Senior Cybersecurity Engineer
About the Role
As part of the Cyber Risk and Resilience Directorate, you will join a team of cyber security engineers applying the latest tools, techniques, and methods to cyber security and operational resilience challenges. The Senior Cybersecurity Engineer will work directly with leaders in government, academia, and industry to protect the services and capabilities that the American public relies on every day for national security and economic stability.
The Senior Cybersecurity Engineer will support the operational capabilities and evolution of the Cybersecurity Assurance Team (CA Team), focusing on cybersecurity, operational resilience, and applied research in these areas. The CA team develops solutions—including frameworks, models, tools, policies, practices, technical guidance, and training—that allow industry, government, and military components to measure and improve their management of operational and technical risks to mission-critical services, including the impact of changes in technology such as artificial intelligence and agentic-driven systems.
Responsibilities
- Lead engagements with customers and mission partners, representing the CA Team’s and SEI’s work (50%).
- Contribute to customer projects designed to advance the state of the art in cybersecurity, regularly presenting the SEI’s mission and work to stakeholders (30%).
- Engage with communities of interest through publications, presentations, and relationship-building with relevant research and technology communities (15%).
- Grow your knowledge and skills in cybersecurity, staying current on emerging trends and topics relevant to the team’s portfolio (5%).
- Serve as a trusted advisor to defense and critical infrastructure customers.
- Support cybersecurity assessment standardization, develop and employ security measurement approaches, and transition expertise to the broader community.
- Work collaboratively on multidisciplinary teams to solve difficult customer challenges in diverse environments.
- Conduct research into novel methods and approaches for managing cybersecurity resilience across disciplines such as cyber operations, artificial intelligence, continuity planning, and organizational/social implications of cyber incidents.
Requirements
- BS degree in a relevant discipline with 10 years of applicable experience, or an MS degree in a relevant discipline with 8 years of applicable experience, or a PhD in a relevant discipline with 5 years of applicable experience.
- Track record of successfully leading projects in a technical discipline with a user-centered, accomplishment-focused approach.
- Ability to lead diverse teams in analyzing and solving real-world problems by developing engineering guidance and applying/tailoring SEI and non-SEI technologies.
- Experience contributing to multiple simultaneous projects in a creative, high-energy environment, with a willingness to experiment and develop effective processes.
- Strong mentorship skills to motivate and empower less-experienced team members.
- Outstanding communication skills, with the ability to interact collaboratively and diplomatically with customers and colleagues at all levels, grasp big-picture goals, and explain complex technical concepts clearly.
- Frequent travel (15-35%) to SEI/CMU locations, customer sites, conferences, and offsite meetings.
- Ability to obtain and maintain a Department of War security clearance; subject to a background investigation.
- Currently legally authorized to work for CMU in the United States (CMU will not sponsor or take over sponsorship of an employment visa for this opportunity).
Skills
Candidates should have experience or knowledge in several of the following areas:
- Mid to senior-level industry experience managing information security risks and implementing controls.
- Mid to senior-level industry experience managing technology controls and risks (e.g., change management, infrastructure, capacity planning, availability, cloud services, technology implementations).
- Mid to senior-level industry experience managing continuity-related controls and risks (e.g., business continuity, disaster recovery).
- Experience deploying information technology (e.g., implementing security technology, designing/building/maintaining networks).
- Consulting experience with private industry or government customers, including leading projects and engagements.
- Familiarity with cybersecurity and resilience standards (e.g., NIST CSF, NIST SP 800 series, ISO 27000 series).
- Knowledge of audit and assessment methodologies, tactics, techniques, and procedures.
- Knowledge of critical infrastructure protection concepts and standards.
- Understanding of maturity model concepts (e.g., CMMI, Financial Sector Cyber Profile).
- Ability to collaborate diplomatically with customers, co-workers, and professional colleagues.
Desired Experience
- Strong writing and editing ability.
- Experience functioning as a member of a process action team or instructional design working group.
- Experience with course and information mapping, flowcharting, and similar techniques.
- Certifications such as A+ CE, CCNA-Security, CND, Network+ CE, SSCP, CISSP, CISM, CISA, PMP, or equivalent experience.
- Military experience (beneficial but not required) for understanding the institute’s mission and stakeholders.
Benefits
- Comprehensive medical, prescription, dental, and vision insurance.
- Generous retirement savings program with employer contributions.
- Tuition benefits.
- Ample paid time off and observed holidays.
- Life and accidental death and disability insurance.
- Free Pittsburgh Regional Transit bus pass.
- Access to the Family Concierge Team for childcare navigation.
- Fitness center access.
- Additional perks and professional development opportunities.
Location
Arlington, VA or Pittsburgh, PA
Schedule
Full-time