Sr. Research IT Security Risk and Compliance Analyst - Computing Services

Carnegie Mellon UniversityPittsburgh, PA
Onsite

About The Position

The Senior Research IT Security Risk & Compliance Analyst will assess, document, and implement various controls for University research. This individual manages the control documentation and advises on best business practices for all stakeholders. The incumbent is responsible for managing processes related to the information security of regulated research, systems audit assistance, coordination, and support (e.g., internal audit for information security). This requires familiarity with risk assessments, privacy regulations, standards, and sets of controls. The incumbent will have a well-rounded technical background in Information Technology (IT). This includes and is not limited to software development, DevSecOps, systems, IoT, help desk, risk management, information security, and emerging technology such as agentic-AI.

Requirements

  • Bachelor’s Degree
  • 5-7 Years of experience working with researchers and regulated data
  • A combination of education and relevant experience from which comparable knowledge is demonstrated may be considered.
  • Passed the CMMC Certified Professional (CCP) exam or able to do so within the first 3 months of employment
  • Successful background check

Nice To Haves

  • Well-rounded technical background in Information Technology (IT), including software development, DevSecOps, systems, IoT, help desk, risk management, information security, and emerging technology such as agentic-AI.
  • Familiarity with risk assessments, privacy regulations, standards, and sets of controls.
  • Adaptability and openness to change as the department and organization evolves.
  • Ability to work well with others and/or as part of a team.
  • Ability to work with sensitive information, maintain confidentiality and use discretion.
  • Ability to pay close attention to detail; keep and maintain accurate and detailed reports and records.
  • Ability to maintain composure when dealing with difficult situations and/or individuals.
  • Ability to meet deadlines, work under pressure and with frequent interruptions.
  • Ability to understand and follow directions.
  • Ability to prioritize work and handle multiple tasks simultaneously.
  • Visual acuity to perform activities such as extended use of a computer monitor, extensive reading.
  • Flexibility, excellence, and passion are vital qualities within Computing Services.
  • Inclusion, collaboration, and cultural sensitivity are valued competencies at CMU.
  • Able to effectively interact with a varied population of internal and external partners at a high level of integrity.
  • Shares CMU values and supports the mission of the university through their work.

Responsibilities

  • Audit Research IT systems and ensure established controls are being followed.
  • Identify security findings and assist in driving risk items to closure with the correct stakeholders.
  • Apply familiarity with risk assessments and common control sets, including the Cybersecurity Maturity Model Certification (CMMC/NIST 800-171) and Health Insurance Portability and Accountability Act (HIPAA).
  • Lead compliance projects involving multiple stakeholders within established deadlines.
  • Manage the documentation and development of policies, guidance, and procedures related to research information security for the University’s Information Security Office (ISO).
  • Write, gather evidence, investigate existing processes and regulations, and implement best practices.
  • Demonstrate quick learning and interest in the intersection of information security, people, and the law.
  • Maintain a strong understanding of the bridge between security and research and pay close attention to detail.
  • Partner with key internal campus stakeholders on processes and controls, including the Office of the Vice Provost for Research, University Libraries, and researchers.
  • Use Microsoft Office Suite (for example, Word, Excel, and PowerPoint) and document-sharing tools such as Google Docs and Box proficiently.
  • Review third-party documentation to determine information security risk and communicate those risks to stakeholders.
  • Communicate effectively in writing and orally with technical, end-user, and executive audiences, depending on the context.
  • Interface with researchers to determine information security requirements and technical requirements, and help the researcher find the appropriate environment.
  • Create research specific training and documentation, including System Security Plans, for regulated research.
  • Lead continuous monitoring for specific IT systems, primarily research.
  • Assist with Security Operations related to specific IT systems, primarily research.
  • Participate with Incident Response Coordinator to respond to incidents involving specific IT systems, primarily research.
  • Other duties as assigned.

Benefits

  • Comprehensive medical, prescription, dental, and vision insurance
  • Generous retirement savings program with employer contributions
  • Tuition benefits
  • Ample paid time off
  • Observed holidays
  • Life and accidental death and disability insurance
  • Free Pittsburgh Regional Transit bus pass
  • Access to Family Concierge Team to help navigate childcare needs
  • Fitness center access
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service