Senior Identity Cybersecurity Engineer
About the role
At MITRE, you can engage in meaningful work while maintaining a fulfilling life. We are a not-for-profit corporation chartered to work for the public interest, with no commercial conflicts influencing our efforts. The R&D centers we operate for the government create lasting impact in fields such as cybersecurity, healthcare, aviation, defense, and enterprise transformation. Our workplace reflects our values, offering competitive benefits, professional development opportunities, and a culture of innovation.
The Cryptography, ICAM, & System Assurance (L527) Department is a multidisciplinary team driving innovation in Cryptography, System Assurance, and Identity, Credential and Access Management (ICAM). We develop scalable approaches, evaluate technology, lead external partnerships, and conduct novel research and development. Our critical roles include:
- Aiding the Federal Government in architecting and applying modern ICAM technologies to secure systems, software, and protocols, with a focus on zero trust architectures, post-quantum cryptography, non-human and agentic identity, and secure multi-party federation.
- Developing strategies, assessing policy and technical constraints, and facilitating the deployment of ICAM solutions into cloud, hybrid, and on-premises infrastructures for enterprise and tactical environments.
- Working at the intersection of Cybersecurity and AI on trustworthy approaches to applying AI to ICAM applications and developing frameworks for evaluating AI-based techniques.
- Performing research and development, evaluation, testing, and operational support for high-priority sponsor mission applications and MITRE Labs strategic initiatives.
Responsibilities
- Understand mission needs and translate them into ICAM technical requirements, interfaces, and measurable outcomes.
- Design and assess Zero-Trust-aligned ICAM architectures and reference designs.
- Engineer authentication, authorization, and federation solutions (e.g., SAML/OIDC, step-up authentication) and manage credentials/trust services (PKI, certificates).
- Support Identity Governance & Administration (IGA), including provisioning, joiner-mover-leaver workflows, and authoritative source integration.
- Develop, evaluate, and steer RBAC/ABAC/PBAC models, entitlement/attribute strategies, and privileged-access controls.
- Collaborate with engineers, integrators, and vendors on technology evaluation, trade studies, reusable assets, and mentorship.
Requirements
- Typically requires a minimum of 5 years of related experience with a bachelor’s degree; or 3 years and a master’s degree; or a PhD with relevant experience; or equivalent combination of education and work experience.
- Strong analytical and problem-solving skills with sound technical judgment.
- Excellent written and verbal communication skills.
- Demonstrated ability to deliver results and collaborate across teams.
- Ability to work effectively in secure/classified environments.
- Active Secret U.S. Government-issued Security Clearance (or ability to obtain one within one year of hire).
- U.S. citizenship is required for security clearance eligibility.
- This position requires a minimum of 4 days a week on-site.
Preferred Qualifications
- Degree in Computer Science, Cybersecurity, Electrical/Computer Engineering, or a related field.
- Systems engineering experience (requirements, architecture, integration, test) and familiarity with development lifecycles.
- Experience applying security principles to enterprise architecture and system design.
- Strong understanding of ICAM concepts supporting a Zero Trust security model.
- Familiarity with threats and attack patterns relevant to identity and access systems.
- Interest in applied research and building reusable, scalable technical approaches.
- TS/SCI eligibility preferred; willingness to take and successfully complete a CI polygraph is a plus.
- Active TS/SCI with CI polygraph preferred.
Pay
Salary compensation range: $129,200 - $161,500 - $193,800 annually.
Schedule
This position requires a minimum of 4 days a week on-site.