Mid Level Security Researcher Jobs
Mid level security researcher jobs go to professionals ready to own vulnerability assessments end to end, mentor junior analysts, and drive security decisions with limited oversight. Roles run across 25% remote and hybrid settings in Technology & Software, Education, and Agriculture & Farming, with employers like NVIDIA, Pensar, and CrowdStrike competing for researchers at this level now.
Find JobsOverview
Showing 5 of 6+ Mid Level Security Researcher jobs











Posting Information
Posting Number PG194797EP
Internal Recruitment No
Working Title Research Security Specialist
Anticipated Hiring Range $130,000 - $150,000
Work Schedule 8:00 am - 5:00 pm; with additional hours as needed; on-call rotation is required
Job Location Raleigh, NC
Department Security & Compliance
About the Department
The Security & Compliance Unit (S&C) within the Office of Information Technology (OIT) oversees the cybersecurity of the University’s systems and data in a manner consistent with industry best practices and the University’s IT compliance and IT risk management obligations. S&C develops and ensures compliance with cybersecurity policies/regulations/procedures, supports and oversees implementation of strategic information security initiatives, provides operational security services, and provides campus-wide vendor risk and license management. S&C is also the functional lead for the university’s identity and access management program.
The Information Security Risk and Assurance (ISRA) team within the Office of Information Technology (OIT) Security & Compliance unit is a central point for managing university cyber, data, IT risk and compliance activities, such as but not limited to: DMCA, FERPA, GLBA, HEOA, HIPAA, ISO 27002, NC ID Theft Act, PCI-DSS, NIST 800-171, Red Flags Rule. The team assists with IT strategic planning and cybersecurity service development and is primarily responsible for the implementation, guidance and maintenance of the following services:
- Security Consulting and Education
- Data Management
- IT Risk Management
- Security Awareness and Training
- Security Liaison Team Program Management
- Security Policy and Compliance
- Data/System Access Reviews
- Internal & External OIT Audit Coordination
- Litigation Holds/eDiscovery and Records Retention
- Research Data Security Consultation & Evaluation
- Security Compliance Program Development, Management and Continuous Assessment
- Security Policy, Regulations, Rules, and SOP Development
- Identity & Access Management Data Steward
- Strategic and Tactical Planning
- Business Analyst for IAM services (SAR, Password Self-Service, OIM, etc.)
Wolfpack Perks and Benefits
As a Pack member, you belong here, and can enjoy exclusive perks designed to enhance your personal and professional well-being. As you consider this opportunity, we encourage you to review our Employee Value Proposition and learn more about what makes NC State the best place to learn and work for everyone.
What we offer:
- Medical, Dental, and Vision
- Flexible Spending Account
- Retirement Programs
- Disability Plans
- Life Insurance
- Accident Plan
- Paid Time Off and Other Leave Programs
- 12 Holidays Each Year
- Tuition and Academic Assistance
- And so much more!
Attain Work-life balance with our Childcare benefits, Wellness & Recreation Membership, and Wellness Programs that aim to build a thriving wolfpack community.
Disclaimer: Perks and Benefit eligibility is based on Part-Time or Full-Time Employment status. Eligibility and Employer Sponsored Plans can be found within each of the links offered.
Essential Job Duties
Professional Knowledge
The IT Security Professional provides technical implementations and daily monitoring of the university’s complex IT environment in accordance with best practices and standards such as NIST 800-171, CMMC, CUI, NIST 800-53, PCI DSS (Payment Card Industry Data Security Standards), DMCA, FERPA, GLBA, HIPAA, etc. Responsibilities include cybersecurity reviews, risk assessments, risk management, data management, policies/standards and guidelines, cybersecurity awareness and training, audit coordination and project management.
Security Operations, Risk Management and Compliance
Specifically, this position reviews, coordinates and monitors information technology security controls that protect confidentiality, integrity and availability of the organization’s controlled secure research data in accordance with contractual, legal, regulatory and institutional requirements. The position is responsible for ensuring that users with access to secure research data receive appropriate training.
The position consults with faculty/researchers, college/unit IT staff, applicable OIT staff, applicable Office of Research and Innovation (ORI) staff, and other subject matter experts to ensure technology solutions and compliance standards are in line with contract requirements. Moreover, the position will ensure appropriate auditing and documentation, providing guidance and recommendations to the research community in areas of data security, from award negotiation through project close-out.
