Critical Infrastructure Systems Security and Resilience, Principal

The MITRE Corporation

$172K — $259K *
Energy & Utilities
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Minimum 10 years’ experience with relevant bachelor's degree; or 8 years with master's; or 5 years with PhD; or equivalent experience.
  • Degree in Engineering, Computer Science, Cybersecurity or related field.
  • Significant experience in industrial control systems (ICS), Operational Technology (OT) or cyber-physical systems.
  • Experience with OT cybersecurity tools and techniques.
  • Strong analytical skills for assessing critical infrastructure threats and risks.
  • Demonstrated leadership and mentorship skills for technical teams.
  • Active Top Secret clearance required.

Responsibilities

  • Lead a 5-person technical team, ensuring quality and mission impact.
  • Engage with government sponsors and senior MITRE leaders regularly.
  • Advise stakeholders on capabilities and policies for CI cyber intelligence.
  • Collaborate with internal teams to enhance cyber resilience efforts at MITRE.
  • Align diverse government and contractor stakeholders to meet sponsor objectives.
  • Balance leadership roles with direct technical contributions as needed.
  • Conduct in-depth threat and risk analysis for critical infrastructure.

Benefits

  • Active mentoring and professional development opportunities.
  • Collaborative working environment with cross-discipline teams.
  • Engagement with high-level government and industry stakeholders.
  • Opportunity for influence in national security and cyber infrastructure.
  • Dynamic and inclusive workplace culture focused on innovation.
Full Job Description
Are you ready to defend national critical infrastructure from evolving non-kinetic cyber threats? The Critical Infrastructure Protection Department (L561), sitting within MITRE's Cyber-Physical Systems Division, delivers innovative solutions to sponsor challenges critical to national security and public sector missions. Our multidisciplinary team researches, develops, and applies advanced technologies to ensure the operational resilience of vital national assets. Our core focus areas include: - Infrastructure Susceptibility Analysis - Safety Engineering - Threat-Informed Recommendations - Critical Infrastructure (CI) Threat Detection, Analytics, & Adversary Emulation - Operational Technology (OT) Device Security & Space System OT - Cross-Sector Interdependency Analysis - Defense Critical Infrastructure Expertise - Civilian Critical Infrastructure Sector-Specific Expertise **Roles & Responsibilities** **Team & Strategic Leadership** - **Shape & Lead the Work:** Own accountability for staffing, mentorship, execution, quality, and mission impact for a 5-person technical team. - **Sponsor Engagement:** Engage frequently with the DoW sponsor and report directly to senior business leaders at MITRE. - **Strategic Advisory:** Guide government stakeholders and private owner/operators in building and advancing their capabilities and policy for CI cyber threat intelligence, risk-to-mission analysis, detection engineering, attack recognition, threat hunting, and threat-informed mitigation. - **Internal Collaboration:** Coordinate internally with cross-MITRE efforts to improve DoW cyber resilience; contribute to thought leadership and inform MITRE's CI capability stewardship. - **External Influence:** Foster alignment across diverse government and contractor stakeholders to achieve sponsor goals. - **Agility:** Pivot fluidly between team leadership, individual technical contribution, and informing department-level strategy. **Technical & Mission Execution** - **Threat Analysis:** Track and analyze adversary tactics, techniques, and procedures (TTPs) relevant to industrial control systems (ICS), Operational Technology (OT), space system OT, and cyber-physical technologies. - **OT Cybersecurity:** Produce evidence-based recommendations to inform stakeholder decisions about OT protection and monitoring. - **All-Source Research:** Lead technical research using open-source, classified, and all-source information to characterize infrastructure systems, dependencies, and potential attack paths. - **Apply Adversary Thinking:** Assess how threat actors could target critical infrastructure systems, exploit technologies, and cause operational impacts; identify intelligence gaps; prioritize analyses and mitigations. - **Risk & Resilience Assessments:** Lead and perform cyber threat modeling, mission impact analyses, and supply chain risk analyses for critical infrastructure and space systems. - **Intelligence and Data Fusion:** Fuse intelligence, technical, and operational data into products that support mission assurance and risk-informed decision-making. - **Actionable Insights:** Work closely with OT engineers, infrastructure SMEs, and Mission SMEs to synthesize and translate complex all-source information into clear, decision-focused insights and recommendations (reports, white papers, strategic briefings, graphics) for senior leaders. **Basic Qualifications** - **Experience:** Typically requires a minimum of 10 years of related experience with a bachelor's degree; or 8 years and a master's degree; or a PhD with 5 years' experience; or equivalent combination of related education and work experience. - **Education:** Degree in Electrical, Mechanical, or Civil Engineering, Computer Science, Cybersecurity, Intelligence Studies, or a related technical field (equivalent utility, intelligence, military, or industrial experience may be considered). - **Core Technical Domain:** Significant experience with industrial control systems (ICS), Operational Technology (OT), SCADA, cyber-physical systems, or other critical infrastructure technologies in engineering, cyber defense, intelligence, research, or operational environments. - **OT Cyber Tooling:** Experience with OT threat monitoring platforms (e.g., Dragos, Nozomi, Claroty, Malcolm), the MOSAICS framework, industrial firewalls (e.g., Fortinet), OT Software-Defined Networking (SDN), OT Zero Trust architectures (e.g., BlastWave), OT device hardening best practices and research, and Cyber-Informed Engineering (CIE) principles - **Analytical Capability:** Experience applying engineering or intelligence expertise to analyze CI dependencies, threats, vulnerabilities, adversary behaviors, and mission risks. - **Team Leadership:** Evidence of accountability and impact when leading customer engagement, technical strategy, planning, budgeting, execution, and mentorship for teams of 4+ technical staff. - **DoW Domain Expertise:** Previous government or contractor experience supporting the Department of War (DoW). - **Executive Presence & Lead-by-Influence:** Demonstrated ability to operate within senior leadership circles (GS-15, SES, or O-6+ ranks) to lead through influence, build trusted relationships, and advocate for government interests among diverse stakeholders with competing priorities. - **Technical Translation & Communication:** Mastery in synthesizing highly complex technical findings into crystal-clear presentations, graphics, formal reports, and data-driven recommendations tailored precisely for both technical engineers and non-technical executive stakeholders. - **Clearance Requirement: **Must have an active Top Secret U.S Government issued Security Clearance and must be eligible to obtain and maintain a Top Secret/SCI U.S Government issued Security Clearance. Per the U.S. Government's eligibility requirements, you must be a U.S Citizen to be considered for a security clearance - **Work Location & Presence: **This position requires a minimum of 4 days a week on-site. A minimum of 2 of those days must be spent at the Mark Center (Alexandria, VA); the remaining required on-site time may be fulfilled at the Mark Center, MITRE campuses, or other government facilities. **Preferred Qualifications** - **Clearance:** Active or recent (within 2 years) TS/SCI preferred. - **Sector-Specific Expertise:** Operational, engineering, or cyber defense experience related to electric power, oil and gas, nuclear energy, transportation, water, telecommunications, manufacturing, space systems, or weapons systems. - **System Architecture & Tooling:** Significant knowledge and hands-on experience with ICS/OT architectures (SCADA, DCS, PLCs) and proficiency with native industrial development environments (e.g., TIA Portal, PAC Machine Edition, ladder logic, IEC 61131). - **Protocols & Cyber-Physical Security:** Strong understanding of security principles unique to cyber-physical systems, including the analysis of industrial (Modbus, DNP3, ProfiNET) and specialized communications protocols (BACnet, CAN, MIL-STD-1553). - **Standards & Frameworks:** Familiarity with cybersecurity policies and standards (NIST SP 800-82, NERC-CIP, DoD Zero Trust Strategy, IEC 62443) and threat frameworks like MITRE ATT&CK® for ICS. - **All-Source Threat Research:** Demonstrated experience conducting technical research across open-source, classified, and all-source intelligence to accurately characterize industrial technologies, infrastructure dependencies, and evolving adversary TTPs. - **Threat-Informed Defense & Frameworks:** Proven capability translating threat intelligence and vulnerability data into actionable security controls, risk modeling, and resilience planning; includes hands-on familiarity with frameworks like MITRE ATT&CK® to inform defensive postures. - **Advanced Technical Skills:** Experience with embedded system firmware, real-time operating systems (RTOS), or software development languages (Python, Java, C/C++, JavaScript). - **Emerging Technology:** Knowledge of state-of-the-art methods to support data analytics and intelligence, including the deployment and design of generative and agentic AI. - **Business Acumen:** Demonstrated success shaping new work, contributing to winning proposals, growing sponsor relationships, or managing multi-stakeholder agreements. **This requisition requires the candidate to have a minimum of the following clearance(s):** Top Secret **This requisition requires the hired candidate to have or obtain, within one year from the date of hire, the following clearance(s):** Top Secret/SCI **Salary compensation range and midpoint:** $172,800 - $216,000 - $259,200 Annual **Work Location Type:** Onsite

Similar Jobs

More Jobs at The MITRE Corporation

More Energy & Utilities Jobs

Find similar Critical Infrastructure Systems Security and Resilience, Principal jobs: