-223
Work Location
  • Location: Knoxville, TN
  • Hybrid - successful candidate will be required to be onsite as necessary to complete job responsibilities and support incident response activities.
Compensation And Benefits
  • UT market range: MR16
  • Anticipated hiring range: $100,000 – $110,000
  • Find more information on the UT Market Range structure here
  • Find more information on UT Benefits here
About The Division

OIT is a centralized IT organization, which means many of the core technology services the university relies on are coordinated, supported, and managed through one central unit. Rather than each department building its own separate support structure, OIT helps unify technology operations so that students, faculty, and staff across the university have a consistent, reliable experience.

About Us

The University of Tennessee, Knoxville, has shaped leaders, changemakers, and innovative thinkers since its founding in 1794. The university is home to more than 38,000 students and 10,000 statewide employees—the Volunteers—who uphold the university’s tradition of lighting the way for others through leadership and service. UT Knoxville offers over 900 programs of study across 14 degree-granting colleges and schools. As Tennessee’s flagship land‑grant university, its footprint spans the entire state. The university holds the highest Carnegie classification for research activity and has deep partnerships with industry leaders and the US Department of Energy’s largest multidisciplinary laboratory, Oak Ridge National Laboratory. The Knoxville campus serves and recruits for UT Knoxville, including the Institute of Agriculture and the Space Institute, as well as the UT Institute of Public Service. UT Knoxville considers its employees its number one asset. With values that focus on work‑life balance, compensation, and innovation leadership, all Vols are supported to advance professionally. Employees have access to career development and coaching, continued education, and an extensive list of development and training possibilities. The Volunteer employee experience implements structures and practices to attract and retain top‑tier talent, fostering a strong staff community and supporting a culture of involvement and engagement for everyone. The university holds a strong commitment to its land‑grant mission of learning and engagement, with a tradition of service and leadership that carries that Volunteer spirit throughout the state and around the world. It has been ranked nationally as “Best Employer for New Graduates,” “One of America’s Best Large Employers,” and “Best Workplace for Women,” and has been designated as “Best Place for Working Parents” by Forbes Magazine.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

HPSC System Administrator: Office of Innovative Technologies - UTK
HPSC System Administrator: Office of Innovative Technologies - UTK

University of Tennessee, Knoxville • Knoxville (TN)

Hybrid
USD 95,000 - 105,000
Financial Assurance Officer - Office of Research, Innovation, & Economic Development - UTK
Financial Assurance Officer - Office of Research, Innovation, & Economic Development - UTK

University of Tennessee, Knoxville • Knoxville (TN)

On-site
USD 67,000 - 82,000
Research Computing Facilitator: National Institute for Computational Sciences - UTK
Research Computing Facilitator: National Institute for Computational Sciences - UTK

University of Tennessee, Knoxville • Knoxville (TN)

Hybrid
USD 90,000 - 110,000
Assistant Director of Assessment - Office of Student Success Analytics - UTK
Assistant Director of Assessment - Office of Student Success Analytics - UTK

University of Tennessee, Knoxville • Knoxville (TN)

On-site
USD 63,000 - 77,000
Senior IT Technician: Tickle College of Engineering - UTK
Senior IT Technician: Tickle College of Engineering - UTK

University of Tennessee, Knoxville • Knoxville (TN)

On-site
USD 55,000 - 60,000
Business Manager - Kinesiology, Recreation, and Sport Studies - UTK
Business Manager - Kinesiology, Recreation, and Sport Studies - UTK

University of Tennessee, Knoxville • Knoxville (TN)

On-site
USD 71,000 - 77,000
Financial Analyst: UT Space Institute
Financial Analyst: UT Space Institute

University of Tennessee, Knoxville • Tullahoma (TN)

Hybrid
USD 80,000 - 87,000
Data Analyst: Engineering Data Analytics - UTK
Data Analyst: Engineering Data Analytics - UTK

University of Tennessee, Knoxville • Knoxville (TN)

Hybrid
USD 85,000 - 95,000
Senior Financial Associate: Department of Chemical and Biomolecular Engineering - UTK
Senior Financial Associate: Department of Chemical and Biomolecular Engineering - UTK

University of Tennessee, Knoxville • Knoxville (TN)

On-site
USD 38,000 - 53,000
Help Desk Analyst: Office of Innovative Technologies - UTK
Help Desk Analyst: Office of Innovative Technologies - UTK

Knoxville Technology Council • Knoxville (TN)

Hybrid
USD 48,000 - 52,000