Department Summary:MITRE's Defensive Cyber Operations department is seeking creative people to work collaboratively with our staff of cybersecurity engineers in the fields of defensive cyber operations, threat hunting, detection engineering, and cyber deception and adversary engagement with increasing emphasis on Artificial Intelligence (AI) to support mission-driven cybersecurity initiatives for government sponsors.
This role blends hands-on defensive operations with advanced research and applied development in AI-enabled cybersecurity. The successful candidate will help design, implement, and evaluate next-generation defensive capabilities that leverage machine learning, large language models, autonomous systems, and advanced analytics to protect mission-critical systems and national infrastructure.
Roles & Responsibilities:Our work responsibilities vary, but could include:
- Combining cybersecurity domain expertise and contemporary data science skills to enhance adversary detection, network defense, and Security Operations Center (SOC) process improvement.
- Developing AI-enabled cybersecurity tools for anomaly detection, behavioral analytics, malware analysis, and adversary emulation.
- Researching emerging AI techniques (e.g., machine learning, deep learning, generative AI, reinforcement learning) and assessing their applicability to defensive cyber missions.
- Using MITRE ATT&CK® to hunt the adversary and build TTP-based defenses.
- Using detection engineering to create security analytics and dashboards in Splunk or Elastic and integrating new data feeds
- Automating container environments via continuous integration and continuous deployment (CI/CD)
- Acting as a trusted advisor to the Federal Government
Basic Qualifications:- Typically requires a minimum of 8 years of related experience with a Bachelor's degree; or 6 years and a Master's degree; or a PhD with 3 years' experience; or equivalent combination of related education and work experience
- Knowledge of cyber security operations and cyber security principles and their application
- Experience in at least one of: security operations centers, threat hunting, detection engineering, malware analysis, or cyber deception
- Applicants selected for this position will be subject to a government clearance security investigation and must meet eligibility requirements for access to classified information
- Must have an active Top Secret U.S Government issued Security Clearance. Per the U.S. Government's eligibility requirements, you must be a U.S Citizen to be considered for a security clearance
- This position requires a minimum of 50% hybrid on-site
Preferred Qualifications: - Experience with Splunk or Elastic/ELK
- Experience using MITRE ATT&CK®
- Experience using or developing AI tools and techniques for defensive cyber operations
- TS/SCI preferred
This requisition requires the candidate to have a minimum of the following clearance(s):Top Secret
This requisition requires the hired candidate to have or obtain, within one year from the date of hire, the following clearance(s):Top Secret
Salary compensation range and midpoint:$158,800 - $198,500 - $238,200 Annual
Work Location Type:Hybrid