Vulnerability Researcher

3 weeks ago


Pittsburgh, United States Software Engineering Institute Full time

The SEI helps advance software engineering principles and practices and serves as a national resource in software engineering, computer security, and process improvement. The SEI works closely with defense and government organizations, industry, and academia to continually improve software-intensive systems. Our core purpose is to help organizations improve software engineering capabilities and develop or acquire the right software, defect free, within budget and on time, every time.

The CERT Division of the Software Engineering Institute (SEI) is seeking applicants for the Vulnerability Researcher role. The Vulnerability Analysis Team, within the Threat Analysis Directorate, is a group of internet security experts focused on advancing the state of the art in vulnerability assessment and discovery, coordinated vulnerability disclosure, and software security on a national and global scale. We participate in communities of network defenders, software developers and vendors, security researchers, and policy-makers. We publish security advisories, papers, blog posts, data, and tools. The SEI is a federally funded research and development center at Carnegie Mellon University.

What you'll do

  • Develop state of the art approaches for analyzing executable code.
  • Apply these approaches to understanding systemic vulnerabilities in software systems and how attackers adapt their tradecraft to exploit those vulnerabilities.
  • Study and influence the software security and vulnerability disclosure ecosystems.
    Evaluate the effectiveness of tools, techniques and processes developed by industry and the security research community.
  • Uncover some of the fundamental assumptions underlying current best practice in software security.
  • Develop models, tools and data sets that can be used to characterize the threats to, and vulnerabilities in, software systems, and publish those results. You will also use these results to aid in the testing, evaluation and transition of technologies developed by government-funded research programs.
Who you are
  • You have a deep interest in cybersecurity, intellectual curiosity and a desire to make an impact beyond your organization.
  • You enjoy developing and communicating innovative ideas and thinking creatively to solve tough problems.
  • You relate collaboratively and diplomatically with people inside and outside the organization.
  • You have a strong understanding of research methods in computer science, engineering and security, and related fields as well as of Internet fundamentals including network protocols, provider operations and governance.
  • You enjoy mentoring and training others as well as sharing knowledge.
You have experience
  • Vulnerability research, analysis, disclosure, and mitigation
  • Applying knowledge of technology, systems architecture and security best practice to practical problems in enterprise security.
  • Advising on a range of security topics based on research and expert opinion.
  • Organizing and planning complex projects
  • Communicating complex system designs, technical approaches and road maps to sponsors, project managers and technical staff, and the ability to distill the implications of complex research results and apply those results to government operations.
  • Applying modern data-driven research methods to cost-effectiveness analysis, risk analysis and information security decision making and collaborating on industry and academic community projects.
  • Developing software in Python and other modern programming languages
  • Mathematical programming, statistical modeling, or machine learning
  • Recognizing and properly handling confidential and sensitive information.
  • Applying cybersecurity knowledge to areas such as AI/ML domain and open-source software
  • Automating existing security practices
You are able to
  • You have BS in Computer Science, Information Science, or Analytical discipline with eight (8) years of experience; OR MS in the same fields with five (5) years of experience; OR PhD in the same fields with two (2) years of experience.
  • You have a willingness to travel to various locations to support the SEI's overall mission. This includes sponsor sites, conferences, and offsite meetings on occasion. Moderate Travel (15%)
  • You will be subject to a background check and obtain and maintain an active Department of Defense security clearance. Applicants for this position must be currently legally authorized to work for CMU in the United States. CMU will not sponsor or take over sponsorship of an employment visa for this opportunity.
Why work here?
  • Join a world-class organization that has significant impact on software.
  • Work with cutting edge technologies and experts to solve tough problems for the government and the nation.
  • Get 8% monthly contribution for your retirement, without having to contribute yourself.
  • Get tuition benefits to CMU and other institutions for you and your dependent children.
  • Enjoy a healthy work/life balance with flexible work arrangements and paid parental and military leave.
  • Get access to university resources including mindfulness programs, childcare and back-up care benefits, a monthly transit benefit on WMATA, free transportation on the Pittsburgh Regional Transit System.
  • Enjoy annual professional development opportunities; attend conferences and training or obtain a certification and get reimbursed for membership in professional societies.
  • Qualify for relocation assistance and so much more.
Location
Pittsburgh, PA
Job Function
Software/Applications Development/Engineering
Position Type
Staff - Regular
Full time/Part time
Full time
Pay Basis
SalaryMore Information:
  • Please visit "Why Carnegie Mellon" to learn more about becoming part of an institution inspiring innovations that change the world.
  • Click here to view a listing of employee benefits
  • Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran.
  • Statement of Assurance