This position will work closely with ORI Sponsored Programs & Regulatory Compliance to assist with monitoring the secure research environment setups, conducting follow-up reviews, and ensuring contract terms and conditions are in line with NC State standards for data security. This position serves as the formal Information Systems Security Manager (ISSM) for the university’s Secure University Research Environment (SURE), which is the university’s C3PAO CMMC Level 2 certified environment.
The overall duties are as follows:
- Serve as the bridge between IT, information security and research requirements
- Lead the maintenance and growth of the existing NIST 800-171 security and compliance program, especially in the research context.
- Assist OIT, ORI and campus stakeholders on maintaining compliance with CMMC 2.0 level 1 and 2
- Serve as the SURE Information Systems Security Manager (ISSM)
- Assist the ISRA staff with processing cybersecurity requests, such as ITPC items that require a security review / risk assessment
- Explore opportunities for the use of AI and their impacts on cybersecurity, data usage and compliance
- Participate in programs to improve the university’s cybersecurity awareness and outreach
- Assist the ISRA staff with GRC project strategies, project tasks and testing of the service
- Assist in the enhancement of existing PRRs and the construction of needed procedures across OIT and campus IT
This position involves access to information, items, or technology controlled under the International Traffic in Arms Regulations (ITAR) or Export Administration Regulations (EAR). To comply with federal export control laws, candidates must be a “U.S. Person” as defined by 22 C.F.R. § 120.62 (e.g., U.S. Citizen, U.S. Lawful Permanent Resident / Green Card Holder, Refuged or Asylee status under 8 U.S.C. 1324b(a)(3)).
Other Responsibilities
- Other duties will be assigned as needed.
Qualifications
Minimum Education and Experience
- A minimum of 5 years of cybersecurity or related information technology skills (IT risk management, information auditor, etc.)
- Graduation from an accredited four-year college or university with a major in information technology, computer science, a closely related field, or equivalent years of experience.
Other Required Qualifications
- Strong experience with implementing security controls in one or more of the following areas:
+ Network administration
+ System administration
+ Software development
+ Cybersecurity administration
- Advanced understanding of technical IT security controls relating to the university network, servers, workstations, cloud services and other end user devices.
- Knowledge and an awareness of the key attributes of applicable federal regulations, state laws, and other external requirements and their impact on cybersecurity, privacy and compliance such as the following:
+ FERPA – Family Education Rights and Privacy Act
+ GLBA – Gramm-Leach-Bliley Act
+ HIPAA – Health Insurance Portability and Accountability Act of 1996
+ ISO/IEC 27000 series – International Organization for Standardization & International Electrotechnical Commission
+ NIST FIPS PUB 800-53 and 800-171 – National Institute of Standards & Technology
+ FAR/DFARs/CMMC (Federal and Defense Federal Acquisition Regulation Supplement, Cybersecurity Maturity Model Certification)
+ PCI/DSS – Payment Card Industry Data Security Standard
+ FTC (Federal Trade Commission) Red Flags Rule
+ SSAE16 (Statement on Auditing Standards No. 70) and SOC 1 & 2 (Service Organization Controls)
+ HEOA – Higher Education Opportunity Act
+ DMCA – Digital Millennium Copyright Act
- Ability to interpret various hardware, software, procedural, and policy manuals and other technical and complex documentation
- Advanced experience working with System Security Plans (SSPs) and Plan of Actions and Milestones (POAMs)
- Advanced experience conducting risk/security assessments, particularly of cloud service vendors
- Proven ability to enhance and/or implement an enterprise-wide cybersecurity education and awareness program
- Effective communication skills with various types of audiences such as research administration, compliance, faculty; IT support; information security team members
- Experience working as an effective team member and team lead
- Experience in project management methodologies.
Preferred Qualifications
- Five (5) or more years of experience in the information security field.
- In-depth knowledge of cybersecurity principles, information auditing principles, cybersecurity policy and compliance and IT risk management
- Experience in cybersecurity and data governance practices within an academic environment.
- Experience working with data classification systems and implementing solutions to track and monitor the respective classifications and any relevant compliance obligations.
- Strong technical writing skills and experience with the development of business, technical and procedural documentation.
- Detailed knowledge of NIST 800-171, NIST 800-53, and CMMC.
- Strong working knowledge of IT standards and IT related internal control frameworks (such as NIST, ISO/IEC, COBIT, etc.)
- Strong working knowledge of federal, state government laws and regulations.
