Chapter Announcements

  • Job Posting - CMU SEI - Senior Cyber Risk Engineer

    Cybersecurity Risk Engineers at the SEI use advanced skills in statistics, mathematics, risk analysis, systems engineering, economics and other technical fields in an interdisciplinary manner to help our government and industry mission partners to identify, research, and solve cyber security challenges. In this role, you will work with our mission partners to identify areas where advanced quantitative & technical skills can help tackle problems, plan and develop prototype solutions, and create final products designed to better manage risk. You'll work with cyber security professionals and university collaborators to build new technologies that will influence national cyber security strategies for decades to come. You will build and evaluate models, create products, conduct applied research, present findings to stakeholders, and develop transition plans for solutions to our partners.

    Our team works on a wide range of projects. Our current research focus includes experimental designs for measuring cyber risk, researching methodologies for improvement of risk-based decision making, and building and evaluating models to identify security vulnerabilities. Additionally, we work on developing and conducting organizational security assessments, evaluating risk management programs, threat modeling, economics of cybersecurity and measurement. If you are an experienced researcher with an interest in risk management and cybersecurity, we want to hear from you!

    As a Senior Cyber Risk Engineer, you will work directly with government, industry, and academic partners to identify, analyze, and solve complex cybersecurity risk management challenges. You will apply expertise in statistics, mathematics, risk analysis, systems engineering, and data science to develop innovative approaches for measuring, modeling, and managing cyber risk. Your work will help shape cybersecurity strategies, influence risk-based decision making, and improve the resilience of mission-critical systems and services.

    Knowledge, Skills, and Abilities:

    Candidates should have experience or knowledge in several of the following:

    • Understanding of risk management principles and their application to cybersecurity.
    • Experience performing cyber risk analysis, risk quantification, or security measurement.
    • Expertise in one or more quantitative disciplines such as statistics, mathematics, econometrics, operations research, systems engineering, data science, or machine learning.
    • Experience developing and applying statistical models, predictive analytics, or simulation techniques.
    • Experience with uncertainty quantification, probabilistic analysis, or decision science methodologies.
    • Experience conducting threat modeling, vulnerability analysis, or security assessments.
    • Knowledge of cybersecurity risk management frameworks and methodologies.
    • Experience evaluating organizational cybersecurity programs and risk management practices.
    • Ability to design and conduct applied research in cybersecurity, risk management, or related fields.
    • Experience developing analytical tools, models, or decision-support capabilities.
    • Ability to collaborate effectively within multidisciplinary teams of researchers, engineers, and cybersecurity professionals.
    • Strong analytical, problem-solving, and critical-thinking skills.
    • Ability to communicate complex technical concepts and analytical findings to both technical and non-technical audiences.
    • Ability to work collaboratively, diplomatically, and effectively with customers, colleagues, researchers, and senior stakeholders.

    Requirements:

    • Education and Experience: BS degree in Computer Science, Statistics, Engineering, Mathematics, Economics, Data Science, or a related highly quantitative discipline with ten (10) years of applicable experience; or a MS degree in a relevant discipline with eight (8) years of applicable experience; or a PhD in a relevant discipline with five (5) years of applicable experience.
    • Technical Excellence: You have a track record of applying advanced analytical methods to solve complex cybersecurity challenges and delivering impactful technical outcomes. You possess expertise in one or more areas including cybersecurity risk management, risk quantification, statistics, econometrics, systems engineering, machine learning, modeling and simulation, or data science. You are focused on developing practical solutions that improve risk-based decision making for mission partners.
    • Leadership: You have the ability to lead multidisciplinary teams in analyzing and solving real-world cybersecurity and risk management problems. You can guide research efforts, develop analytical frameworks, and influence technical direction while collaborating with researchers, engineers, government stakeholders, and external partners. Your leadership extends beyond formal reporting relationships through technical influence and collaboration.
    • Working in a Creative, Dynamic Environment: You have experience contributing to multiple simultaneous projects and thrive in a fast-paced research environment. You are willing to experiment with innovative analytical techniques, explore emerging technologies, and develop new methodologies that advance cybersecurity risk management and measurement.
    • Mentorship: You enjoy mentoring and motivating team members. You contribute to the development of technical talent through knowledge sharing, collaboration, and professional guidance.
    • Communication: You have outstanding communication skills and can interact collaboratively and diplomatically with customers, mission partners, researchers, and colleagues at all levels. You understand both strategic objectives and technical details and can communicate complex analytical findings to audiences with varying levels of technical expertise.
    • Travel: Periodic travel to customer sites, conferences, workshops, and stakeholder meetings is required to support the SEI's mission and research activities.
    • Security Clearance: You will be subject to a background investigation and must have the ability to obtain and maintain a Department of War security clearance. 
    • Applicants for this position must be currently legally authorized to work for CMU in the United States. CMU will not sponsor or take over sponsorship of an employment visa for this opportunity.

