Carnegie Mellon University’s Information Security Office is seeking an IT Security Engineer to help investigate and respond to security incidents across a large, diverse, and technically complex university environment.
This is a hands-on security position with a strong focus on incident response, digital forensics, security monitoring, and technical investigation. You will use endpoint, network, application, identity, and other security data to determine what happened, understand the scope and impact of an incident, preserve and analyze evidence, contain threats, and help affected teams recover securely.
The environment is broad, and investigations frequently involve unfamiliar systems or technologies. One incident may require analyzing an endpoint compromise, another may involve reconstructing activity from network traffic and logs, while another may require learning enough about an application, operating system, or protocol to understand unexpected behavior.
You do not need to be an expert in every technology or security discipline described in this posting. We are looking for strong technical fundamentals, investigative ability, curiosity, sound judgment, clear communication, and the ability to learn unfamiliar systems when an investigation requires it.
If you enjoy understanding how systems work beneath the surface, following evidence until you can explain what happened, considering systems from both attacker and defender perspectives, or building tools to answer questions that existing products cannot, you may be a strong fit for this team.
What You’ll Do:
A significant portion of this position is dedicated to security incident response and digital forensics. Responsibilities include:
The position also contributes to the broader work of the Information Security Office. Depending on team needs, current priorities, and your areas of expertise, this may include:
What We’re Looking For
Minimum Qualifications:
Direct professional experience in every area covered by this position is not required. Candidates with strong backgrounds in systems, networking, software, infrastructure, or other technical disciplines who can demonstrate security aptitude and investigative ability are encouraged to apply.
Experience That Would Be Helpful
Experience in one or more of the following areas is beneficial:
Depth in one or more technical areas is more important than superficial experience with every technology listed above.
Candidates who have developed relevant skills through professional work, independent research, home labs, open-source projects, capture-the-flag competitions, security research, academic work, or other substantive hands-on activities are encouraged to describe that experience.
Professional certifications such as CISSP, GSEC, GCFE, or other security and technology certifications are welcomed but are not required.
How We Work
Curiosity matters here. Strong candidates tend to want to understand why systems behave the way they do. They are comfortable starting with incomplete information, asking good questions, testing hypotheses, digging beneath product interfaces, and considering how a system might behave differently from what its designers intended.
We value people who can combine that curiosity with careful technical reasoning and sound judgment. Security investigations may involve production systems, sensitive data, legal matters, or significant service impact, so creativity must be balanced with appropriate caution and communication.
We also value engineers who look for ways to improve how work is performed. That may mean automating a repetitive task, creating a better investigative workflow, developing a small utility, integrating data from multiple systems, or identifying a more effective way to answer an investigative question.
No security engineer knows every technology they will encounter. The ability to recognize a gap in your knowledge, research the problem, experiment appropriately, and apply what you learn is an important part of this role.
Accountability and Decision Making
The IT Security Engineer plays an important role in the timely identification, containment, investigation, and prevention of computer and network security incidents.
After an appropriate period of onboarding and training, the engineer is expected to independently handle routine investigations and operational responsibilities. This includes evaluating the severity of security alerts, selecting appropriate investigative techniques, recommending containment or remediation actions, and determining when an issue should be escalated.
Significant incidents, sensitive data exposures, major service disruptions, legal matters, notification decisions, and other unusual or sensitive situations are handled collaboratively with senior staff, the Incident Response Coordinator, management, and other university stakeholders as appropriate.
On-Call and Other Position Requirements
This position participates in a shared 24x7 on-call rotation for security monitoring, incident response, and infrastructure support. On-call responsibilities may occasionally require work outside normal business hours or travel to campus.
The position involves access to sensitive security, investigative, institutional, and potentially legally protected information. Appropriate judgment, discretion, and professionalism are essential.
The successful candidate must qualify as a U.S. person under the applicable requirements governing this position.
This position does not have formal supervisory responsibilities.
Professional Development:
Continued learning is an expected part of the position. Engineers are encouraged to remain current with security technologies, attack techniques, investigative methods, vulnerabilities, and changes in the broader security community through technical research, training, conferences, professional communities, internal knowledge sharing, and independent experimentation.
If you meet the core qualifications and believe your technical background, investigative ability, and curiosity would allow you to succeed in this role, we encourage you to apply even if your experience does not match every preferred qualification listed above.
Are you interested in this exciting opportunity?! Apply today!
Joining the CMU team opens the door to an array of exceptional benefits.
Benefits eligible employees enjoy a wide array of benefits including comprehensive medical, prescription, dental, and vision insurance as well as a generous retirement savings program with employer contributions. Unlock your potential with tuition benefits, take well-deserved breaks with ample paid time off and observed holidays, and rest easy with life and accidental death and disability insurance.
Additional perks include a free Pittsburgh Regional Transit bus pass, access to our Family Concierge Team to help navigate childcare needs, fitness center access, and much more!
For a comprehensive overview of the benefits available, explore our Benefits page.
At Carnegie Mellon, we value the whole package when extending offers of employment. Beyond credentials, we evaluate the role and responsibilities, your valuable work experience, and the knowledge gained through education and training. We appreciate your unique skills and the perspective you bring. Your journey with us is about more than just a job; it’s about finding the perfect fit for your professional growth and personal aspirations.
Are you interested in an exciting opportunity with an exceptional organization?! Apply today!
Location
Pittsburgh, PA
Job Function
Security
Position Type
Staff – Regular
Full Time/Part time
Full time
Pay Basis
Salary
More Information: