Senior Research IT Security Risk and Compliance Analyst

Carnegie Mellon University

Confirmed live today High trust

Quick summary

Work type
On-site
Location
Pittsburgh, PA
Employment
Full-time
Posted
5 days ago
Freshness
Confirmed live today

Market check

Salary context

How this pay compares to similar roles

Similar $153k
$105k $204k
below market most similar roles pay here above market

This listing doesn't post a salary. Most similar roles pay $123,954–$182,255.

Based on 240 similar postings.

Employer

About Carnegie Mellon University

Carnegie Mellon University is a leading private research university in Pittsburgh, Pennsylvania, internationally recognized for programs in computer science, engineering, business, the arts, and artificial intelligence. Industry: Higher Education & Research

Carnegie Mellon University currently has 71 open roles on FindRole.

Most-posted roles

View all roles at Carnegie Mellon University

At a glance

TL;DR · Senior Research IT Security Risk and Compliance Analyst

The Sr. Research IT Security Risk and Compliance Analyst joins the Computing Services team to assess, document, and implement controls for university research. This role involves managing information security for regulated research, assisting with systems audits, and leading compliance projects. The incumbent will audit research IT systems, identify security findings, and develop policies, guidance, and procedures for the Information Security Office. Key responsibilities include creating System Security Plans, performing continuous monitoring, and participating in incident response. The position requires a technical background in software development, DevSecOps, systems, IoT, and agentic-AI. Candidates must apply knowledge of CMMC/NIST 800-171 and HIPAA standards while using Microsoft Office Suite, Google Docs, and Box. The role solves the complex problem of bridging security requirements with diverse research environments and regulated data.

What you'll do

  • Audit research IT systems to ensure compliance with established security controls.
  • Identify security findings and drive risk items to closure with relevant stakeholders.
  • Apply risk assessments and control sets including CMMC, NIST 800-171, and HIPAA.
  • Manage the development of policies, guidance, and procedures for research information security.
  • Review third-party documentation to determine and communicate information security risks.
  • Create research-specific training and documentation, including System Security Plans.
  • Lead continuous monitoring and assist with security operations for research IT systems.
  • Participate with the Incident Response Coordinator to respond to incidents involving research systems.

What we're looking for

  • 5-7 years of experience working with researchers and regulated data.
  • Well-rounded technical background in IT, including software development, DevSecOps, systems, IoT, and risk management.
  • Familiarity with risk assessments and control sets including CMMC/NIST 800-171 and HIPAA.
  • Proficiency in Microsoft Office Suite and document-sharing tools like Google Docs and Box.
  • Ability to communicate effectively in writing and orally with technical, end-user, and executive audiences.
  • Passed the CMMC Certified Professional (CCP) exam or able to do so within the first 3 months of employment.
  • Successful background check.
  • Bachelor’s Degree.

More like this

Similar roles

Senior IT Business Systems Analyst, Computing Services

Carnegie Mellon University

Pittsburgh, PA 5 days ago
SQL Business Process Analysis Requirements Elicitation Solution Design System Testing Data Analysis Agile Scrum ITIL Lean Six Sigma Huron Research Suite Inteum Minuet User Stories Defect Triage

IT Security Engineer, Computing Services

Carnegie Mellon University

Pittsburgh, PA 5 days ago
Incident Response Digital Forensics Security Monitoring SIEM Endpoint Detection and Response Vulnerability Management Penetration Testing Python PowerShell Go Ruby Perl Java C C++ Linux Windows macOS TCP/IP Virtualization E-Discovery Public Key Infrastructure Certificate Authority Log Analysis Threat Hunting Malware Analysis
3+ yrs exp

Compliance Analytics Senior Analyst

SoFi

San Francisco, CA 11 days ago $89,600–$168,000
SQL Python dbt Snowflake Tableau GitLab CI/CD Data Engineering Machine Learning Data Pipelines Data Quality Testing Risk Analytics AML Data Transformation
6+ yrs exp

Senior Information Security Analyst

Betterment

New York, NY 11 days ago $170,000–$185,000
GRC SOC 2 ISO 27001 NIST CSF Vulnerability Management SDLC Application Security Business Continuity Disaster Recovery Audit AI Automation AWS CISSP CISA CISM
6+ yrs exp Hybrid

Senior Cyber Threat Detection and Response Analyst

McKesson Corporation

Richmond, VA 3 days ago $122,500–$204,100
SIEM EDR XDR SOAR Python PowerShell Bash KQL SPL AWS Azure GCP MITRE ATT&CK IDS/IPS Firewalls Windows Linux NIST CIS Benchmarks Incident Response
4+ yrs exp Hybrid

Senior Cyber Security Analyst

FedEx

Pittsburgh, PA +2 1 day ago
Okta SAML OIDC Active Directory LDAP SailPoint Privileged Access Management (PAM) Python PowerShell JavaScript REST APIs Okta Workflows ServiceNow MFA SSO Postman Generative AI Machine Learning
4+ yrs exp Hybrid