Cybersecurity Engineer
About the Role
As part of the Cyber Risk and Resilience Directorate, you will join a team of cybersecurity engineers applying the latest tools, techniques, and methods to address cybersecurity and operational resilience challenges. This role supports the operational capabilities and evolution of the Cybersecurity Assurance Team (CA Team), focusing on cybersecurity, operational resilience, and applied research. The CA Team develops frameworks, models, tools, policies, practices, technical guidance, and training to help industry, government, and military components measure and improve their management of operational and technical risks to mission-critical services, including the impact of emerging technologies like artificial intelligence and agentic systems.
You will serve as a trusted advisor to defense and critical infrastructure customers, collaborating on multidisciplinary teams to solve complex challenges. The role also offers opportunities to conduct research into novel methods for managing cybersecurity resilience across disciplines such as cyber operations, AI applications, continuity planning, and organizational/social mitigations related to cyber incidents.
Responsibilities
- Customer Engagement (50%): Lead engagements with customers and mission partners, representing the CA Team’s and SEI’s work. Consult directly with mission partners and subject matter experts across the CA portfolio to advance cybersecurity assessment standardization, develop security measurement approaches, and transition expertise to the broader community.
- Project Participation (30%): Contribute to customer projects designed to advance the state of the art in cybersecurity. Regularly represent the SEI by presenting its mission and work to stakeholders.
- Community Engagement (15%): Engage with communities of interest through publications, presentations, and relationship-building with research and technology communities.
- Professional Development (5%): Continuously grow your knowledge and skills in cybersecurity and stay current on emerging trends relevant to the team’s portfolio.
Requirements
- Education and Experience:
- BS degree in a relevant discipline with 8 years of applicable experience, or
- MS degree in a relevant discipline with 5 years of applicable experience, or
- PhD in a relevant discipline with 2 years of applicable experience.
- Technical Excellence: A track record of successfully leading technical projects with a user-centered, accomplishment-focused approach.
- Leadership: Ability to lead diverse teams in analyzing and solving real-world problems by developing engineering guidance and applying SEI and non-SEI technologies. Demonstrated leadership by influence beyond your immediate team.
- Adaptability: Experience contributing to multiple simultaneous projects in a creative, high-energy environment. Willingness to experiment with new practices and develop effective processes.
- Mentorship: Enjoy mentoring, motivating, and empowering less-experienced team members to promote performance and teamwork.
- Communication: Outstanding ability to interact collaboratively and diplomatically with customers and colleagues at all levels. Ability to grasp the big picture while diving into technical details and present complex ideas to non-experts.
- Travel: Frequent travel (15-35%) to SEI/CMU locations, customer sites, conferences, and offsite meetings.
- Security Clearance: Ability to obtain and maintain a Department of War security clearance. Subject to a background investigation.
- Work Authorization: Must be currently legally authorized to work for CMU in the United States. CMU will not sponsor or take over sponsorship of an employment visa for this opportunity.
Skills and Qualifications
Candidates should have experience or knowledge in several of the following areas:
- Mid to senior-level industry experience managing information security risks and implementing controls.
- Mid to senior-level industry experience managing technology controls and risks (e.g., change management, infrastructure, capacity planning, availability, cloud services, technology implementations).
- Mid to senior-level industry experience managing continuity-related controls and risks (e.g., business continuity, disaster recovery).
- Experience deploying information technology (e.g., implementing security technology, designing/building/maintaining networks).
- Consulting experience with private industry or government customers, including leading projects and engagements.
- Familiarity with cybersecurity and resilience standards (e.g., NIST CSF, NIST SP 800 series, ISO 27000 series).
- Knowledge of audit and assessment methodologies, tactics, techniques, and procedures.
- Knowledge of critical infrastructure protection concepts and standards.
- Understanding of maturity model concepts (e.g., CMMI, Financial Sector Cyber Profile).
- Ability to collaborate diplomatically with customers, co-workers, and professional colleagues.
Desired Experience
- Strong writing and editing ability.
- Experience functioning as a member of a process action team or instructional design working group.
- Experience with course and information mapping, flowcharting, and similar tasks.
- Relevant certifications (e.g., A+ CE, CCNA-Security, CND, Network+ CE, SSCP, CISSP, CISM, CISA, PMP) or equivalent experience.
- Military experience (beneficial but not required) to better understand the institute’s mission and stakeholders.
Benefits
- Comprehensive medical, prescription, dental, and vision insurance.
- Generous retirement savings program with employer contributions.
- Tuition benefits for professional development.
- Ample paid time off and observed holidays.
- Life and accidental death and disability insurance.
- Free Pittsburgh Regional Transit bus pass.
- Access to the Family Concierge Team for childcare navigation.
- Fitness center access.
- Additional perks and resources for employee well-being.
Location
Arlington, VA or Pittsburgh, PA
Schedule
Full-time
Pay
Salary-based compensation.