Information Security Assessment and Analysis Team Lead

Apply now Search #: 499811
Work type: Full-time
Location: UConn Storrs
Categories: Information Technology

JOB SUMMARY

Under the general direction of the Chief Information Security Officer, the Information Security Assessment and Analysis Team Lead is responsible for leading the University's Security Assessment and Security Analysis programs in support of the University of Connecticut Information Security Office.

The Information Security Assessment and Analysis Team Lead works regularly with other senior members of the Information Security Office and serves as a member of the CISO's senior leadership team.

This position serves in a dual capacity as both a technical subject matter expert and the supervisor of a functional team. The incumbent provides strategic and operational leadership for the University's security assessment; vulnerability management; cyber security program reviews; governance, risk, and compliance; vendor risk management; and data security programs while actively participating in complex security assessments, technical reviews, and enterprise risk analysis. This position currently has three direct FTE reports, with team growth envisioned, as well as oversight of student workers.

The Security Assessment and Analysis Team Lead manages a multidisciplinary team of cybersecurity professionals responsible for Vulnerability Management; Security Policy, Risk, and Compliance; Application and Systems Security; Data Security; Third-Party Risk Management; and Security Assessments. The function and nature of the team is expected to evolve and keep pace with the changing technology and threat landscape. The team is designed to grow over time to include Cloud Security and Artificial Intelligence Security functions.

The Team Lead establishes strategic direction, operational priorities, standards, assessment methodologies, and technical guidance that improve the University's overall security posture across academic, research, and administrative environments.

The Team Lead collaborates closely with University leadership, Information Technology Services, Enterprise Applications, Research IT, Enterprise Infrastructure, Counsel, Compliance, Privacy, Internal Audit, Procurement, Research Compliance, and other stakeholders to integrate cybersecurity risk management throughout the institution.

The Security Assessment and Analysis Team Lead is responsible for continuously improving the University's cybersecurity maturity through comprehensive security assessments, governance, risk management, vulnerability management, technical standards development, and staff development.

SALARY

  • Information Security Assessment and Analysis Team Lead (Information Technology Team Lead 2 – UCP 7): $95,066 to $123,585

Note: All minimum qualifications must be met to be eligible for consideration. Salary will be commensurate with experience within the established range.

BENEFITS INCLUDE

  • Defined contribution with employer match or defined benefit program retirement options
  • Excellent and affordable healthcare options
  • 35 hour work week
  • 22 paid vacation days per year
  • Paid sick leave
  • 13 paid holidays
  • Employee and dependent tuition waiver programs
  • A highly desirable work environment and work-life balance

DUTIES AND RESPONSIBILITIES

Leadership and Program Management

  • Lead the University's Information Security Assessment and Security Analysis programs under the oversight of the Chief Information Security Officer.
  • Direct day-to-day operations of the Information Security Assessment and Analysis Team, including prioritization of work, workload management, coaching, mentoring, performance management, and career development.
  • Develop strategic roadmaps for security assessment, governance, risk management, vulnerability management, application security, data security, and third-party risk.
  • Serve as the University's senior technical authority for security assessment methodologies and cybersecurity risk analysis.
  • Participate as a member of the CISO's senior leadership team in establishing strategic direction for the Information Security Office.
  • Develop staffing plans and future organizational capabilities, including expansion into emerging disciplines such as AI Security and Cloud Security.

Information Security Assessment

  • Lead enterprise security assessments of infrastructure, applications, cloud services, research environments, and business processes.
  • Develop and maintain assessment methodologies, technical standards, security baselines, and review procedures.
  • Conduct or oversee security reviews for enterprise technology initiatives.
  • Review security implications of new technologies, enterprise platforms, and major IT projects.

Vulnerability Management

  • Oversee staff operating, and individually participate in, the University's enterprise vulnerability management program.
  • Establish vulnerability assessment methodologies, remediation priorities, and enterprise reporting.
  • Develop metrics and dashboards measuring organizational vulnerability reduction and remediation effectiveness.
  • Oversee the coordination of remediation activities with infrastructure, application, research, cloud, and distributed IT teams.

Policy, Risk and Compliance

  • Oversee staff developing, and individually participate in development of,  cybersecurity governance, policy development, risk management, and compliance activities.
  • Oversee the development and maintenance of University information security policies, standards, procedures, and guidelines.
  • Oversee staff operating the exception management processes. Apply standardized risk tolerance and acceptance criterial to exception requests, evaluate and recommend exception criteria for novel or unique justifiable business use cases.
  • Coordinate security compliance efforts supporting FERPA, HIPAA, PCI DSS, CMMC, NIST 800-171, CJIS, GLBA, research security requirements, and other applicable regulations.
  • Support audits, assessments, and regulatory reviews.

Application and Systems Security

  • Oversee staff conducting, and individually participate in, application security assessments, secure code development initiatives, penetration testing coordination, and secure SDLC guidance.
  • Collaborate with development teams to integrate security through-out software development lifecycles.

Data Security

  • Oversee data security initiatives including data classification, protection, encryption, data loss prevention, and secure handling of sensitive institutional information.
  • Develop security strategies to protect regulated information, research data, and institutional intellectual property.

Third Party Risk Management

  • Oversee staff conducting, and individually participate in, security assessments of vendors, cloud providers, research collaborators, and third-party service providers.
  • Develop third-party security assessment standards and risk evaluation methodologies.
  • Coordinate procurement security reviews and vendor remediation activities.

Strategic Leadership

  • Develop enterprise cybersecurity metrics, dashboards, executive reports, and key performance indicators.
  • Evaluate emerging technologies, security tools, and vendor solutions.
  • Develop long-term improvement plans aligned with University strategic objectives.
  • Maintain awareness of evolving threats, vulnerabilities, technologies, regulations, and industry best practices.
  • Represent the Information Security Office on institutional committees and strategic initiatives.
  • Participate in after-hours incident response and operational escalations as required.
  • Other related duties as assigned.

RELATED SKILLS AND COMPETENCIES

  • Leadership - Demonstrates the ability to lead, motivate, coach, and develop highly skilled technical professionals. Creates a collaborative, service-oriented culture focused on operational excellence and continuous improvement.
  • Security Assessment Expertise - Demonstrates expert knowledge of: Security architecture; Risk assessment; Vulnerability management; Application security; Cloud security; Data security; Governance, Risk, and Compliance (GRC); Third-party risk management; Enterprise cybersecurity frameworks.
  • Strategic Thinking - Develops long-term security strategies, evaluates emerging technologies, aligns cybersecurity initiatives with institutional priorities, and balances security with business objectives.
  • Communication - Communicates effectively with executive leadership, technical teams, auditors, researchers, faculty, legal counsel, vendors, and external partners. Produces clear technical documentation and executive-level reporting.
  • Project Management - Plans and manages multiple strategic initiatives while balancing operational responsibilities and organizational priorities.
  • Physical Demands - This position involves extended periods of sitting and extensive use of computers and office equipment.

MINIMUM QUALIFICATIONS

  1. Must meet and maintain eligibility requirements to work with CUI/CTI data, as determined by the Facility Security Officer and the Office of Export Control.
  2. Bachelor's degree and six (6) years of related experience in information security or information technology; OR Associate's degree and eight (8) years of related experience; OR ten (10) years of related experience.
  3. Four (4) or more years of experience must be specifically in security assessment, vulnerability management, governance/risk/compliance, application security, or related cybersecurity disciplines.
  4. One or more years of experience leading or supervising a technical cybersecurity team or serving as a technical team lead supervising direct reports.
  5. Demonstrated experience conducting enterprise security assessments and cybersecurity risk analyses.
  6. Demonstrated Experience with vulnerability management platforms and enterprise vulnerability assessment, prioritization, and remediation methodologies.
  7. Demonstrated Experience developing security policies, standards, procedures, and governance documentation.
  8. Demonstrated Experience supporting enterprise compliance initiatives involving frameworks and standards such as NIST CSF, NIST 800-53, NIST 800-171, CIS Controls, ISO 27001, PCI DSS, HIPAA, FERPA, CJIS, CMMC, or comparable standards.
  9. Experience performing vendor security assessments and third-party risk analysis.
  10. Demonstrated experience in the management, evaluation, and development of cyber security professional team members.
  11. Demonstrated leadership, analytical, organizational, communication, and project management skills.

