Cybersecurity Engineer
Do you want to make a difference and help support the resilience and security of the nation? As part of the Cyber Risk and Resilience Directorate, you will be part of a team of cyber security engineers applying the latest tools, techniques, and methods to cyber security and operational resilience challenges. The Cybersecurity Engineer will work directly with leaders in government, academia, and industry to protect the services and capabilities that the American public relies on every day for national security and economic stability.
About the Role
The Cybersecurity Engineer will support the operational capabilities and evolution of the Cybersecurity Assurance Team (CA Team), specifically focusing on cybersecurity, operational resilience, and applied research in these areas. The CA team develops solutions (in the form of frameworks, models, tools, policies, practices, technical guidance, and training) that allow industry, government, and military components to measure and improve their management of operational and technical risks to mission-critical services. This includes and is linked to the impact of changes in technology, including artificial intelligence and agentic driven systems.
As a Cybersecurity Engineer, you will be responsible for direct consulting with mission partners and subject matter experts across the CA portfolio. You will support cybersecurity assessment standardization, develop and employ security measurement approaches, and transition your knowledge and expertise to the broader community. You will work collaboratively on multidisciplinary teams solving difficult customer challenges in diverse environments. You will serve as a trusted advisor to defense and critical infrastructure customers. Cybersecurity Engineers also have the opportunity to conduct research into novel methods and approaches to managing cybersecurity resilience across all the component disciplines (for example cyber operations, application of artificial intelligence, continuity planning and management, organizational and social implications and mitigations related to cyber incidents and failures).
Responsibilities
- Customer Engagement (50%): Lead engagements with customers and mission partners, including representing the CA Team’s and SEI’s work to mission partners.
- Project Participation (30%): Contribute to customer projects designed to advance the state of the art in cybersecurity; represent the SEI regularly by presenting our mission and work to stakeholders.
- Community Engagement (15%): Engage with communities of interest through publication and presentation; build and maintain relationships with relevant research and technology communities.
- Professional Development (5%): Continue to grow knowledge and skills in cybersecurity and stay current on emerging trends relevant to the team’s portfolio.
Requirements
- Education and Experience:
- BS degree in a relevant discipline with 8 years of applicable experience, or
- MS degree in a relevant discipline with 5 years of applicable experience, or
- PhD in a relevant discipline with 2 years of applicable experience.
- Technical Excellence: Track record of successfully leading projects for a technical discipline; user-centered and accomplishment-focused, driving projects and teams to successful, high-impact outcomes.
- Leadership: Ability to lead diverse teams in analyzing and solving real-world problems by developing engineering guidance and applying SEI and non-SEI technologies; leadership by influence extends beyond immediate team.
- Working in a Creative, Dynamic Environment: Experience contributing to multiple simultaneous projects; thrive in a creative and high-energy environment; willing to experiment with new practices and develop effective processes.
- Mentorship: Enjoy mentoring, motivating, and empowering less-experienced team members to promote performance and teamwork.
- Communication: Outstanding communicator; interact collaboratively and diplomatically with customers and colleagues at all levels; grasp the big picture and direction while digging into technical details; present complex ideas to non-experts.
- Travel: Frequent (15-35%) to various locations within the SEI and CMU community, customer sites, conferences, and offsite meetings.
- Security Clearance: Subject to a background investigation; must have the ability to obtain and maintain a Department of War security clearance.
- Work Authorization: Currently legally authorized to work for CMU in the United States; CMU will not sponsor or take over sponsorship of an employment visa for this opportunity.
Skills
Candidates should have experience/knowledge in several of the following:
- Mid to senior-level industry experience managing information security risks and implementing controls.
- Mid to senior-level industry experience managing technology controls and risks (e.g., change management, infrastructure, capacity planning, availability, cloud services, technology implementations).
- Mid to senior-level industry experience managing continuity-related controls and risks (e.g., business continuity, disaster recovery).
- Experience deploying information technology (e.g., implementing security technology, designing, building, and maintaining networks).
- Consulting experience with private industry or government customers, including leading projects and engagements.
- Familiarity with cybersecurity and resilience standards (e.g., NIST CSF, NIST SP 800 series, ISO 27000 series).
- Knowledge of audit and assessment methodologies, tactics, techniques, and procedures.
- Knowledge of critical infrastructure protection concepts and standards.
- Understanding of maturity model concepts (e.g., CMMI, Financial Sector Cyber Profile).
- Ability to deal collaboratively, diplomatically, and successfully with customers, co-workers, and professional colleagues.
Desired Experience
- Strong writing/editing ability.
- Ability to interact and function as a member of a process action team or instructional design working group.
- Experience with course and information mapping, flowcharting, etc.
- Certifications: A+ CE, CCNA-Security, CND, Network+ CE, SSCP, Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Systems Auditor (CISA), Project Management Professional (PMP), or equivalent experience.
- Military experience (beneficial for understanding the institute’s mission and stakeholders).
Benefits
- Comprehensive medical, prescription, dental, and vision insurance.
- Generous retirement savings program with employer contributions.
- Tuition benefits.
- Ample paid time off and observed holidays.
- Life and accidental death and disability insurance.
- Free Pittsburgh Regional Transit bus pass.
- Access to Family Concierge Team for childcare navigation.
- Fitness center access.
Location
Arlington, VA or Pittsburgh, PA
Schedule
Full time