An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Carnegie Mellon University’s Information Security Office is seeking an IT Security Engineer to bolster incident response, forensics, and monitoring across a diverse university environment. You’ll analyze endpoint, network, and application data to determine impact, preserve evidence, and guide recovery with colleagues across admin, development, and research teams.
The role emphasizes curiosity, rigorous investigation, clear communication, and learning unfamiliar systems while applying strong
Carnegie Mellon University’s Information Security Office is seeking an IT Security Engineer to help investigate and respond to security incidents across a large, diverse, and technically complex university environment. This is a hands‑on security position with a strong focus on incident response, digital forensics, security monitoring, and technical investigation. You will use endpoint, network, application, identity, and other security data to determine what happened, understand the scope and impact of an incident, preserve and analyze evidence, contain threats, and help affected teams recover securely. The environment is broad, and investigations frequently involve unfamiliar systems or technologies. One incident may require analyzing an endpoint compromise, another may involve reconstructing activity from network traffic and logs, while another may require learning enough about an application, operating system, or protocol to understand unexpected behavior. You do not need to be an expert in every technology or security discipline described in this posting. We are looking for strong technical fundamentals, investigative ability, curiosity, sound judgment, clear communication, and the ability to learn unfamiliar systems when an investigation requires it. If you enjoy understanding how systems work beneath the surface, following evidence until you can explain what happened, considering systems from both attacker and defender perspectives, or building tools to answer questions that existing products cannot, you may be a strong fit for this team.
A significant portion of this position is dedicated to security incident response and digital forensics.
Direct professional experience in every area covered by this position is not required. Candidates with strong backgrounds in systems, networking, software, infrastructure, or other technical disciplines who can demonstrate security aptitude and investigative ability are encouraged to apply.
Professional certifications such as CISSP, GSEC, GCFE, or other security and technology certifications are welcomed but are not required.
Curiosity matters here. Strong candidates tend to want to understand why systems behave the way they do. They are comfortable starting with incomplete information, asking good questions, testing hypotheses, digging beneath product interfaces, and considering how a system might behave differently from what its designers intended. We value people who can combine that curiosity with careful technical reasoning and sound judgment. Security investigations may involve production systems, sensitive data, legal matters, or significant service impact, so creativity must be balanced with appropriate caution and communication. We also value engineers who look for ways to improve how work is performed. That may mean automating a repetitive task, creating a better investigative workflow, developing a small utility, integrating data from multiple systems, or identifying a more effective way to answer an investigative question. No security engineer knows every technology they will encounter. The ability to recognize a gap in your knowledge, research the problem, experiment appropriately, and apply what you learn is an important part of this role.
The IT Security Engineer plays an important role in the timely identification, containment, investigation, and prevention of computer and network security incidents. After an appropriate period of onboarding and training, the engineer is expected to independently handle routine investigations and operational responsibilities. This includes evaluating the severity of security alerts, selecting appropriate investigative techniques, recommending containment or remediation actions, and determining when an issue should be escalated. Significant incidents, sensitive data exposures, major service disruptions, legal matters, notification decisions, and other unusual or sensitive situations are handled collaboratively with senior staff, the Incident Response Coordinator, management, and other university stakeholders as appropriate.
This position participates in a shared 24x7 on-call rotation for security monitoring, incident response, and infrastructure support. On-call responsibilities may occasionally require work outside normal business hours or travel to campus. The position involves access to sensitive security, investigative, institutional, and potentially legally protected information. Appropriate judgment, discretion, and professionalism are essential. The successful candidate must qualify as a U.S. person under the applicable requirements governing this position. This position does not have formal supervisory responsibilities.
Continued learning is an expected part of the position. Engineers are encouraged to remain current with security technologies, attack techniques, investigative methods, vulnerabilities, and changes in the broader security community through technical research, training, conferences, professional communities, internal knowledge sharing, and independent experimentation.
Joining the CMU team opens the door to an array of exceptional benefits. Benefits eligible employees enjoy a wide array of benefits including comprehensive medical, prescription, dental, and vision insurance as well as a generous retirement savings program with employer contributions. Unlock your potential with tuition benefits, take well-deserved breaks with ample paid time off and observed holidays, and rest easy with life and accidental death and disability insurance. Additional perks include a free Pittsburgh Regional Transit bus pass, access to our Family Concierge Team to help navigate childcare needs, fitness center access, and much more!
Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran.
Pay Basis Salary
Location Pittsburgh, PA
Position Type Staff - Regular Full Time/Part time Full time
If you need assistance or a reasonable accommodation at any stage of the application, interview, or hiring process, please contact Equal Opportunity Services by email at employeeaccess@andrew.cmu.edu or by phone at 412-268-5072.