> Markdown version of [/jobs/ext/2177867-sr-research-it-security-risk-and-compliance-analyst-computing-services](https://www.wearedevelopers.com/jobs/ext/2177867-sr-research-it-security-risk-and-compliance-analyst-computing-services). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Research IT Security Risk and Compliance Analyst - Computing Services - **Company:** Carnegie Mellon University - **Location:** Pittsburgh, PA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Cyber Security, Google Docs, Information Technology Audit, Microsoft Office, Microsoft PowerPoint, Software Engineering, Information Technology, Virtual Agents, Devsecops - **Published:** August 22, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3362072720&tx=YT707CTZ&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Adaptability and openness to change as the department and organization evolves. * Ability to work well with others and/or as part of a team. * Ability to work with sensitive information, maintain confidentiality and use discretion. * Ability to pay close attention to detail; keep and maintain accurate and detailed reports and records. * Ability to maintain composure when dealing with difficult situations and/or individuals. * Ability to meet deadlines, work under pressure and with frequent interruptions. * Ability to understand and follow directions. * Ability to prioritize work and handle multiple tasks simultaneously. * Visual acuity to perform activities such as extended use of a computer monitor, extensive reading, * Bachelor's Degree * 5-7 Years of experience working with researchers and regulated data A combination of education and relevant experience from which comparable knowledge is demonstrated may be considered. Certifications: * Passed the CMMC Certified Professional (CCP) exam or able to do so within the first 3 months of employment Requirements: * Successful background check ## Description The Senior Research IT Security Risk & Compliance Analyst will assess, document, and implement various controls for University research. This individual manages the control documentation and advises on best business practices for all stakeholders. The incumbent is responsible for managing processes related to the information security of regulated research, systems audit assistance, coordination, and support (e.g., internal audit for information security). This requires familiarity with risk assessments, privacy regulations, standards, and sets of controls. The incumbent will have a well-rounded technical background in Information Technology (IT). This includes and is not limited to software development, DevSecOps, systems, IoT, help desk, risk management, information security, and emerging technology such as agentic-AI. Your core responsibilities will include: * Audit Research IT systems and ensure established controls are being followed. * Identify security findings and assist in driving risk items to closure with the correct stakeholders. * Apply familiarity with risk assessments and common control sets, including the Cybersecurity Maturity Model Certification (CMMC/NIST 800-171) and Health Insurance Portability and Accountability Act (HIPAA). * Lead compliance projects involving multiple stakeholders within established deadlines. * Manage the documentation and development of policies, guidance, and procedures related to research information security for the University's Information Security Office (ISO). * Write, gather evidence, investigate existing processes and regulations, and implement best practices. * Demonstrate quick learning and interest in the intersection of information security, people, and the law. * Maintain a strong understanding of the bridge between security and research and pay close attention to detail. * Partner with key internal campus stakeholders on processes and controls, including the Office of the Vice Provost for Research, University Libraries, and researchers. * Use Microsoft Office Suite (for example, Word, Excel, and PowerPoint) and document-sharing tools such as Google Docs and Box proficiently. * Review third-party documentation to determine information security risk and communicate those risks to stakeholders. * Communicate effectively in writing and orally with technical, end-user, and executive audiences, depending on the context. * Interface with researchers to determine information security requirements and technical requirements, and help the researcher find the appropriate environment. * Create research specific training and documentation, including System Security Plans, for regulated research. * Lead continuous monitoring for specific IT systems, primarily research. * Assist with Security Operations related to specific IT systems, primarily research. * Participate with Incident Response Coordinator to respond to incidents involving specific IT systems, primarily research. * Other duties as assigned., * Decisions generally affect own job or specific functional area. * Decisions may affect a work unit or department. Job may contribute to business and operational decisions. * Decisions have implications on management and operations of a unit or department. Job may contribute to important strategy, operation and business decisions. Working Conditions: * Required to work normal business hours; evening and weekend work may occasionally be required. Accountability: * Accountable for the successful completion of individual goals and priorities. Direction: * Receives little instruction on day-to-day work and receives general instructions on new assignments. * Establishes methods and procedures for attaining specific goals and objectives, and receives guidance in terms of broad goals. Flexibility, excellence, and passion are vital qualities within Computing Services. Inclusion, collaboration, and cultural sensitivity are valued competencies at CMU. Therefore, we are in search of a team member who is able to effectively interact with a varied population of internal and external partners at a high level of integrity. We are looking for someone who shares our values and who will support the mission of the university through their work. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Developing the Rich Text Editor for DeepL.com](https://www.wearedevelopers.com/videos/1172-developing-the-rich-text-editor-for-deepl-com) - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)