Demo

Associate Vulnerability Researcher

Carnegie Mellon University
Pittsburgh, PA Full Time
POSTED ON 2/5/2025
AVAILABLE BEFORE 4/4/2025

The Software Engineering Institute (SEI) at Carnegie Mellon University is a Federally Funded Research and Development Center (FFRDC) focused on advancing software engineering, cybersecurity, and process improvement. The SEI works closely with defense and government organizations, industry, and academia to continually improve software-intensive systems. Additionally, Artificial Intelligence (AI) engineering is a key focus area, as the SEI recently developed the AI Security Incident Response Team (AISIRT) to fill the need for a capability that can identify, analyze, and respond to threats, vulnerabilities, and incidents that emerge from ongoing advances in AI and machine learning (ML).   
 
The Vulnerability Analysis Team, within the Threat Analysis Directorate, is an elite team of National Security dedicated personnel that work to reduce the societal harm from vulnerable information processing systems and related processes. The Vulnerability Analysis Team has three core functions:  1) research and development (R&D) of systemic software vulnerabilities and Coordinated Vulnerability Disclosure (CVD) processes; 2) vulnerability response and management to mitigate priority vulnerabilities; and 3) vulnerability community outreach and engagement to influence software policies and standards. 

As an Associate Vulnerability Researcher you will have opportunity to advance the start-of-the-art in software and system vulnerability research and advance CVD operations of vulnerabilities on national and global scales. You’ll also collaborate with network defenders, developers, security researchers, and policymakers, and share findings through advisories, papers, and tools. You will also have the opportunity to influence upcoming technology trends leading to more secure and sustainable systems, including AI/ML systems.

 
What you’ll do 

  • Enable and develop state-of-the-art approaches, techniques, and processes for analyzing executable code. 
  • Apply these approaches, techniques, and processes to understanding systemic vulnerabilities in software systems (including AI/ML) and how attackers adapt their tradecraft to exploit those vulnerabilities.
  • Integrate threat intelligence into ongoing systemic vulnerability R&D, analysis of AI-related threats, and analysis of malware analysis samples analysis. 
  • Study and influence the software security and vulnerability disclosure ecosystems; evaluate the effectiveness of tools, techniques, and processes developed by industry and the security research community. 
  • Uncover some of the fundamental assumptions underlying current best practices in software security (including AI/ML).  
  • Conduct vulnerability response and management to mitigate discovered and/or reported software and system vulnerabilities. 
  • Publish reports, technical notes, white papers, Vulnerability Notes, and/or blog posts to a variety of audiences. 
  • Develop models, tools, and data sets that can be used to characterize the threats to, and vulnerabilities in, software systems; aid in testing, evaluating, and transitioning technologies developed by government-funded research programs. 
  • Conduct outreach and engagement activities across the vulnerability communities (public and private) to influence software security policies and standards. 

Who you are 

  • You have a deep interest in cybersecurity with an intellectual curiosity and desire to make an impact beyond your organization. 
  • You enjoy developing and communicating innovative ideas and thinking creatively to solve tough problems. 
  • You relate collaboratively and diplomatically with people inside and outside the organization. 
  • You have a strong understanding of research methods in computer science, engineering and security, and related fields to include Internet fundamentals such as network protocols
  • You enjoy mentoring and training others as well as sharing knowledge.

You have experience 

  • Vulnerability research, analysis, discovery, disclosure, and mitigation. 
  • Organizing, planning, and executing complex projects. 
  • Cyber threat intelligence analysis and application. 
  • Applying knowledge of technology, systems architecture, and security best practices to practical problems in enterprise security. 
  • Advising on a range of security topics based on research and expert opinion.  
  • Communicating complex system designs, technical approaches and road maps to sponsors, project managers and technical staff, and the ability to distill the implications of complex research results and apply those results to government operations. 
  • Applying modern data-driven research methods to cost-effectiveness analysis, risk analysis and information security decision making and collaborating on industry and academic community projects.  
  • Developing software in Python and other modern programming languages 
  • Mathematical programming, statistical modeling, or machine learning. 
  • Recognizing and properly handling confidential and sensitive information. 
  • Applying cybersecurity knowledge to areas such as AI/ML domain and open-source software.
  • Automating existing security practices.  

