Salary : See Position Description
Location : Honolulu, HI
Job Type : Full-Time Permanent
Job Number : 2025-02011
Department : Information Technology Services System
Division : Office of the VP for Information Technology and Chief Information Officer
Opening Date : 09 / 18 / 2025
Closing Date : 10 / 9 / 2025 11 : 59 PM Hawaii
Position Number : : 0077441
Description
Title : Security Administrator / Information Security Specialist
Position Number : 0077441
Hiring Unit : Administration, Info Tec Svc, OVPIT
Location : UH System Offices, Manoa Campus
Date Posted : September 18, 2025
Closing Date : October 9, 2025
Band : B
Salary : salary schedules and placement information
Full Time / Part Time : Full Time
Month : 11-month
Temporary / Permanent : Permanent
DUTIES & RESPONSIBILITIES (
- denotes essential functions) :
- As a member of the UH Information Security Team, develops, implements & maintains the system-wide information security program that supports research, academic & administrative use of IT resources in a distributed / decentralized computing environment.
- Responsible for compliance related to federal / state / local / external regulations / laws / standards such as but not limited to the DOD Cybersecurity Maturity Model Certification program, GDPR, PCI-DSS, HIPAA, FERPA, NIST 800-171, HRS 487N, HRS 92F & UH policies / procedures across the UH system.
- Serves as a subject matter expert on regulatory / legal / compliance requirements related to information security.
- Develop & maintain information security awareness materials including development of web pages, video / audio recordings, managed instructional materials in a learning management system (e.g. Brightspace); includes providing materials / training for targeted audiences in face-to-face and distance-delivered environments (e.g. compliance training programs for specific regulations, specific training for functional areas, etc.).
- Actively promotes security awareness among university faculty, staff and students.
- Responsible for the evaluation, development, implementation, and enforcement of information security policies, standards, procedures, guidelines, and best practices with primary focus on regulatory / legal / compliance requirements.
- Provides general guidance, technical advice, problem-solving assistance, and answers to questions regarding the information security program, policies, standards and procedures.
- Identifies potential compliance vulnerabilities & risk; develops / implements corrective action plans for resolution of issues.
- Performs quantitative, qualitative, and compliance risk and vulnerability assessments to identify deficiencies in security and compliance requirements; develops and implements (or oversees implementation of) remediation plans as appropriate.
- Provides risk assessment reports to senior staff on the operation and progress of compliance efforts.
- Performs remote and on-site vulnerability scans of data networks and computing devices using commercial or open-source vulnerability scanning tools, and reviews reports for threats and vulnerabilities; reports findings to appropriate staff; monitors remediation efforts; summarizes findings & generates reports on a regular basis for senior staff.
- Participates in emergency situations, security incident response and investigations, including those involving policy and regulatory violations. Handles legal requests and provides remediation support as necessary.
- Evaluates and recommends security-related technologies as needed to address new security deficiencies and threats.
- Reviews the work of and provides input and guidance on laws, rules, regulations and policy and other areas of expertise to other security team members; monitors, reviews and directs subordinates and student assistants as necessary.
- Continuously monitors security trends, the security threat landscape, technological developments and emerging practices in the IT industry and higher education.
- Develop and coordinate 'security-themed' events such as informational fairs, workshops, conferences including identifying and scheduling of location venues, speakers, etc.
- Perform other related duties as directed by senior information security staff, Chief Information Security Officer, VP IT & CIO, AVP IT & Deputy CIO, General Counsel and / or other UH system administrators.
- Other Duties as Assigned.
MINIMUM QUALIFICATIONS
Possession of a pertinent baccalaureate educational degree in Information & Computer Sciences, Information Assurance, IT with an emphasis in information security / information assurance or related field and 5 years of progressively responsible professional information technology experience with responsibilities for Information Security of which 2 years of the experience must have been comparable in scope and complexity to the next lower payband in the University of Hawai'i broadband system; or any equivalent combination of education and / or professional work experience which provides the required education, knowledge, skills and abilities as indicated.Considerable working knowledge of information security as demonstrated by the broad knowledge and understanding of the full range of pertinent standard and evolving information technology concepts, principles and methodologies.Considerable working knowledge and understanding of the broad technology, systems, hardware and software associated with information security.Demonstrated ability to recognize a wide range of intricate problems, use reasoning and logic to determine accurate causes, and apply principles and practices to determine, evaluate, integrate, and implement practical and thorough solutions in an effective and timely manner.Demonstrated ability to interpret and present information and ideas clearly and accurately in writing, verbally and by preparation of reports and other materials.Demonstrated ability to establish and maintain effective working relationships with internal and external organizations, groups, team leaders and members, and individuals.Demonstrated ability to lead subordinates, manage work priorities and projects, and manage employee relations.Considerable knowledge of information security current practices and threat landscape.Considerable knowledge of current information security technologies and tools.Considerable knowledge of security incident responseConsiderable working knowledge of computer forensics and investigative techniquesConsiderable knowledge of information security related frameworks as it applies to higher education.Considerable knowledge of international, federal, state and local laws, rules, and regulations related to information security, privacy, and higher education.Functional knowledge of a scripting or programming language used to develop open source tools.Demonstrated ability to configure, administer, and manage systems and network hardware as related to information security.Demonstrated ability to combine and apply skill sets from many areas of IT.Demonstrated ability to speak, read, comprehend, interpret and write fluently in English.Demonstrated ability to establish and maintain effective working relationships in a positive, service-oriented manner with others.Demonstrated ability to work cooperatively with leadership, supervisor, project staff, and customers in a team environment to accomplish tasks and meet deadlines.Demonstrated ability to understand and follow oral and written instructions and documentation, write reports and procedures, and communicate effectively in a variety of situations.Demonstrated ability to learn and apply new technologies independently and in a timely manner using books, manuals, online research, and other resources.Demonstrated ability to develop effective training materials.Demonstrated ability to conduct effective in-person or virtual training / workshops.Working knowledge of HTML / CSS.Working knowledge of common Internet protocols and applications.Working knowledge of TCP / IP protocols and analysis.Ability to review and provide relevant input for work products from other security team members, subordinates, and student assistants.Ability to manage multiple projects.Ability to work a variable work schedule; and work outside normally scheduled work hours including day, night, weekend and / or holiday hours as directed.DESIRABLE QUALIFICATIONS
Prior cybersecurity experience in or with higher education.Experience with various industry-recognized cybersecurity frameworks.Experience with vulnerability scanning tools.Experience with a SIEM (Security Incident & Event Management) toolCertifications related to the information security area (CISSP, GIAC / GSEC, CISM, etc.)Experience as an administrator of Active Directory environments.TO APPLY :
Click on the "Apply" button on the top right corner of the screen to complete an application and attached required documents.
Note : If you have not previously applied for a position using NeoGov, you will need to create an account.
Applicants must submit the following :
Cover letter to the selection committee indicating interest in the position and how the minimum and desirable qualifications are met,Resume,The names and contact information (telephone number and email addresses) of at least three (3) professional references, andCopies of educational transcripts are acceptable; however, original official transcripts will be required at time of hire. Diplomas and copies will NOT be accepted. Transcripts issued from an institution outside of the United States of America (USA) require a course-by-course analysis with an equivalency statement from an agency having membership with the National Association of Credential Evaluation Services, Inc., verifying the degree equivalency to that of an accredited institution within the USA. Expense of the evaluation shall be borne by the applicant.Late or incomplete applications will not be considered. The application will be considered incomplete if any of the required documents / materials are not included or are unreadable.
Please redact references to social security numbers and birthdate on submitted documents.
Employment may be contingent on verification of credentials and other background information, including the completion of a criminal history check.
Inquiries :
(808) 956-9098, itsadmin@hawaii.edu
EEO, Clery Act, ADA
The University of Hawai'i is an Equal Opportunity Institution and is committed to a policy of nondiscrimination in employment, including on the basis of veteran and disability status. For more information, visit :
Employment is contingent on satisfying employment eligibility verification requirements of the Immigration Reform and Control Act of 1986; reference checks of previous employers; and for certain positions, criminal history record checks.
In accordance with the Jeanne Clery Disclosure of Campus Security Policy and Campus Crime Statistics Act, annual campus crime statistics for the University of Hawai'i may be viewed at : , or a paper copy may be obtained upon request from the respective UH Campus Security or Administrative Services Office.
In accordance with Article 10 of the unit 08 collective bargaining agreement, bargaining unit members receive priority consideration for APT job vacancies. As a result, external or non BU 08 applicants may not be considered for some APT vacancies. BU 08 members with re-employment rights or priority status are responsible for informing the hiring unit of their status.
Accommodation Request : The University of Hawai'i complies with the provisions of the Americans with Disabilities Act (ADA). Applicants requiring a reasonable accommodation for any part of the application and hiring process should contact the EEO coordinator directly. Determination on requests for reasonable accommodation will be made on a case-by-case basis. For further information, please refer to the following link :