  • Pittsburgh, Pennsylvania, United States Carnegie Mellon University Full time

    Job DescriptionThe Carnegie Mellon University is seeking a highly skilled Senior Vulnerability Researcher to join our team. As a key member of our Threat Analysis Directorate, you will be responsible for developing state-of-the-art approaches for analyzing executable code and understanding systemic vulnerabilities in software systems.Key...


  • Pittsburgh, Pennsylvania, United States Carnegie Mellon University Full time

    About the RoleThe Carnegie Mellon University Software Engineering Institute (SEI) is seeking a highly skilled Vulnerability Researcher to join our team. As a key member of our Threat Analysis Directorate, you will play a critical role in advancing the state of the art in vulnerability assessment and discovery, coordinated vulnerability disclosure, and...


  • Pittsburgh, Pennsylvania, United States Carnegie Mellon University Full time

    Cybersecurity Expert for Advanced Vulnerability AnalysisAt Carnegie Mellon University, we're seeking an exceptional Cybersecurity Expert for Advanced Vulnerability Analysis to join our team. This role offers a unique opportunity to contribute to the advancement of software engineering principles and practices, working closely with government organizations,...


  • Pittsburgh, Pennsylvania, United States Software Engineering Institute Full time

    AI Security Researcher RoleWe are seeking a highly skilled AI Security Researcher to join our team at the Software Engineering Institute. As an AI Security Researcher, you will be responsible for developing state-of-the-art approaches for analyzing the robustness of AI systems, understanding vulnerabilities in AI systems, and reverse engineering malicious...


  • Pittsburgh, Pennsylvania, United States Software Engineering Institute Full time

    About the RoleWe are seeking a highly skilled AI Security Researcher to join our team at the Software Engineering Institute. As a member of our Threat Analysis Directorate, you will play a critical role in advancing the state of the art in AI security at a national and global scale.Key ResponsibilitiesDevelop state-of-the-art approaches for analyzing the...


  • Pittsburgh, United States MSCCN Full time

    Reference #: 2021569 Are you a cybersecurity and/or AI researcher who enjoys a challenge? Are you excited about pioneering new research areas that will impact academia, industry, and national security? If so, we want you for our team, where you'll collaborate to deliver high-quality results in the emerging area of AI security. The CERT Division of the...


  • Pittsburgh, United States Software Engineering Institute Full time

    Are you a cybersecurity and/or AI researcher who enjoys a challenge? Are you excited about pioneering new research areas that will impact academia, industry, and national security? If so, we want you for our team, where you'll collaborate to deliver high-quality results in the emerging area of AI security. The CERT Division of the Software Engineering...


  • Pittsburgh, United States MSCCN Full time

    Reference #: 2021569 Are you a cybersecurity and/or AI researcher who enjoys a challenge? Are you excited about pioneering new research areas that will impact academia, industry, and national security? If so, we want you for our team, where you'll collaborate to deliver high-quality results in the emerging area of AI security. The CERT Division of the...


  • Pittsburgh, United States Carnegie Mellon University Full time

    Are you a cybersecurity and/or AI researcher who enjoys a challenge? Are you excited about pioneering new research areas that will impact academia, industry, and national security? If so, we want you for our team, where you'll collaborate to deliver high-quality results in the emerging area of AI security. The CERT Division of the Software Engineering...


