Threat Emulation and Exercises Capability Area Lead

The MITRE Corporation

$172K — $259K *
Technical Services
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of experience in cybersecurity or related fields, or 8 years with a Master's degree, or a PhD with 5 years' experience.
  • Deep understanding of cybersecurity missions, domains, and MITRE sponsors' challenges.
  • Strong communication skills, both written and verbal, with a focus on collaborative work.
  • Proficient in MITRE ATT&CK framework and related threat modeling tools such as Caldera.
  • Hands-on experience in adversary emulation, red teaming, and penetration testing.
  • Demonstrated ability in designing and leading cyber exercises relevant to different stakeholders.
  • Top Secret/SCI clearance and U.S. Citizenship required.

Responsibilities

  • Develop and execute strategy for threat emulation and exercises capability area.
  • Collaborate with Tier 2 capability leads to prioritize research and ensure quality outcomes.
  • Represent the capability area to external partners, developing sponsor briefings and staffing work accordingly.
  • Promote external publications and presentations on cybersecurity capabilities.
  • Foster a community of excellence by organizing training and enhancing team skillsets across operational functions.
  • Engage with internal R&D programs to shape research priorities and mentor staff effectively.
  • Participate in hiring activities and advocate for the capability area internally and externally.

Benefits

  • Hybrid work model, requiring a minimum of 50% on-site presence.
  • Opportunities for professional development through training and conferences.
  • Participation in mentorship programs for staff development.
  • Involvement in shaping cybersecurity R&D initiatives with academic and industry connections.
Full Job Description
Department Summary:

The Cyber Operations Division (L510) is seeking a Capability Area Lead (CAL) for the Tier 3 Threat Emulation and Exercises Capability Area. This capability area will be part of the Cyber Intelligence Tier 2 capability within the Tier 1 Cyber Operations Technologies capability. The CAL is responsible for developing and executing the strategy for the capability. This is a leadership role that requires close collaboration with department and division leadership, other CALs, staff across the company working in the domain, relevant Research Program Leads, and portfolio, and program division staff with sponsor opportunities related to the capability area.

Roles & Responsibilities:

Key functions of this role include:
  • Guiding capability area strategy and coordination: The CAL builds and executes the capability strategy in coordination with the Tier 2 Cyber Intelligence Capability Chief Engineer (CCE), prioritizing research, identifying and promoting re-usable capabilities, and ensuring the quality of work done in this area. The CAL also collaborates with the CAL for Cyber Intelligence Targeting on shared tools, frameworks, and tradecraft, and builds working relationships with Tier 1 and Tier 2 capabilities that draw on offensive security, threat emulation, assessments, and exercises, including Hard Targets and Technical Tradecraft, Critical Infrastructure Resilience, and Cryptography, Identity, and Data Protection.
  • Driving impact across the work program: The CAL represents the capability area and, more broadly, the division's work in that area to partner divisions, programs, and sponsors. It requires developing and delivering sponsor briefings, shaping and helping to staff work to meet the needs of the sponsor, and promoting external publication and sponsor presentations.
  • Fostering a community of excellence and innovation: The CAL is the focal point and thought leader for the capability's work in the division. The CAL organizes TEMs, trainings, and grows the division's skillset across both operational functions, and engages with the internal R&D program to help shape research priorities and mentor staff from ideation through proposal and execution. The CAL participates in hiring activities related to the capability area and advocates for the capability and the team through direct work, conference presentations, and open-source development.


Basic Qualifications:
  • Typically requires a minimum of 10 years of related experience with a Bachelor's degree; or 8 years and a Master's degree; or a PhD with 5 years' experience; or equivalent combination of related education and work experience.
  • Understanding of the missions, domains, and challenges of cybersecurity work with MITRE sponsors.
  • Excellent written, oral, and interpersonal communication skills and a keen desire to learn. An open attitude to promoting the work of others.
  • Knowledge of ATT&CK, Caldera, ATT&CK Evaluations, and MITRE's work in threat-informed defense.
  • Experience scoping and conducting adversary emulation, simulation, or purple teaming.
  • Experience with hands-on red teaming, penetration testing, and other offensive security operations.
  • Experience designing and leading threat-driven cyber exercises, including tabletop and readiness exercises, along with threat assessments that prioritize adversary and mission relevance for stakeholders.
  • Active Top Secret/SCI clearance.
  • Per the U.S. Government's eligibility requirements for a clearance, U.S Citizenship is required.
  • This position requires a minimum of 50% hybrid on-site.


Preferred Qualifications:
  • Experience creating offensive security tools, malware implants, or other red team capabilities in one or more programming languages.
  • Demonstrated track record building strong internal and external partnerships.


This requisition requires the candidate to have a minimum of the following clearance(s):
Top Secret/SCI

This requisition requires the hired candidate to have or obtain, within one year from the date of hire, the following clearance(s):
Top Secret/SCI

Salary compensation range and midpoint:
$172,800 - $216,000 - $259,200 Annual

Work Location Type:
Hybrid

It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Similar Jobs

More Jobs at The MITRE Corporation

More Technical Services Jobs

Find similar Threat Emulation and Exercises Capability Area Lead jobs: