Hiring.Camp

Sr. Research IT Security Risk and Compliance Analyst - Computing Services

Careers @ Carnegie Mellon

·

Today

Location
Pittsburgh, United States of America
Type
Full-time
Department
Education
Experience
5+ years
Source
Workday

Description

The Senior Research IT Security Risk & Compliance Analyst will assess, document, and implement various controls for University research. This individual manages the control documentation and advises on best business practices for all stakeholders. The incumbent is responsible for managing processes related to the information security of regulated research, systems audit assistance, coordination, and support (e.g., internal audit for information security). This requires familiarity with risk assessments, privacy regulations, standards, and sets of controls. The incumbent will have a well-rounded technical background in Information Technology (IT). This includes and is not limited to software development, DevSecOps, systems, IoT, help desk, risk management, information security, and emerging technology such as agentic-AI.

Your core responsibilities will include:

  • Audit Research IT systems and ensure established controls are being followed.

  • Identify security findings and assist in driving risk items to closure with the correct stakeholders.

  • Apply familiarity with risk assessments and common control sets, including the Cybersecurity Maturity Model Certification (CMMC/NIST 800-171) and Health Insurance Portability and Accountability Act (HIPAA).

  • Lead compliance projects involving multiple stakeholders within established deadlines.

  • Manage the documentation and development of policies, guidance, and procedures related to research information security for the University’s Information Security Office (ISO).

  • Write, gather evidence, investigate existing processes and regulations, and implement best practices.

  • Demonstrate quick learning and interest in the intersection of information security, people, and the law.

  • Maintain a strong understanding of the bridge between security and research and pay close attention to detail.

  • Partner with key internal campus stakeholders on processes and controls, including the Office of the Vice Provost for Research, University Libraries, and researchers.

  • Use Microsoft Office Suite (for example, Word, Excel, and PowerPoint) and document-sharing tools such as Google Docs and Box proficiently.

  • Review third-party documentation to determine information security risk and communicate those risks to stakeholders.

  • Communicate effectively in writing and orally with technical, end-user, and executive audiences, depending on the context.

  • Interface with researchers to determine information security requirements and technical requirements, and help the researcher find the appropriate environment.

  • Create research specific training and documentation, including System Security Plans, for regulated research.

  • Lead continuous monitoring for specific IT systems, primarily research.

  • Assist with Security Operations related to specific IT systems, primarily research.

  • Participate with Incident Response Coordinator to respond to incidents involving specific IT systems, primarily research.

  • Other duties as assigned.

Physical and Mental Requirements:

  • Adaptability and openness to change as the department and organization evolves.

  • Ability to work well with others and/or as part of a team.

  • Ability to work with sensitive information, maintain confidentiality and use discretion.

  • Ability to pay close attention to detail; keep and maintain accurate and detailed reports and records.

  • Ability to maintain composure when dealing with difficult situations and/or individuals.

  • Ability to meet deadlines, work under pressure and with frequent interruptions.

  • Ability to understand and follow directions.

  • Ability to prioritize work and handle multiple tasks simultaneously.

  • Visual acuity to perform activities such as extended use of a computer monitor, extensive reading

Decision Making:

  • Decisions generally affect own job or specific functional area.

  • Decisions may affect a work unit or department. Job may contribute to business and operational decisions.

  • Decisions have implications on management and operations of a unit or department. Job may contribute to important strategy, operation and business decisions.

Working Conditions:

  • Required to work normal business hours; evening and weekend work may occasionally be required.

Accountability:

  • Accountable for the successful completion of individual goals and priorities.

Direction:

  • Receives little instruction on day-to-day work and receives general instructions on new assignments.

  • Establishes methods and procedures for attaining specific goals and objectives, and receives guidance in terms of broad goals.

Flexibility, excellence, and passion are vital qualities within Computing Services. Inclusion, collaboration, and cultural sensitivity are valued competencies at CMU. Therefore, we are in search of a team member who is able to effectively interact with a varied population of internal and external partners at a high level of integrity. We are looking for someone who shares our values and who will support the mission of the university through their work.

Qualifications:

  • Bachelor’s Degree

  • 5-7 Years of experience working with researchers and regulated data

A combination of education and relevant experience from which comparable knowledge is demonstrated may be considered.

Certifications:

  • Passed the CMMC Certified Professional (CCP) exam or able to do so within the first 3 months of employment

Requirements:

  • Successful background check

Are you interested in this exciting opportunity?! Apply today!

Joining the CMU team opens the door to an array of exceptional benefits.

Benefits eligible employees enjoy a wide array of benefits including comprehensive medical, prescription, dental, and vision insurance as well as a generous retirement savings program with employer contributions. Unlock your potential with tuition benefits, take well-deserved breaks with ample paid time off and observed holidays, and rest easy with life and accidental death and disability insurance. 

Additional perks include a free Pittsburgh Regional Transit bus pass, access to our Family Concierge Team to help navigate childcare needs, fitness center access, and much more!

For a comprehensive overview of the benefits available, explore our Benefits page.

At Carnegie Mellon, we value the whole package when extending offers of employment. Beyond credentials, we evaluate the role and responsibilities, your valuable work experience, and the knowledge gained through education and training. We appreciate your unique skills and the perspective you bring. Your journey with us is about more than just a job; it’s about finding the perfect fit for your professional growth and personal aspirations.

Are you interested in an exciting opportunity with an exceptional organization?! Apply today!

Location

Pittsburgh, PA

Job Function

Security

Position Type

Staff – Regular

Full Time/Part time

Full time

Pay Basis

More Information: 

  • Please visit Why Carnegie Mellonto learn more about becoming part of an institution inspiring innovations that change the world. 

  • Click here to view a listing of employee benefits

  • Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran

  • Statement of Assurance

Skills

ExcelCybersecurityRisk ManagementComplianceHIPAA

Similar Jobs

6

Sr. Support Analyst, Sales & Research, IT

Citicclsa · Hong Kong - One Pacific Place

2 weeks ago

Sr. Business Analyst, Research AI, IT

Citicclsa · Hong Kong - CITIC Tower

1 month ago

Multi- Asset Solutions (MAS) Data Specialist - Investment Research IT- Senior Manager

Statestreet · Bangalore, India

2 months ago

Sr Business Analyst, Research, IT

Citicclsa · Hong Kong - CITIC Tower

3 months ago

Senior IT Governance, Risk, and Compliance Analyst - Research Cybersecurity

Euv Emory · Atlanta, GA, US

1+ year ago

Senior IT Governance, Risk, and Compliance Analyst - Research Cybersecurity

Staff Emory · Atlanta, GA, US

1+ year ago