  • Pittsburgh, Pennsylvania, United States Carnegie Mellon University Full time

    About the RoleCarnegie Mellon University is seeking a highly skilled AI Security Researcher to join our team. As a key member of our research group, you will be responsible for developing and implementing cutting-edge AI security solutions to protect our nation's critical infrastructure.Key ResponsibilitiesDesign and develop novel AI security approaches to...


  • Pittsburgh, United States Carnegie Mellon University Full time

    Join a dynamic team of motivated individuals with deep collective experience throughout digital forensics, incident response, investigation, operations, and academic research. We seek individuals with strong interest in understanding and resolving technical challenges in the national security space. Our group focuses on applied research into the...


  • Pittsburgh, United States Carnegie Mellon University Full time

    Join a dynamic team of motivated individuals with deep collective experience throughout digital forensics, incident response, investigation, operations, and academic research. We seek individuals with strong interest in understanding and resolving technical challenges in the national security space. Our group focuses on applied research into the...


  • Pittsburgh, Pennsylvania, United States Aurora Innovation Full time

    About the RoleAurora Innovation is seeking a highly skilled Product Security Specialist to join our team. As a Product Security Specialist, you will be responsible for ensuring the secure design and implementation of the technology built for the Aurora Driver.Key ResponsibilitiesPerform secure design reviews and threat modeling to identify and prioritize...


  • Pittsburgh, Pennsylvania, United States NCFTA Full time

    Job Title: Financial Cyber Intelligence AnalystNCFTA is seeking a highly skilled Financial Cyber Intelligence Analyst to join our team. As a key member of our organization, you will play a critical role in conducting research into the latest network cyber threats with our financial and banking partners.Key Responsibilities:Conduct data collection and...


  • Pittsburgh, Pennsylvania, United States NCFTA Full time

    Job OverviewThe National Cyber Forensics & Training Alliance (NCFTA) is seeking a highly skilled Cyber Financial Intelligence Analyst to join our team. As a key member of our organization, you will play a critical role in conducting research into the latest network cyber threats with our financial and banking partners.This position is responsible for...


  • Pittsburgh, Pennsylvania, United States Integrity Placement Group Full time

    Internal Medicine Physician OpportunityWe are seeking a compassionate and dedicated Internal Medicine Physician to join our team at Integrity Placement Group. Our client is a comprehensive Federally Qualified Health Center (FQHC) providing patient-centered care demonstrating "Healthcare with a Heart."The PositionThe ideal candidate is passionate about...


  • Pittsburgh, United States Duquesne Light Company Full time

    Duquesne Light Company, headquartered in downtown Pittsburgh, is a leader in providing electric energy and has been in the forefront of the electric energy market, with a history rooted in technological innovation and superior customer service. Today, the company continues its role as a leader in the transmission and distribution of electric energy,...

  • Medical Director

    2 months ago


    Pittsburgh, Pennsylvania, United States Integrity Placement Group Full time

    Internal Medicine Physician OpportunityWe are seeking a compassionate and dedicated Internal Medicine Physician to join our team at Integrity Placement Group. Our client is a comprehensive Federally Qualified Health Center (FQHC) providing patient-centered care demonstrating "Healthcare with a Heart."About the PositionThe ideal candidate is passionate about...

  • Security Analyst III

    3 weeks ago


    Pittsburgh, Pennsylvania, United States Saxon Global Full time

    Job Summary:Saxon Global is seeking a highly skilled Security Analyst III to support the 'Permit to Operate' assessment gate by performing security control assessments for applications deploying changes to production. The ideal candidate will participate in projects in support of PTX metrics and control automation.Key Responsibilities:Participate in 'Permit...


  • Pittsburgh, United States Duquesne Light Full time

    Reference #: 18815 Duquesne Light Company, headquartered in downtown Pittsburgh, is a leader in providing electric energy and has been in the forefront of the electric energy market, with a history rooted in technological innovation and superior customer service. Today, the company continues its role as a leader in the transmission and distribution of...