Sr. Research IT Security Risk and Compliance Analyst - Computing Services
Carnegie Mellon UniversityAbout the role
The Senior Research IT Security Risk & Compliance Analyst will assess, document, and implement various controls for University research. This individual manages the control documentation and advises on best business practices for all stakeholders. The incumbent is responsible for managing processes related to the information security of regulated research, systems audit assistance, coordination, and support (e.g., internal audit for information security). This requires familiarity with risk assessments, privacy regulations, standards, and sets of controls. The incumbent will have a well-rounded technical background in Information Technology (IT). This includes and is not limited to software development, DevSecOps, systems, IoT, help desk, risk management, information security, and emerging technology such as agentic-AI.
Your core responsibilities will include:
Audit Research IT systems and ensure established controls are being followed.
Identify security findings and assist in driving risk items to closure with the correct stakeholders.
Apply familiarity with risk assessments and common control sets, including the Cybersecurity Maturity Model Certification (CMMC/NIST 800-171) and Health Insurance Portability and Accountability Act (HIPAA).
Lead compliance projects involving multiple stakeholders within established deadlines.
Manage the documentation and development of policies, guidance, and procedures related to research information security for the University’s Information Security Office (ISO).
Write, gather evidence, investigate existing processes and regulations, and implement best practices.
Demonstrate quick learning and interest in the intersection of information security, people, and the law.
Maintain a strong understanding of the bridge between security and research and pay close attention to detail.
Partner with key internal campus stakeholders on processes and controls, including the Office of the Vice Provost for Research, University Libraries, and researchers.
Use Microsoft Office Suite (for example, Word, Excel, and PowerPoint) and document-sharing tools such as Google Docs and Box proficiently.
Review third-party documentation to determine information security risk and communicate those risks to stakeholders.
Communicate effectively in writing and orally with technical, end-user, and executive audiences, depending on the context.
Interface with researchers to determine information security requirements and technical requirements, and help the researcher find the appropriate environment.
Create research specific training and documentation, including System Security Plans, for regulated research.
Lead continuous monitoring for specific IT systems, primarily research.
Assist with Security Operations related to specific IT systems, primarily research.
Participate with Incident Response Coordinator to respond to incidents involving specific IT systems, primarily research.
Other duties as assigned.
Physical and Mental Requirements:
Adaptability and openness to change as the department and organization evolves.
Ability to work well with others and/or as part of a team.
Ability to work with sensitive information, maintain confidentiality and use discretion.
Ability to pay close attention to detail; keep and maintain accurate and detailed reports and records.
Ability to maintain composure when dealing with difficult situations and/or individuals.
Ability to meet deadlines, work under pressure and with frequent interruptions.
Ability to understand and follow directions.
Ability to prioritize work and handle multiple tasks simultaneously.
Visual acuity to perform activities such as extended use of a computer monitor, extensive reading
Decision Making:
Decisions generally affect own job or specific functional area.
Decisions may affect a work unit or department. Job may contribute to business and operational decisions.
Decisions have implications on management and operations of a unit or department. Job may contribute to important strategy, operation and business decisions.
Working Conditions:
Required to work normal business hours; evening and weekend work may occasionally be required.
Accountability:
Accountable for the successful completion of individual goals and priorities.
Direction:
Receives little instruction on day-to-d
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s