... NIST, HITRUST, ISO 27001, and other applicable frameworks. • Oversee enterprise risk assessments, third-party risk management, and control effectiveness evaluations. • Translate regulatory, legal ...
... NIST, HITRUST, ISO 27001, and other applicable frameworks. • Oversee enterprise risk assessments, third-party risk management, and control effectiveness evaluations. • Translate regulatory, legal ...
Cloud Security Engineer
Dover, DE · On-site
A deep understanding of NIST 800-207 and Zero Trust Architecture best practices is essential, along with hands-on experience with ZTNA technologies, particularly Zscaler. Cloud Platform Expertise:
Cloud Security Engineer
Dover, DE · On-site
A deep understanding of NIST 800-207 and Zero Trust Architecture best practices is essential, along with hands-on experience with ZTNA technologies, particularly Zscaler. Cloud Platform Expertise:
Senior Security Engineer(Zero-Trust Expertise)
Dover, DE · On-site
$90K - $124K/yr
A deep understanding of NIST 800-207 and Zero Trust Architecture best practices is essential, along with hands-on experience with ZTNA technologies, particularly Zscaler. Cloud Platform Expertise:
Senior Security Engineer(Zero-Trust Expertise)
Dover, DE · On-site
$90K - $124K/yr
A deep understanding of NIST 800-207 and Zero Trust Architecture best practices is essential, along with hands-on experience with ZTNA technologies, particularly Zscaler. Cloud Platform Expertise:
NIST-800 or FISMA (nice to have) federal audit readiness, federal it audit, enterprise risk, and federal continuous monitoring DUTIES * Provide high quality, professional day-to-day execution of ...
Quick apply
NIST-800 or FISMA (nice to have) federal audit readiness, federal it audit, enterprise risk, and federal continuous monitoring DUTIES * Provide high quality, professional day-to-day execution of ...
Required : • Experience with Product feature development and delivery in Cloud environments. • Understanding of NIST and FIDO Standards as they impact credential structure, delivery and customer ...
Required : • Experience with Product feature development and delivery in Cloud environments. • Understanding of NIST and FIDO Standards as they impact credential structure, delivery and customer ...
Principal Security Architect
$127K - $235K/yr
Experience in regulated environments and familiarity with NIST, ISO 27001, or similar frameworks. Education Requirement Bachelor's degree in Computer Science, Information Security, or related ...
Principal Security Architect
$127K - $235K/yr
Experience in regulated environments and familiarity with NIST, ISO 27001, or similar frameworks. Education Requirement Bachelor's degree in Computer Science, Information Security, or related ...
Principal Security Architect
Wilmington, DE · On-site
$127K - $235K/yr
... NIST, ISO 27001, or similar frameworks. Education Requirement • Bachelor's degree in Computer Science, Information Security, or related discipline, or equivalent experience. Additional Company ...
Principal Security Architect
Wilmington, DE · On-site
$127K - $235K/yr
... NIST, ISO 27001, or similar frameworks. Education Requirement • Bachelor's degree in Computer Science, Information Security, or related discipline, or equivalent experience. Additional Company ...
Principal Security Architect
Wilmington, DE · On-site
$127K - $235K/yr
... NIST, ISO 27001, or similar frameworks. Education Requirement • Bachelor's degree in Computer Science, Information Security, or related discipline, or equivalent experience. The company offers a ...
Principal Security Architect
Wilmington, DE · On-site
$127K - $235K/yr
... NIST, ISO 27001, or similar frameworks. Education Requirement • Bachelor's degree in Computer Science, Information Security, or related discipline, or equivalent experience. The company offers a ...
Business Process Red Team Operator
$152K - $260K/yr
... NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents * Excellent communication, collaboration, and report writing skills, with the ability to influence and ...
Business Process Red Team Operator
$152K - $260K/yr
... NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents * Excellent communication, collaboration, and report writing skills, with the ability to influence and ...
Information Technology Specialist (DATAMGT)
Georgetown, DE · On-site
$125K/yr
Experience applying federal AI guidelines, including EO 13960, NIST AI RMF, and OMB standards, ensuring privacy and accountability in protecting taxpayer data. * Experience communicating technical ...
Information Technology Specialist (DATAMGT)
Georgetown, DE · On-site
$125K/yr
Experience applying federal AI guidelines, including EO 13960, NIST AI RMF, and OMB standards, ensuring privacy and accountability in protecting taxpayer data. * Experience communicating technical ...
Information Technology Specialist (DATAMGT)
Newark, DE · On-site
$125K/yr
Experience applying federal AI guidelines, including EO 13960, NIST AI RMF, and OMB standards, ensuring privacy and accountability in protecting taxpayer data. * Experience communicating technical ...
Information Technology Specialist (DATAMGT)
Newark, DE · On-site
$125K/yr
Experience applying federal AI guidelines, including EO 13960, NIST AI RMF, and OMB standards, ensuring privacy and accountability in protecting taxpayer data. * Experience communicating technical ...
Information Technology Specialist (DATAMGT)
Dover, DE · On-site
$125K/yr
Experience applying federal AI guidelines, including EO 13960, NIST AI RMF, and OMB standards, ensuring privacy and accountability in protecting taxpayer data. * Experience communicating technical ...
Information Technology Specialist (DATAMGT)
Dover, DE · On-site
$125K/yr
Experience applying federal AI guidelines, including EO 13960, NIST AI RMF, and OMB standards, ensuring privacy and accountability in protecting taxpayer data. * Experience communicating technical ...
Strong understanding of technology control frameworks and industry standards such as NIST, COBIT, ITIL, ISO 27001, CSA CCM, or equivalent. * Experience developing policies, standards, control ...
Strong understanding of technology control frameworks and industry standards such as NIST, COBIT, ITIL, ISO 27001, CSA CCM, or equivalent. * Experience developing policies, standards, control ...
Familiarity of the regulatory landscape (NCUA, GLBA, FFIEC, NIST). * Strong understanding of TCP/IP, VLANs, routing fundamentals; Firewall policy management; Endpoint security tools (EDR); Patch ...
Familiarity of the regulatory landscape (NCUA, GLBA, FFIEC, NIST). * Strong understanding of TCP/IP, VLANs, routing fundamentals; Firewall policy management; Endpoint security tools (EDR); Patch ...
Information Technology Specialist (DATAMGT)
Georgetown, DE · On-site
$125K/yr
Experience applying federal AI guidelines, including EO 13960, NIST AI RMF, and OMB standards, ensuring privacy and accountability in protecting taxpayer data. * Experience communicating technical ...
Information Technology Specialist (DATAMGT)
Georgetown, DE · On-site
$125K/yr
Experience applying federal AI guidelines, including EO 13960, NIST AI RMF, and OMB standards, ensuring privacy and accountability in protecting taxpayer data. * Experience communicating technical ...
Establish and maintain security policies, standards, procedures, and control frameworks aligned with NIST, HITRUST, ISO 27001, and other applicable frameworks. * Oversee enterprise risk assessments ...
Establish and maintain security policies, standards, procedures, and control frameworks aligned with NIST, HITRUST, ISO 27001, and other applicable frameworks. * Oversee enterprise risk assessments ...
Information Technology Specialist (DATAMGT)
Dover, DE · On-site
$125K/yr
Experience applying federal AI guidelines, including EO 13960, NIST AI RMF, and OMB standards, ensuring privacy and accountability in protecting taxpayer data. * Experience communicating technical ...
Information Technology Specialist (DATAMGT)
Dover, DE · On-site
$125K/yr
Experience applying federal AI guidelines, including EO 13960, NIST AI RMF, and OMB standards, ensuring privacy and accountability in protecting taxpayer data. * Experience communicating technical ...
IT Infrastructure/Security Engineer
Dover, DE · On-site
$142K/yr
Familiarity of the regulatory landscape (NCUA, GLBA, FFIEC, NIST). * Strong understanding of TCP/IP, VLANs, routing fundamentals; Firewall policy management; Endpoint security tools (EDR); Patch ...
IT Infrastructure/Security Engineer
Dover, DE · On-site
$142K/yr
Familiarity of the regulatory landscape (NCUA, GLBA, FFIEC, NIST). * Strong understanding of TCP/IP, VLANs, routing fundamentals; Firewall policy management; Endpoint security tools (EDR); Patch ...
Evaluate controls supporting compliance with relevant regulations, standards, and frameworks (e.g., GDPR, ISO 27001, DORA, NIST, and other regional supervisory expectations). Cybersecurity ...
Evaluate controls supporting compliance with relevant regulations, standards, and frameworks (e.g., GDPR, ISO 27001, DORA, NIST, and other regional supervisory expectations). Cybersecurity ...
Business Process Red Team Operator
Wilmington, DE · On-site
$152K - $260K/yr
... NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents * Excellent communication, collaboration, and report writing skills, with the ability to influence and ...
Business Process Red Team Operator
Wilmington, DE · On-site
$152K - $260K/yr
... NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents * Excellent communication, collaboration, and report writing skills, with the ability to influence and ...
Nist information
See Delaware salary details
$43K - $52.8K
1% of jobs
$52.8K - $62.5K
6% of jobs
$62.5K - $72.2K
10% of jobs
$78.9K is the 25th percentile. Wages below this are outliers.
$72.2K - $82K
12% of jobs
$82K - $91.7K
15% of jobs
The median wage is $95.9K / yr.
$91.7K - $101.5K
15% of jobs
$101.5K - $111.2K
10% of jobs
$115.4K is the 75th percentile. Wages above this are outliers.
$111.2K - $120.9K
16% of jobs
$120.9K - $130.7K
7% of jobs
$130.7K - $140.4K
5% of jobs
$140.4K - $150.1K
3% of jobs
$43K
$99.5K
$150.1K
How much do nist jobs pay per year?
What are NIST professionals and what do they do?
What are the key skills and qualifications needed to thrive as a NIST (National Institute of Standards and Technology) professional, and why are they important?
What are some common challenges faced by NIST cybersecurity professionals when implementing new security frameworks in an organization?
What is the difference between Nist vs Cybersecurity Analyst?
| Aspect | Nist | Cybersecurity Analyst |
|---|---|---|
| Certifications | Typically no specific certifications required, but familiarity with NIST frameworks is essential | Often requires certifications like CompTIA Security+, CISSP, or CEH |
| Work Environment | Develops and maintains cybersecurity standards and frameworks for organizations | Monitors, analyzes, and responds to security threats within organizations |
| Industry Usage | Used across industries for cybersecurity best practices and compliance | Employed in various sectors to protect information systems |
| Primary Focus | Creating and implementing cybersecurity standards based on NIST guidelines | Detecting and mitigating security incidents and vulnerabilities |
While NIST focuses on developing cybersecurity standards and frameworks, a Cybersecurity Analyst applies these standards in practical security operations. Both roles are essential in maintaining organizational cybersecurity, with NIST providing the foundational guidelines and the analyst executing security measures based on those guidelines.

Full-time
Re-posted 5 days ago
University Of Delaware rating
5.7
Based on 21 frontline employees who took The Breakroom Quiz
577th of 613 rated colleges and universities
Job description
The University of Delaware is seeking a Director of GRC and Security Architecture to lead the organization's information security risk, compliance, and architectural security posture. This senior leadership role involves overseeing the enterprise-wide governance, risk management, and security architecture, ensuring compliance with regulations such as HIPAA while partnering with various teams to implement effective security controls.
Responsibilities:
• Lead the enterprise Information Security Governance, Risk, and Compliance (GRC) program.
• Establish and maintain security policies, standards, procedures, and control frameworks aligned with NIST, HITRUST, ISO 27001, and other applicable frameworks.
• Oversee enterprise risk assessments, third-party risk management, and control effectiveness evaluations.
• Translate regulatory, legal, and contractual requirements into actionable security controls and architectural standards.
• Ensure ongoing compliance with applicable regulations and standards, including HIPAA, PCI DSS, FERPA, SOC 2, and FIPS-140, as applicable
• Serve as the organization’s designated HIPAA Security Officer.
• Oversee administrative, technical, and physical safeguards required under the HIPAA Security Rule.
• Partner with Privacy, Legal, Compliance, and Health IT leadership on risk analyses, remediation plans, and regulatory inquiries.
• Support audits, investigations, and compliance reviews related to protected health information (PHI).
• Ensure appropriate security awareness and HIPAA training programs are developed and delivered across the organization.
• Own and lead the security architecture function, defining enterprise security architecture principles, reference architectures, and design standards.
• Review and approve security architecture for new systems, applications, cloud services, and major technology initiatives.
• Ensure security is embedded early in system lifecycle activities through secure-by-design and defense-in-depth principles.
• Partner with infrastructure, cloud, application, and DevOps teams to integrate security requirements into platforms and solutions.
• Guide architectural decisions related to identity, network segmentation, encryption, key management, logging, and data protection.
• Contribute to and lead multi-year security strategy and roadmap development in alignment with organizational objectives.
• Actively participate in enterprise security and risk governance forums, advising executive leadership on risk posture and architectural trade-offs.
• Balance risk reduction with operational efficiency, usability, and institutional mission requirements.
• Serve as a trusted advisor to schools, departments, and business units on risk and architectural security decisions.
• Provide governance and oversight for security technologies supporting risk management, compliance, and architectural controls.
• Ensure alignment between security architecture standards and operational security tooling.
• Evaluate new security technologies and frameworks to address evolving regulatory and threat landscapes.
• Develop and report meaningful risk and compliance metrics to senior leadership and governance committees.
• Communicate complex security and compliance topics clearly to technical and non-technical stakeholders.
• Provide executive-level reporting on risk trends, compliance posture, and architectural maturity.
• Lead and develop GRC and security architecture professionals.
• Establish clear role definitions, performance expectations, and professional development pathways.
• Foster a culture of accountability, continuous improvement, and collaboration across security and IT teams.
• Manage budgets associated with GRC, compliance, and security architecture programs.
• Oversee vendor relationships related to risk management, compliance tooling, and architectural services.
• Ensure responsible financial stewardship and alignment with strategic priorities.
Qualifications:
Required:
• Bachelor’s degree in Information Security, Computer Science, Information Systems, or a related field
• Seven years of progressive experience in information security, risk management, or IT, including leadership roles
• Demonstrated experience leading GRC programs, regulatory compliance efforts, and enterprise risk management
• Strong knowledge of HIPAA Security Rule, PCI DSS, and related regulatory frameworks
• Proven experience defining and governing security architecture across enterprise and cloud environments
• Excellent written and verbal communication skills, including executive-level presentations
Preferred:
• Master’s degree in Information Security, Computer Science, Information Systems, or a related field
• Experience supporting healthcare, higher education, or regulated enterprise environments
• Hands-on experience with NIST, HITRUST CSF, ISO 27001, SOC 2, and third-party risk frameworks
• Professional certifications such as CISSP, CISM, CRISC, or equivalent
• Experience partnering closely with SOC, IR, Privacy, and Legal teams
• Demonstrated success leading organizational change and maturing security governance programs
Company:
The University of Delaware is a private-public research university located in Newark, Delaware. UD is the largest university in Delaware Founded in 1743, the company is headquartered in Newark, USA, with a team of 1001-5000 employees. The company is currently Late Stage.
What University Of Delaware employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About University of Delaware
Sourced by ZipRecruiter
Industry
Colleges, universities, and professional schools
Company size
1,001 - 5,000 Employees
Headquarters location
Newark, DE, US
Year founded
1743