    Desired Experience:

    • Experience in cyber risk quantification and measurement.
    • Experience in econometrics, applied statistics, or quantitative risk analysis.
    • Experience in uncertainty quantification and probabilistic modeling.
    • Experience in machine learning, data science, or advanced analytics.
    • Experience in modeling and simulation.
    • Experience conducting threat modeling and vulnerability analysis.
    • Experience evaluating organizational cybersecurity and risk management programs.
    • Experience supporting test and evaluation activities for large-scale government research programs.
    • Demonstrated ability to learn new concepts and grow into emerging technical areas.
    • Strong technical writing, editing, and presentation skills.
    • Experience working with government agencies, defense organizations, federally funded research centers, or academic institutions is a plus.

    Location

    Arlington, VA, Pittsburgh, PA

    Job Function

    Software/Applications Development/Engineering

    Position Type

    Staff – Regular

    Full time/Part time

    Full time

    Pay Basis

    Salary

  • Three Rivers Information Security Symposium (TRISS)

    Thursday, October 22, 2026
    TRISS is a one-day, multi-track event bringing together Pittsburgh’s information security community to share information and insights on the latest cyber risk and controls solutions trends.  Organized entirely by volunteers, TRISS aims to increase cyber risk awareness, foster collaboration, and enhance information security professionals’ expertise. 

    Click here to register

  • BSidesPGH

    Friday, July 10, 2026
    Pittsburgh Rivers Casino
    Security BSides is a global series of community-driven conferences allowing experienced information security practitioners to present and share their expertise on a wide range of cyber topics.  Pittsburgh's annual BSidesPGH conference has become one of Pittsburgh's largest gatherings of information security professionals for networking, technical presentations, and capture-the-flag events.
    Click 
    here to register

  • 2026 ISACA North America Conference

    May 6-8, 2026
    This annual event for IT risk professionals covers topics including advanced IT audit practices, cybersecurity, risk management, data privacy, AI's impact, and emerging tech (Blockchain, IoT) to help attendees build skills, network, and earn CPE credits for certifications. The conference is a key gathering for IS/IT leaders and experts to discuss best practices and shape the future of information systems.
    Click 
    here to register

  • Job Posting: Information Technology Auditor - Federated Hermes

    Federated Hermes is looking for an Information Technology Auditor.  This is a hybrid role at the Warrendale location (3 days in office, 2 days remote work per week)  (JOB ID 9630)

  • 2026 ISACA Los Angeles February Webinar - Navigating California’s Updated Privacy Laws

     2026 ISACA Los Angeles February Webinar - Navigating California’s Updated Privacy Laws - Free Webinar

  • Job Posting: Senior VP and General Auditor - Federal Reserve Bank of Cleveland

    The Federal Reserve Bank of Cleveland is looking to hire a new Senior VP and General Auditor responsible for the Bank's Audit Department.  Strong IT/IS as well as AI background preferred.  For information as well as to apply:  Federal Reserve System Careers

  • Job Posting: Technology Manager - CMU CERT

    The CMU CERT Cyber Risk & Resilience Directorate has just posted a Technical Manager position, for the Cyber Risk Management Team. 

    https://cmu.wd5.myworkdayjobs.com/en-US/SEI/job/Technical-Manager---Cyber-Risk-Management_2023820-1