Jobs · Information Technology · Alabama

Defensive Cybersecurity Engineer/Blue Team

MITRE · Huntsville, AL · 1 mo ago
Information Technology$159k–$199k/yrFull-time

Department Summary

The MITRE’s Defensive Cyber Operations department seeks creative individuals to work collaboratively with cybersecurity engineers in defensive cyber operations, threat hunt, detection engineering, and cyber deception and adversary engagement with increasing emphasis in Artificial Intelligence (AI).

Roles & Responsibilities

  • Combine cybersecurity domain expertise and contemporary data science skills to enhance adversary detection, network defense, and threat hunting process improvement.
  • Develop AI-enabled cybersecurity tools for anomaly detection, behavioral analytics, malware analysis, and adversary emulation.
  • Design, develop, and optimize advanced threat hunting methodologies, Splunk detections, analytics, and dashboards to improve cyber defense capabilities.
  • Develop scripts, APIs, and automation solutions that enhance cyber operations, improve analyst workflows, and integrate security platforms.
  • Research emerging AI techniques (e.g., machine learning, deep learning, generative AI, reinforcement learning) and assess their applicability to defensive cyber missions.
  • Use MITRE ATT&CK® to hunt the adversary and build TTP-based defenses.
  • Create security analytics and dashboards in Splunk or Elastic and integrate new data feeds.
  • Automate container environments via continuous integration and continuous deployment (CI/CD).
  • Act as a trusted advisor to the Federal Government.

Basic Qualifications

  • A minimum of 8 years of related experience with a Bachelor’s degree; or 6 years and a Master’s degree; or a PhD with 3 years’ experience; or equivalent combination of related education and work experience.
  • Significant experience with Splunk, including both backend administration and detection/content development.
  • Experience developing scripts and integrating APIs to automate cyber operations and security workflows.
  • Strong understanding of the MITRE ATT&CK knowledge base.
  • Excellent written and verbal communication skills, including experience presenting technical analysis to both technical and executive audiences.

Preferred Qualifications

  • Experience supporting or developing capabilities within the Augury platform.
  • Experience developing advanced Splunk analytics, detections, dashboards, and security content.
  • Experience with cyber automation, orchestration, and Security Operations Center (SOC) modernization initiatives.
  • Experience with Elastic/ELK.
  • Experience using MITRE ATT&CK®.
  • Experience using or developing AI tools and techniques for defensive cyber operations.

Similar jobs

Defensive Cyber Engineer

Allyon, Inc.Beale Air Force Base, CA· 3 wk ago
Engineering$140k–$155k/yrapply on allyon.my.salesforce-sites.com