Lead Cybersecurity Engineer
About the Role
The Cyber Strategy, Policy, Privacy, and Risk Department (L526) is seeking a Cybersecurity and Privacy Strategy & Policy Principal Cybersecurity Engineer. This department features leaders and staff who work with our sponsors to position sponsor programs for the future. The department leads MITRE's technical capability areas in Cybersecurity Strategy and Policy and Privacy and Data Protection. Our team of cybersecurity professionals apply leading edge thinking to develop effective sponsor cybersecurity and privacy strategies and policies implemented through appropriate cybersecurity and privacy-enhancing technologies, tools, practices, and frameworks. Through collaborative work with our sponsors, we provide expertise to ensure information and cybersecurity programs meet organizational and business mission requirements, and we establish mechanisms that gauge operational security effectiveness. Through partnerships, we leverage MITRE's cyber expertise to raise cybersecurity maturity nationally and internationally by engaging with traditional and non-traditional partners and sponsors to address broad reaching cyber security challenges, with a focus on risk frameworks, privacy, cyber supply chain risk management, strategic assessments, threat collaboration, and cyber workforce.
Responsibilities
- Lead cybersecurity technical, policy, and strategy, assessments and workshops for government agencies.
- Develop and implement security strategies for MITRE sponsors and programs
- Provide mentorship to junior professionals.
- Lead Cybersecurity Risk Management by demonstrating expert knowledge of cybersecurity risk management frameworks (RMF) and methodologies.
- Conduct Security Controls analysis, workshops, and audits for internal teams and partner organizations.
- Contribute technically to one or more Sponsor tasks.
- Collaborate effectively with MITRE, government, and contractors; effectively communicate in writing, presentations, and collaborative discussions; and interface with peers, managers, and sponsors.
- Promote collaboration and integration with other organizational elements within the department and across MITRE.
Basic Qualifications
- Bachelor of Science in Computer Science/Information Systems/ or related field with ten years of relevant experience.
- Typically requires a minimum of 8 years of related experience with a bachelor's degree; or 6 years and a master's degree; or a PhD with 3 years' experience; or equivalent combination of related education and work experience.
- Demonstrated experience creating or analyzing policy at Federal Department/ Agency level.
- Experience with RMF, NIST SP-800 series, Zero Trust, and Security Controls analysis.
- Experience in cybersecurity frameworks and application, including requirements analysis and technical writing.
- Familiarity with risks and risk frameworks applied to Windows, Linux, macOS/Open BSD, or other operating systems.
- Must have an active Secret U.S Government issued Security Clearance and must be eligible to obtain and maintain a Top-Secret U.S Government issued Security Clearance. Per the U.S. Government's eligibility requirements, you must be a U.S Citizen to be considered for a security clearance.
- This position requires a minimum of 4 days a week on-site
Preferred Qualifications
- Graduate-level degree in a technical discipline (Cybersecurity, Information Assurance, etc.) or 15 years of relevant experience.
- Familiarity with both Information Technology (IT), operational technology (OT), and National Security Systems (NSS).
- 7 years related experience as a cybersecurity analyst or systems/ network security engineer.
- Experience with various Security Information and Event Management (SIEM) platforms (Splunk, QRadar, Tenable products, etc.)
- Familiarity with cloud architectures such as AWS, Azure, or others
- Familiarity with defensive cybersecurity and DoW Information Network operations
- Certified Information Systems Security Professional (CISSP).
- GIAC Penetration Tester (GPEN), GIAC Certified Intrusion Analyst (GCIA)
- CompTIA Security+, CompTIA Network+, CompTIA Linux+
Pay
Salary compensation range and midpoint: $158,800 - $198,500 - $238,200 Annual
Schedule
Work Location Type: Onsite