Threat Emulation and Exercises Capability Area Lead
Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That's because MITRE people are committed to tackling our nation's toughest challenges—and we're committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work for the public interest, with no commercial conflicts to influence what we do. The R&D centers we operate for the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation. We're making a difference every day—working for a safer, healthier, and more secure nation and world. Our workplace reflects our values. We offer competitive benefits, exceptional professional development opportunities for career growth, and a culture of innovation that embraces adaptability, collaboration, technical excellence, and people in partnership.
About the Role
The Cyber Operations Division (L510) is seeking a Capability Area Lead (CAL) for the Tier 3 Threat Emulation and Exercises Capability Area. This capability area will be part of the Cyber Intelligence Tier 2 capability within the Tier 1 Cyber Operations Technologies capability. The CAL is responsible for developing and executing the strategy for the capability. This is a leadership role that requires close collaboration with department and division leadership, other CALs, staff across the company working in the domain, relevant Research Program Leads, and portfolio and program division staff with sponsor opportunities related to the capability area.
Responsibilities
- Guiding capability area strategy and coordination: The CAL builds and executes the capability strategy in coordination with the Tier 2 Cyber Intelligence Capability Chief Engineer (CCE), prioritizing research, identifying and promoting re-usable capabilities, and ensuring the quality of work done in this area. The CAL also collaborates with the CAL for Cyber Intelligence Targeting on shared tools, frameworks, and tradecraft, and builds working relationships with Tier 1 and Tier 2 capabilities that draw on offensive security, threat emulation, assessments, and exercises, including Hard Targets and Technical Tradecraft, Critical Infrastructure Resilience, and Cryptography, Identity, and Data Protection.
- Driving impact across the work program: The CAL represents the capability area and, more broadly, the division’s work in that area to partner divisions, programs, and sponsors. It requires developing and delivering sponsor briefings, shaping and helping to staff work to meet the needs of the sponsor, and promoting external publication and sponsor presentations.
- Fostering a community of excellence and innovation: The CAL is the focal point and thought leader for the capability’s work in the division. The CAL organizes TEMs, trainings, and grows the division's skillset across both operational functions, and engages with the internal R&D program to help shape research priorities and mentor staff from ideation through proposal and execution. The CAL participates in hiring activities related to the capability area and advocates for the capability and the team through direct work, conference presentations, and open-source development.
Qualifications
- Typically requires a minimum of 10 years of related experience with a Bachelor's degree; or 8 years and a Master's degree; or a PhD with 5 years' experience; or equivalent combination of related education and work experience.
- Understanding of the missions, domains, and challenges of cybersecurity work with MITRE sponsors.
- Excellent written, oral, and interpersonal communication skills and a keen desire to learn. An open attitude to promoting the work of others.
- Knowledge of ATT&CK, Caldera, ATT&CK Evaluations, and MITRE's work in threat-informed defense.
- Experience scoping and conducting adversary emulation, simulation, or purple teaming.
- Experience with hands-on red teaming, penetration testing, and other offensive security operations.
- Experience designing and leading threat-driven cyber exercises, including tabletop and readiness exercises, along with threat assessments that prioritize adversary and mission relevance for stakeholders.
- Active Top Secret/SCI clearance. Per the U.S. Government’s eligibility requirements for a clearance, U.S Citizenship is required.
This position requires a minimum of 50% hybrid on-site.
Preferred Qualifications
- Experience creating offensive security tools, malware implants, or other red team capabilities in one or more programming languages.
- Demonstrated track record building strong internal and external partnerships.
This requisition requires the hired candidate to have or obtain, within one year from the date of hire, a Top Secret/SCI clearance.
Pay
Salary compensation range and midpoint: $172,800 - $216,000 - $259,200 Annual
Schedule
Work Location Type: Hybrid