IT Security Engineer - Computing Services

Carnegie Mellon University

Pittsburgh (Allegheny County)

On-site

USD 90,000 - 130,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Carnegie Mellon University’s Information Security Office is seeking an IT Security Engineer to investigate and respond to security incidents across a large university environment. This hands-on role focuses on incident response, digital forensics, security monitoring, and technical investigation.

You will use endpoint, network, application, identity, and other data to determine what happened, preserve evidence, contain threats, and help teams recover securely while communicating findings clearly

Qualifications

  • Bachelor's degree or equivalent combination of education, training, and experience.
  • Three or more years of relevant technical experience in information security or related field.
  • Hands-on experience with major operating systems environments.

Responsibilities

  • Monitor and investigate security alerts across network, endpoint, and logs.
  • Triage security events and determine if they are incidents.
  • Conduct technical investigations using evidence from endpoints, networks, and applications.
  • Determine root cause, scope, timeline, and impact of incidents.
  • Perform or assist with forensic analysis on hosts and networks.
  • Identify affected assets and recommend containment and recovery actions.
  • Communicate findings clearly to technical and non-technical audiences.
  • Maintain investigation records and evidence custody.

Skills

Incident response
Digital forensics
Security monitoring
Technical investigation
Communication

Education

Bachelor's degree or equivalent

Job description

Carnegie Mellon University's Information Security Office is seeking an IT Security Engineer to help investigate and respond to security incidents across a large, diverse, and technically complex university environment.

This is a hands-on security position with a strong focus on incident response, digital forensics, security monitoring, and technical investigation . You will use endpoint, network, application, identity, and other security data to determine what happened, understand the scope and impact of an incident, preserve and analyze evidence, contain threats, and help affected teams recover securely.

The environment is broad, and investigations frequently involve unfamiliar systems or technologies. One incident may require analyzing an endpoint compromise, another may involve reconstructing activity from network traffic and logs, while another may require learning enough about an application, operating system, or protocol to understand unexpected behavior.

You do not need to be an expert in every technology or security discipline described in this posting. We are looking for strong technical fundamentals, investigative ability, curiosity, sound judgment, clear communication, and the ability to learn unfamiliar systems when an investigation requires it.

If you enjoy understanding how systems work beneath the surface, following evidence until you can explain what happened, considering systems from both attacker and defender perspectives, or building tools to answer questions that existing products cannot, you may be a strong fit for this team.

What You'll Do
  • Monitor and investigate alerts generated by network, endpoint, vulnerability, logging, and other security systems.
  • Triage reported or suspected security events and determine whether they represent security incidents.
  • Conduct technical investigations using endpoint artifacts, network traffic, system and application logs, identity information, and other available evidence.
  • Determine the likely root cause, scope, timeline, and impact of security incidents.
  • Perform or assist with host and network forensic analysis.
  • Identify affected systems, accounts, data, and infrastructure and recommend appropriate containment, eradication, and recovery actions.
  • Work directly with system administrators, network engineers, developers, application owners, researchers, and other members of the university community during investigations.
  • Clearly communicate technical findings, risk, and recommended actions to both technical and non-technical audiences.
  • Maintain accurate investigation records, evidence, timelines, findings, and incident documentation.
  • Collect and preserve digital evidence in support of security investigations and authorized legal matters.
  • Assist with E-Discovery, evidence preservation, chain-of-custody procedures, and other forensic requests when directed by university leadership or the Office of General Counsel.
  • Participate in a shared 24x7 on-call rotation supporting security monitoring, incident response, and security infrastructure.
The position also contributes to the broader work of the Information Security Office
  • Supporting vulnerability scanning and vulnerability management services.
  • Helping campus organizations understand and remediate security vulnerabilities.
  • Supporting endpoint security, endpoint detection and response, certificate authority, public key infrastructure, and data protection services.
  • Monitoring, configuring, evaluating, and improving systems used for security detection, investigation, assessment, and response.
  • Evaluating emerging vulnerabilities, attack techniques, and security threats for relevance to Carnegie Mellon's environment.
  • Conducting or assisting with authorized security assessments and penetration testing of systems, networks, applications, and services.
  • Providing security guidance and technical consulting to teams across the university.
  • Researching, testing, and recommending new security tools and techniques.
  • Developing scripts, utilities, integrations, or other automation that make investigations and security operations more effective.
  • Creating documentation, technical guidance, and security communications.
  • Participating in other Information Security Office projects as needed.
What We're Looking For

Minimum Qualifications:

  • Bachelor's degree or equivalent combination of education, technical training, professional certifications, and relevant experience.
  • Three or more years of relevant technical experience in information security, information technology, systems administration, networking, software engineering, infrastructure engineering, digital forensics, or a related technical discipline.
  • Hands-on experience with one or more major operating system environments such a
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Researcher
Senior Security Researcher

Carnegie Mellon University • Pittsburgh

On-site
USD 90,000 - 130,000
Medical insurance
Dental and vision
Tuition benefits
+2
Security Researcher
Security Researcher

Carnegie Mellon University • Pittsburgh

On-site
USD 110,000 - 160,000
Medical, dental, vision insurance
Retirement contributions
Tuition benefits
+3
Associate Security Researcher
Associate Security Researcher

The Chronicle Of Higher Education, Inc. • Pittsburgh

On-site
USD 90,000 - 120,000
Senior Cybersecurity Operations Researcher
Senior Cybersecurity Operations Researcher

Jobtailor • Pennsylvania

On-site
USD 120,000 - 180,000
Tuition benefits
Retirement contributions
Relocation assistance
+1
Security Engineer: Network Tools & Incident Response
Security Engineer: Network Tools & Incident Response

Carnegie Mellon University • Pittsburgh

On-site
USD 70,000 - 90,000
Comprehensive medical, dental, and vision insurance
Generous retirement savings program
Tuition benefits
+2
InfoSec Analyst/Engineer — Network Security & Incident Response
InfoSec Analyst/Engineer — Network Security & Incident Response

Pittsburgh Supercomputing Center • Pittsburgh

On-site
USD 70,000 - 90,000
IT Security Analyst/Engineer – 2024582
IT Security Analyst/Engineer – 2024582

Pittsburgh Supercomputing Center • Pittsburgh

On-site
USD 70,000 - 90,000
Senior Information Technology Security Analyst
Senior Information Technology Security Analyst

Jobtailor • Philadelphia

On-site
USD 110,000 - 160,000
Security Operations Specialist
Security Operations Specialist

The University of North Carolina • Charlotte (NC)

On-site
USD 90,000 - 120,000
Associate Security Researcher — Applied Cyber & Systems
Associate Security Researcher — Applied Cyber & Systems

The Chronicle Of Higher Education, Inc. • Pittsburgh

On-site
USD 90,000 - 120,000