PREFERRED QUALIFICATIONS

  1. Master's degree in Cybersecurity, Computer Science, Information Assurance, Information Systems or a related field.
  2. Experience leading enterprise Governance, Risk, and Compliance (GRC) programs.
  3. Experience in higher education information security.
  4. Experience with application security testing, secure software development, or DevSecOps.
  5. Experience with cloud security architecture and cloud governance.
  6. Experience operating, assessing, evaluating and documenting security exceptions.
  7. Experience implementing enterprise data protection and data governance initiatives.
  8. Experience supporting research security, export controls, and Controlled Unclassified Information (CUI) environments.
  9. Experience conducting executive cybersecurity risk reporting and board-level presentations.
  10. Experience developing enterprise security metrics and maturity models.
  11. Experience evaluating cybersecurity technologies and vendor solutions.
  12. CISSP, CISM, CRISC, CCSP, CSSLP, or comparable advanced cybersecurity certifications.

APPOINTMENT TERMS

This is a full-time, permanent position located at the Storrs Campus in Storrs, CT. The University offers a competitive salary, and outstanding benefits, including employee and dependent tuition waivers at UConn, and a highly desirable work environment.

This position is on-site. THIS IS NOT A REMOTE POSITION. The position may be eligible for a hybrid work schedule under applicable bargaining agreements, management approval, and not less than an annual review. This position may require you to travel in-state and you may be required to work irregular hours to support operational or security activities and initiatives.

Other rights, terms, and conditions of employment are contained in the collective bargaining agreement between the University of Connecticut and the University of Connecticut Professional Employees Association (UCPEA).

TERMS AND CONDITIONS OF EMPLOYMENT

Employment of the successful candidate is contingent upon the successful completion of a pre-employment criminal background check. The successful candidate must be determined to be and remain eligible to work with CUI/CTI data as determined by the Facility Security Officer and the Office of Export Control.

Employment of the successful candidate is contingent upon the successful completion of a pre-employment criminal background check.

TO APPLY

Please apply online at Faculty and Staff Positions, Search #4999811 to upload a resume, cover letter, and contact information for three (3) professional references. Applicants must clearly demonstrate how they meet the stated minimum qualifications, and any preferred qualifications they may possess, in their application materials.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire.

This job posting is scheduled to be removed at 11:55 p.m. Eastern time on September 11, 2026.

All employees are subject to adherence to the State Code of Ethics.

All members of the University of Connecticut are expected to exhibit appreciation of, and contribute to, an inclusive, respectful, and diverse environment for the University community.

The University of Connecticut aspires to create a community built on collaboration and belonging and has actively sought to create an inclusive culture within the workforce. The success of the University is dependent on the willingness of our diverse employee and student populations to share their rich perspectives and backgrounds in a respectful manner. This makes it essential for each member of our community to feel secure and welcomed and to thoroughly understand and believe that their ideas are respected by all. We strongly respect each individual employee’s unique experiences and perspectives and encourage all members of the community to do the same. All applicants will receive consideration for employment without regard to race, color, ethnicity, religion, age, sex, marital status, national origin, ancestry, sexual orientation, genetic information, physical or mental disabilities, veteran’s status, status as a victim of domestic violence and/or sexual assault and/or trafficking in persons as defined by Connecticut law, prior conviction of a crime, workplace hazards to the reproductive systems, or gender identity or expression.

The University of Connecticut is an AA/EEO employer including for Disability and Veteran status.

Advertised: Eastern Daylight Time
Applications close: Eastern Daylight Time

Back to search results Apply now Refer a friend