Operational Technology Cyber Threat Intelligence, Lead

The MITRE Corporation

$158K — $238K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Minimum 8 years of experience with a bachelor's degree, 6 years with a master's, or a PhD with 3 years' related experience.
  • Degree in Computer Science, Cybersecurity, Information Systems, or related field.
  • At least 2 years of hands-on experience in Operational Technology (OT) or Industrial Control Systems (ICS).
  • Familiarity with industrial communication protocols (e.g., Modbus TCP, DNP3, OPC UA/DA).
  • Experience applying ATT&CK for ICS or similar frameworks to analyze cyber threats.
  • Active Top Secret security clearance required.

Responsibilities

  • Analyze real-world adversary behaviors in ICS/OT environments.
  • Translate threat intelligence into technical requirements for automated emulation.
  • Track advanced persistent threats (APTs) targeting critical infrastructure.
  • Advise government sponsors on developing OT-specific threat intelligence programs.
  • Conduct risk assessments using frameworks like ATT&CK for ICS.
  • Produce actionable technical briefs and strategic briefings for stakeholders.
  • Collaborate with engineering teams to enhance threat defense strategies.

Benefits

  • Comprehensive health and dental insurance plans.
  • Generous paid time off and holiday schedule.
  • Retirement savings plans with company matching contributions.
  • Opportunities for professional development and continuing education.
  • Flexible working arrangements to promote work-life balance.
Full Job Description
Are you ready to defend national critical infrastructure from evolving non-kinetic threats? The Critical Infrastructure Protection Department (L561), sitting within MITRE's Cyber-Physical Systems Division, delivers innovative solutions to sponsor challenges critical to national security and public sector missions. Our multidisciplinary team researches, develops, and applies advanced technologies to ensure the operational resilience of vital national assets. Our core focus areas include: • Infrastructure Susceptibility Analysis • Safety Engineering • Threat-Informed Recommendations • Critical Infrastructure (CI) Threat Detection, Analytics, & Adversary Emulation • Operational Technology (OT) Device Security & Space System OT • Cross-Sector Interdependency Analysis • Defense Critical Infrastructure Expertise • Civilian Critical Infrastructure Sector-Specific Expertise Job Description: MITRE's Critical Infrastructure Protection Department (L561) is seeking an Operational Technology (OT) Cyber Threat Intelligence Lead to bridge the gap between deep OT threat intelligence and automated adversary emulation. In this role, you will analyze real-world adversary TTPs targeting industrial control systems (ICS), SCADA, and Space OT environments. You will distill complex OT threat reporting into operational behaviors, network communication patterns, and protocol mechanics-enabling our software engineering team to automate realistic attack scenarios in platforms like Caldera for OT. If you want to study real-world adversary behavior in complex cyber-physical/OT systems and strengthen national critical infrastructure alongside federal and industry partners, this role is for you. Roles & Responsibilities: • Adversary Behavior Deconstruction: Analyze real-world ICS/OT threat intelligence (e.g., PIPEDREAM, INCONTROLLER, Industroyer) to identify specific adversary behaviors, target device types, and network communication patterns. • Emulation Team Alignment: Translate OT threat intelligence into concrete technical requirements, attack flows, and protocol parameters for developers building automated emulation capabilities (e.g., Caldera for OT). • OT Threat Tracking: Track and characterize advanced persistent threats (APTs) targeting critical infrastructure, defense industrial base assets, and space system OT environments using unclassified and classified intel sources. • Sponsor Program Guidance: Advise government sponsors and critical infrastructure owner/operators on developing OT-specific threat intelligence programs and adopting threat-informed defense strategies. • Risk & Susceptibility Analysis: Conduct OT-focused threat modeling, mission impact analyses, and cyber-physical risk assessments using frameworks such as ATT&CK for ICS and SPARTA. • Technical Artifact Delivery: Produce actionable technical briefs, attack flow mappings, and strategic briefings tailored for both technical engineering teams and leadership Basic Qualifications: • Experience: Typically requires a minimum of 8 years of related experience with a bachelor's degree; or 6 years and a master's degree; or a PhD with 3 years' experience; or equivalent combination of related education and work experience. • Education: Degree in Computer Science, Cybersecurity, Information Systems, Intelligence Studies, Strategic Intelligence, or related field. • Direct OT Environment Experience: Minimum 2 years of hands-on experience analyzing, securing, or threat-modeling Operational Technology (OT), Industrial Control Systems (ICS), SCADA environments, or Space OT systems. (Experience limited to enterprise IT security will not satisfy this requirement.) • Industrial Protocol & Control Architecture Familiarity: Working understanding of common industrial communication protocols (e.g., Modbus TCP, DNP3, OPC UA/DA, Ethernet/IP) and lower-level control architecture (Purdue Model Levels 0-3). • ICS Threat Framework Application: Demonstrated experience applying ATT&CK for ICS, SPARTA, or Cyber Kill Chain for ICS to dissect adversary campaigns and analyze cyber-physical attack paths. • Clearance Requirement: Must have an active Top Secret U.S Government issued Security Clearance and must be eligible to obtain and maintain a Top Secret/SCI U.S Government issued Security Clearance. Per the U.S. Government's eligibility requirements, you must be a U.S Citizen to be considered for a security clearance. • On-Site Requirement: This position requires a minimum of 3 days a week on-site. 60% on-site presence required at MITRE or government locations in the National Capital Region. Preferred Qualifications: • Education: Advanced degree in a relevant technical field. • Active Clearance: Active TS/SCI security clearance. • PCAP & Traffic Analysis: Experience performing network packet capture analysis (e.g., Wireshark, Zeek) on industrial protocol traffic to differentiate normal operations from malicious commands. • Emulation & Red Teaming Collaboration: Experience partnering with red teams, penetration testers, or adversary emulation developers on threat simulation exercises. • Industry Certifications: Relevant OT/ICS certifications such as GIAC Global Industrial Cybersecurity Professional (GICSP), GIAC Response and Industrial Defense (GRID), or GIAC Critical Infrastructure Protection (GCIP). • Government & Sector Advisory: Experience partnering with organizations such as CISA, DoD, or Sector Risk Management Agencies (SRMAs) on threat reporting and mitigation guidance. This requisition requires the candidate to have a minimum of the following clearance(s): Top Secret This requisition requires the hired candidate to have or obtain, within one year from the date of hire, the following clearance(s): Top Secret/SCI Salary compensation range and midpoint: $158,800 - $198,500 - $238,200 Annual Work Location Type: Onsite Benefits information may be found here.

Similar Jobs

More Jobs at The MITRE Corporation

More Information Technology Jobs

Find similar Operational Technology Cyber Threat Intelligence, Lead jobs: