Senior Research IT Security Risk & ComplianceAnalyst
will assess, document, and implement various controlsfor University research. This individual manages the controldocumentation and advises on best business practices for allstakeholders. The incumbent is responsible for managing processesrelated to the information security of regulated research, systemsaudit assistance, coordination, and support (e.g., internal auditfor information security). This requires familiarity with riskassessments, privacy regulations, standards, and sets of controls.The incumbent will have a well-rounded technical background inInformation Technology (IT). This includes and is not limited tosoftware development, DevSecOps, systems, IoT, help desk, riskmanagement, information security, and emerging technology such asagentic-AI.
Your core responsibilities will include:
- Audit Research IT systems and ensure established controls are being followed.
- Identify security findings and assist in driving risk items to closure with the correct stakeholders.
- Apply familiarity with risk assessments and common controlsets, including the Cybersecurity Maturity Model Certification(CMMC/NIST 800-171) and Health Insurance Portability andAccountability Act (HIPAA).
- Lead compliance projects involving multiple stakeholders within established deadlines.
- Manage the documentation and development of policies, guidance,and procedures related to research information security for theUniversity’s Information Security Office (ISO).
- Write, gather evidence, investigate existing processes andregulations, and implement best practices.
- Demonstrate quick learning and interest in the intersection ofinformation security, people, and the law.
- Maintain a strong understanding of the bridge between securityand research and pay close attention to detail.
- Partner with key internal campus stakeholders on processes andcontrols, including the Office of the Vice Provost for Research,University Libraries, and researchers.
- Use Microsoft Office Suite (for example, Word, Excel, andPowerPoint) and document-sharing tools such as Google Docs and Boxproficiently.
- Review third-party documentation to determine informationsecurity risk and communicate those risks to stakeholders.
- Communicate effectively in writing and orally with technical,end-user, and executive audiences, depending on the context.
- Interface with researchers to determine information securityrequirements and technical requirements, and help the researcherfind the appropriate environment.
- Create research specific training and documentation, includingSystem Security Plans, for regulated research.
- Lead continuous monitoring for specific IT systems, primarilyresearch.
- Assist with Security Operations related to specific IT systems, primarily research.
- Participate with Incident Response Coordinator to respond toincidents involving specific IT systems, primarily research.
- Other duties as assigned.
Physical and Mental Requirements:
- Adaptability and openness to change as the department andorganization evolves.
- Ability to work well with others and/or as part of ateam.
- Ability to work with sensitive information, maintainconfidentiality and use discretion.
- Ability to pay close attention to detail; keep and maintainaccurate and detailed reports and records.
- Ability to maintain composure when dealing with difficultsituations and/or individuals.
- Ability to meet deadlines, work under pressure and withfrequent interruptions.
- Ability to understand and follow directions.
- Ability to prioritize work and handle multiple taskssimultaneously.
- Visual acuity to perform activities such as extended use of acomputer monitor, extensive reading
Decision Making:
- Decisions generally affect own job or specific functionalarea.
- Decisions may affect a work unit or department. Job maycontribute to business and operational decisions.
- Decisions have implications on management and operations of aunit or department. Job may contribute to important strategy,operation and business decisions.
Working Conditions:
- Required to work normal business hours; evening and weekendwork may occasionally be required.
Accountability:
- Accountable for the successful completion of individual goalsand priorities.
Direction:
- Receives little instruction on day-to-day work and receivesgeneral instructions on new assignments.
- Establishes methods and procedures for attaining specific goalsand objectives, and receives guidance in terms of broadgoals.
Flexibility, excellence, and passion are vital qualities withinComputing Services. Inclusion, collaboration, and culturalsensitivity are valued competencies at CMU. Therefore, we are insearch of a team member who is able to effectively interact with avaried population of internal and external partners at a high levelof integrity. We are looking for someone who shares our values andwho will support the mission of the university through theirwork.
Qualifications:
- Bachelor’s Degree
- 5-7 Years of experience working with researchers and regulateddata
A combination of education and relevant experience from whichcomparable knowledge is demonstrated may be considered.
Certifications:
- Passed the CMMC Certified Professional (CCP) exam or able to doso within the first 3 months of employment
Requirements:
- Successful background check
Joining the CMU team opens the door to an array of exceptionalbenefits.
Benefits eligible employees enjoy a wide array of benefits, including:
- comprehensive medical, prescription, dental, andvision insurance
- retirement savings program with employercontributions
- tuition benefits
- paid time off
- holidays
- life and accidentaldeath and disability insurance
Additional perks include:
- free Pittsburgh Regional Transit buspass
- Family Concierge Team to help navigatechildcare needs
- fitness center access
For a comprehensive overview of the benefits available, exploreour Benefits page.
At Carnegie Mellon, we value the whole package when extendingoffers of employment. Beyond credentials, we evaluate the role andresponsibilities, your valuable work experience, and the knowledgegained through education and training. We appreciate your uniqueskills and the perspective you bring. Your journey with us is aboutmore than just a job; it’s about finding the perfect fit for yourprofessional growth and personal aspirations.
Location
Pittsburgh, PA
Job Function
Security
Position Type
Staff – Regular
Full Time/Part time
Full time
Pay Basis
More Information:
- Please visit “ Why Carnegie Mellon ” to learn more
- Click here to view a listing of employee benefits
- Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran .
- Statement of Assurance