You have 

  • BS in Computer Science, Information Science, or Analytical discipline with three (3) years of experience; OR MS in the same fields with one (1) year of experience.
  • Willingness to travel to various locations to support the SEI’s overall mission. This includes sponsor sites, conferences, and offsite meetings on occasion. Moderate Travel (10-15%) 
  • Are subject to a background check and obtain and maintain an active Department of Defense security clearance.  Applicants for this position must be currently legally authorized to work for CMU in the United States. CMU will not sponsor or take over sponsorship of an employment visa for this opportunity.

Joining the CMU team opens the door to an array of exceptional benefits available to eligible employees.

Those employees who are benefits eligible have the opportunity to experience the full spectrum of advantages from comprehensive medical, prescription, dental, and vision insurance to an enticing retirement savings program offering a generous employer contribution. You can also unlock your potential with tuition benefits and take well-deserved breaks with ample paid time off and observed holidays. Finally, rest easy knowing you are covered by life and accidental death and disability insurance. 

Other perks include a free Pittsburgh Regional Transit bus pass, our Family Concierge Team to help navigate childcare needs, fitness center access, and so much more!

For a comprehensive overview of the benefits that may be awaiting you, explore our Benefits page.

At Carnegie Mellon, we value the whole package when extending offers of employment. Beyond just credentials, we consider the role and responsibilities, your invaluable work experience, and the knowledge gained through education and training. We acknowledge and appreciate your unique skills and the diverse perspective you bring. Your journey with us is about more than just a job; it’s about finding the perfect fit for your professional growth and personal aspirations.

Are you interested in an exciting opportunity with an exceptional organization?! Apply today!

Location

Pittsburgh, PA

Job Function

Software/Applications Development/Engineering

Position Type

Staff – Regular

Full Time/Part time

Full time

Pay Basis

Salary

More Information: 

  • Please visit Why Carnegie Mellonto learn more about becoming part of an institution inspiring innovations that change the world. 

  • Click here to view a listing of employee benefits

  • Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran

  • Statement of Assurance

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Associate Vulnerability Researcher?

Sign up to receive alerts about other jobs on the Associate Vulnerability Researcher career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$77,657 - $95,021
Income Estimation: 
$97,257 - $120,701
Income Estimation: 
$97,257 - $120,701
Income Estimation: 
$123,167 - $152,295
Income Estimation: 
$123,167 - $152,295
Income Estimation: 
$146,673 - $180,130
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$77,657 - $95,021
Income Estimation: 
$97,257 - $120,701

Sign up to receive alerts about other jobs with skills like those required for the Associate Vulnerability Researcher.

Click the checkbox next to the jobs that you are interested in.

  • Bug/Defect Analysis Skill

    • Income Estimation: $72,620 - $96,681
    • Income Estimation: $74,092 - $105,774
  • Computer Simulation Skill

    • Income Estimation: $77,439 - $91,585
    • Income Estimation: $77,510 - $95,546
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Carnegie Mellon University

Carnegie Mellon University
Hired Organization Address Pittsburgh, PA Full Time
Carnegie Mellon is enjoying its most productive fundraising years in its history, surpassing the initial fundraising goa...
Carnegie Mellon University
Hired Organization Address Pittsburgh, PA Full Time
The CERT division of the Software Engineering Institute (SEI), a federally funded research and development center at Car...
Carnegie Mellon University
Hired Organization Address Pittsburgh, PA Full Time
Position Summary: As part of the Cyber Risk and Resilience Directorate, you will be part of a team of engineers aimed at...
Carnegie Mellon University
Hired Organization Address Pittsburgh, PA Full Time
What We Do: The SEI helps advance software engineering principles and practices and serves as a national resource in sof...

Not the job you're looking for? Here are some other Associate Vulnerability Researcher jobs in the Pittsburgh, PA area that may be a better fit.

Associate Vulnerability Researcher

Software Engineering Institute | Carnegie Mellon University, Pittsburgh, PA

Junior Vulnerability Researcher

ANALYGENCE, Inc, Scottdale, PA

AI Assistant is available now!

Feel free to start your new journey!