- Experience using ServiceNow or a similar call tracking system and providing Tier 1 customer support.
- Advanced troubleshooting skills.
- Familiarity in the use of tools to improve security such as anti-malware, EDR, vulnerability assessments and remediation, intrusion detection and prevention systems (IDS/IPS), log monitoring/correlation, security incident tracking, internal and external penetration testing, forensics, advanced firewall and other network protection, endpoint workstation security protection, cloud technology or encryption.
- Experience in developing and implementing strategies and/or solutions to address security issues and providing administrative, physical and technical security advice to various clients
- Experience conducting and managing IT risk assessments and providing IT risk advisory services
- ISACA, ISC2 or GIAC certification is preferred
- Other SANS or vendor specific certifications in security topics are a plus.
Required License(s) or Certification(s)
N/A
Valid NC Driver's License required No
Commercial Driver's License required No
Recruitment Dates and Special Instructions
Job Open Date 08/07/2026
Anticipated Close Date Open until filled
Special Instructions to Applicants
Please attach a resume and cover letter.
Position Details
Position Number 00107248
Position Type EPS/SAAO
Full Time Equivalent (FTE) (1.0 = 40 hours/week) 1.0
Appointment 12 Month Recurring
Mandatory Designation - Adverse Weather Non Mandatory - Adverse Weather
Mandatory Designation - Emergency Events Non Mandatory - Emergency Event
Department ID 511001 - Security & Compliance
EEO
NC State University is an equal opportunity employer. All qualified applicants will receive equal opportunities for employment without regard to age, color, disability, gender identity, genetic information, national origin, race, religion, sex (including pregnancy), sexual orientation, and veteran status. The University encourages all qualified applicants, including protected veterans and individuals with disabilities, to apply. Individuals with disabilities requiring disability-related accommodations in the application and interview process are welcome to contact 919-513-0574 to speak with a representative of the Office of Equal Opportunity.
If you have general questions about the application process, you may contact Human Resources at (919) 515-2135 or workatncstate@ncsu.edu.
Final candidates are subject to criminal & sex offender background checks. Some vacancies also require credit or motor vehicle checks. Degree(s) must be obtained prior to start date in order to meet qualifications and receive credit.
NC State University participates in E-Verify. Federal law requires all employers to verify the identity and employment eligibility of all persons hired to work in the United States.
See All 6 Mid Level Security Researcher Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsMid Level Security Researcher Job Market
Who's Hiring



Top Industries Hiring
- Technology & Software
- Education
- Agriculture & Farming
Mid Level Security Researcher Jobs: Frequently Asked Questions
How do I get a mid level security researcher job?
Position your experience around ownership and impact, not just task completion. Highlight specific vulnerabilities you discovered, tools you built or improved, and any findings that influenced a security decision. Hiring managers at this level want to see that you can operate independently, communicate risk clearly to non-technical stakeholders, and deliver results without close supervision. Concrete examples from past work carry far more weight than certifications alone.
Which companies hire mid level security researchers?
Companies hiring mid level security researchers right now include NVIDIA, Pensar, and CrowdStrike, based on current listings on Migrate Mate as of August 2026. Hiring at this level covers large technology firms, defense contractors, financial institutions, and managed security service providers, all of which maintain dedicated research functions and need experienced professionals who can work independently on complex threat analysis.
Are there remote mid level security researcher jobs?
Yes, remote and hybrid options are common at this level because security research work is largely computer-based and output-driven. About 25% of mid level security researcher openings are remote or hybrid as of August 2026, reflecting how widely distributed security teams have become across industries. On-site roles still exist, particularly in defense, government contracting, and regulated financial environments where data handling requirements apply.
How do I move up to a mid level security researcher role?
The path from entry level to mid level in security research is built on progressive ownership. Early on, focus on mastering one technical domain such as malware analysis, penetration testing, or vulnerability research, then take on projects where you are accountable for the full finding, not just a single task. Demonstrating measurable impact, whether a critical bug discovered or a process you improved, and showing you can work without step-by-step guidance signals readiness for mid level responsibilities.
Which industries hire the most mid level security researchers?
Mid Level security researcher roles concentrate in Technology & Software, Education, and Agriculture & Farming, based on current listings on Migrate Mate as of August 2026. These sectors drive hiring at this level because they manage high-value data, face persistent threat actors, and require researchers with enough experience to independently assess complex attack surfaces and contribute to defensive strategy without heavy direction.