Full Job Description
Are you ready to defend national critical infrastructure from evolving non-kinetic threats? The Critical Infrastructure Protection Department (L561), sitting within MITRE's Cyber-Physical Systems Division, delivers innovative solutions to sponsor challenges critical to national security and public sector missions. Our multidisciplinary team researches, develops, and applies advanced technologies to ensure the operational resilience of vital national assets.
Our core focus areas include:
• Infrastructure Susceptibility Analysis
• Safety Engineering
• Threat-Informed Recommendations
• Critical Infrastructure (CI) Threat Detection, Analytics, & Adversary Emulation
• Operational Technology (OT) Device Security & Space System OT
• Cross-Sector Interdependency Analysis
• Defense Critical Infrastructure Expertise
• Civilian Critical Infrastructure Sector-Specific Expertise
Job Description:
MITRE's Critical Infrastructure Protection Department (L561) is seeking a Lead Operational Technology (OT) Cybersecurity Engineer & Instructor to pioneer, maintain, and execute hands-on cyber experimentation and training within MITRE's state-of-the-art hardware-in-the-loop (HITL) ranges.
In this multi-faceted role, you will bridge physical engineering and cyber defense. You will design physical and simulated OT testbeds-featuring real PLCs, RTUs, relays, and SCADA software-and use them to conduct applied R&D, execute adversary attack exercises, and train government sponsors and critical infrastructure operators. You will turn range experimentation into actionable, evidence-based recommendations, defensive tactics, and high-impact training curricula that strengthen national security assets.
If you are passionate about getting your hands on physical control hardware, building realistic cyber-physical ranges, and educating the nation's top defenders, this role offers an unmatched platform.
Roles & Responsibilities:
• Hardware-in-the-Loop Range Leadership: Design, build, expand, and maintain hardware-in-the-loop (HITL) cyber experimentation ranges, integrating real-world PLCs, IEDs, RTUs, HMIs, and industrial network infrastructure.
• Curriculum & Exercise Delivery: Develop and lead hands-on technical training, lab exercises, and operational cyber exercises for government sponsors, military personnel, and critical infrastructure owner/operators.
• Applied OT Security Research: Execute applied R&D to test and evaluate new OT sensors, analytics, deception platforms, and defensive tools against realistic cyber-physical attack scenarios.
• Susceptibility & Attack Scenario Analysis: Conduct mission dependency, criticality, and adversary attack scenario analyses to identify vulnerabilities in cyber-physical architectures and recommend resilient countermeasures.
• Guidance & Synthesis: Translate complex experimentation findings into clear, evidence-based conclusions, strategic briefings, and technical guidance for executive leaders and operational engineers.
• Cross-Sector Collaboration: Partner with federal sponsors (e.g., CISA, DoD, DoE) and sector operators to establish requirements, prototype defensive TTPs, and transition technologies into operational environments.
Basic Qualifications:
• Experience & Education: Typically requires a minimum of 8 years of related experience with a Bachelor's degree in Electrical Engineering, Computer Engineering, Systems Engineering, Cybersecurity, or related technical field; or 6 years with a Master's degree; or a PhD with 3 years' experience.
• Direct OT Environment Experience: Minimum 2 years of hands-on experience working directly with Operational Technology (OT), SCADA, PLCs, RTUs, or industrial control network architectures across one or more critical infrastructure sectors (e.g., power, water, oil & gas, manufacturing, transportation). (Experience limited to enterprise IT will not satisfy this requirement.)
• Instruction & Technical Communication: Demonstrated experience developing and delivering technical training, lab tutorials, or hands-on exercises to technical audiences (e.g., engineers, operators, or cyber defenders).
• Industrial Protocols: Working understanding of industrial protocols (e.g., Modbus TCP, DNP3, OPC UA, Ethernet/IP, IEC 61850, or Siemens S7) and lower-level Purdue Model control mechanics.
• Travel Requirement: Willing and able to travel 25% (approximately 12 weeks per year), primarily within the United States.
• Clearance Requirement: Must be eligible to obtain and maintain a Top Secret/SCI U.S Government issued Security Clearance. Per the U.S. Government's eligibility requirements, you must be a U.S Citizen to be considered for a security clearance.
• On-Site Requirement: This position requires a minimum of 3 days a week on-site. 60% hybrid on-site presence required at MITRE or government locations in the National Capital Region.
Preferred Qualifications:
• Electric Sector Depth: Deep experience with industrial control architecture, protocols, and regulatory standards specific to the electric power sector (e.g., transmission/distribution substations, EMS/SCADA, IEC 61850, DNP3, NERC CIP compliance).
• SANS or Industry Instruction Experience: Prior experience creating or instructing formal OT/ICS security training courses (e.g., SANS ICS courses, CISA OT workshops, university labs, or military cyber ranges).
• Hardware & PLC Programming: Hands-on experience configuring, wiring, and programming PLCs/RTUs using native engineering software (e.g., TIA Portal, RSLogix/Studio 5000, PAC Machine Edition) or ladder logic / IEC 61131 standards.
• Range & Emulation Architecture: Experience with range orchestration, virtualization/containerization for OT (e.g., ESXi, GNS3, Docker), network packet manipulation (Wireshark, Scapy), or breach and attack simulation platforms.
• Scripting & Software Prototyping: Proficiency in Python, C/C++, or shell scripting for network automation, protocol parsing, or testbed control.
• Active Security Clearance: Active Secret, Top Secret, or TS/SCI security clearance.
This requisition requires the candidate to have a minimum of the following clearance(s):
None
This requisition requires the hired candidate to have or obtain, within one year from the date of hire, the following clearance(s):
Top Secret/SCI
Salary compensation range and midpoint:
$158,800 - $198,500 - $238,200 Annual
Work Location Type:
Onsite
Benefits information may be found here.