Senior Lead, Cybersecurity Policy & Compliance
![]() | |
![]() | |
![]() United States, Colorado, Boulder | |
![]() | |
Job Description Summary:Reporting to the Chief Information Officer and serving on the IT Senior Leadership Team, the Senior Lead for Cybersecurity Policy and Compliance ("Senior Lead") will serve as the organization's leading subject matter expert on cybersecurity. The successful candidate will be responsible for maintaining a cybersecurity policy that is flexible enough to meet the demands of a national research center, but concrete enough to provide enforceable, actionable guidance to all the organization's staff, including administrative staff, educators, researchers, IT staff, and others.
The Senior Lead is responsible for developing, implementing, managing, and evolving the organization's cybersecurity policies, standards, guidelines, and procedures. This individual will ensure adherence to relevant laws, regulations, industry standards, organizational policies, funder requirements, and internal requirements. The Senior Lead will provide expert guidance on compliance matters and drive the maturity of the cybersecurity compliance program, working in collaboration with the organization's Research Security program, Office of General Counsel, and Contracts Office. This role requires a deep understanding of federal cybersecurity frameworks and regulatory landscapes. The Senior Lead must be able to translate complex technical requirements into clear policies, take firm action with respect to compliance, and ensure that those actions do not disrupt research, educational, operational activities, and/or other mission-facing activities. In addition to policy and compliance responsibilities, the Senior Lead will direct a small team that manages specific cybersecurity-related services and programs such as audit preparation & response, vendor security & privacy assessments, data preservation, cybersecurity aspects of legal holds, annual cybersecurity training, phishing simulation, and related cybersecurity services and programs. Critically, the Senior Lead will serve as the point person for all cybersecurity incident responses, working closely with the Cybersecurity Operations group, which reports separately into UCAR's IT Operations unit. During any incident response situations, the Senior Lead will be expected to coordinate and direct the activities of the Cybersecurity Operations group, serving as a temporary matrixed manager for the duration of the incident. Position Details: Visa Sponsored Job: NoRelocation Assistance Eligible: YesJob Location: Boulder, ColoradoPosition Type & Term: Full time, RegularCompensation Range: Salary Range: $137,229 - $171,537* *Final salary and rates are based on education, experience, skills relevant to the role. Application NotesJob Location: Boulder, Colorado Job Type: Hybrid, 3 days/week minimum requirement in Boulder office Position Type & Term: Full-Time, Regular Application Deadline: This position will be posted until 11:59 PM MT on Sunday, November 9, 2025. Required application materials: (preferably uploaded as a PDF):
Background Checks: Conducted for candidates selected for hire. Learn more. Here is a brief summary of what one would expect to be generally responsible for in this role. Key Responsibilities: Policy & Standard Development:
Compliance Management:
Advisory & Consultation:
Program Maturity & Governance:
Risk Management Integration:
Stakeholder Engagement:
Team Leadership & Mentorship:
Successful candidates will ensure their application materials speak to the following criteria: (Required):
Knowledge, Skills, and Abilities Desired:
Desired but not Required Certifications:
Risk based position: A pre-employment screening is conducted in conjunction with an offer for employment. This screening may involve verifying or reviewing any of the following relevant information: restricted parties screening, employment verification, performance records of internal candidates, education verification, reference checks, verification of professional licenses, certifications, and Motor Vehicle Records. UCAR complies with the Fair Credit Reporting Act (FCRA). Benefits OverviewUCAR affirms its commitment to employees through competitive benefits. In addition to medical, dental, vision, retirement, and life insurance, UCAR offers a variety of programs focused on work-life balance and professional, and personal development. These include:
Applicants are not required to provide age or age-related information and may redact information related to age, date of birth, or dates of attendance at or graduation from an educational institution from any submissions during the initial application process. Some Final ConsiderationsAt NSF NCAR| UCAR | UCP, you will work alongside a dedicated team of professionals conducting critical research and community outreach to solve complex Earth system science problems including climate change, air pollution, extreme weather, floods, drought, wildfires, and space weather, all with the goal of improving human life and reducing economic loss. Each of us, from scientists to the professionals who support their work, serves the public and a collaborative community of scientists in our mission to understand the complex processes that make up the Earth system, from the ocean floor to the Sun's core. Flexible Work At UCAR, we are committed to supporting our mission by giving staff the flexibility to find the schedule and location that works best to maintain their own work-life circumstances and reach their full potential as professionals. Many positions within our organization are eligible for fully on-site, hybrid (three days per week) and/or flexible work hours. Equal Opportunity Employer UCAR is committed to providing equal opportunity for all employees and applicants for employment and does not discriminate on the basis of race, age, creed, color, religion, national origin or ancestry, sex, gender, disability, veteran status, genetic information, sexual orientation, gender identity or expression, or pregnancy.Whatever your intersection of identities, you are welcome at UCAR. Export Control All positions are required to comply with U.S. export compliance regulations and work location requirements regarding access to facilities and research systems. Work Location UCAR requires ALL positions to be performed within the U.S., excluding U.S. Territories. AI Software ChatGPT and similar AI software are powerful tools that are changing theway society receives, processes, and leverages information promptly. While we acknowledge its benefits and do not restrict leveraging it with job applications, we highly encourage a majority of the applicant material to be original work. |