Defensive Cybersecurity Engineer/Blue Team

MITRE Corporation
McLean, VA, United States
1 day ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
8 years minimum
Compensation
$158,800.0 - $198,500.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Cyber Security Continuous Integration Intrusion Detection and Prevention Network Security Machine Learning Security Software Reinforcement Learning Deep Learning Generative AI Malware Cybercrime
+3 more
Cyber Warfare Splunk Blue Team (Cyber Security)

Job description

  • Combining cybersecurity domain expertise and contemporary data science skills to enhance adversary detection, network defense, and Security Operations Center (SOC) process improvement.
  • Developing AI-enabled cybersecurity tools for anomaly detection, behavioral analytics, malware analysis, and adversary emulation.
  • Researching emerging AI techniques (e.g., machine learning, deep learning, generative AI, reinforcement learning) and assessing their applicability to defensive cyber missions.
  • Using MITRE ATT&CK® to hunt the adversary and build TTP-based defenses.
  • Using detection engineering to create security analytics and dashboards in Splunk or Elastic and integrating new data feeds
  • Automating container environments via continuous integration and continuous deployment (CI/CD)
  • Acting as a trusted advisor to the Federal Government

Requirements

  • Typically requires a minimum of 8 years of related experience with a Bachelor’s degree; or 6 years and a Master’s degree; or a PhD with 3 years’ experience; or equivalent combination of related education and work experience
  • Knowledge of cyber security operations and cyber security principles and their application
  • Experience in at least one of: security operations centers, threat hunting, detection engineering, malware analysis, or cyber deception
  • Applicants selected for this position will be subject to a government clearance security investigation and must meet eligibility requirements for access to classified information
  • Must have an active Top Secret U.S Government issued Security Clearance. Per the U.S. Government’s eligibility requirements, you must be a U.S Citizen to be considered for a security clearance
  • This position requires a minimum of 50% hybrid on-site

Preferred Qualifications:

  • Experience with Splunk or Elastic/ELK
  • Experience using MITRE ATT&CK®
  • Experience using or developing AI tools and techniques for defensive cyber operations
  • TS/SCI preferred

Benefits & conditions

Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That’s because MITRE people are committed to tackling our nation’s toughest challenges-and we’re committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work for the public interest, with no commercial conflicts to influence what we do. The R&D centers we operate for the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation. We’re making a difference every day-working for a safer, healthier, and more secure nation and world. Our workplace reflects our values. We offer competitive benefits, exceptional professional development opportunities for career growth, and a culture of innovation that embraces adaptability, collaboration, technical excellence, and people in partnership. If this sounds like the choice you want to make, then choose MITRE - and make a difference with us.

Department Summary:

MITRE’s Defensive Cyber Operations department is seeking creative people to work collaboratively with our staff of cybersecurity engineers in the fields of defensive cyber operations, threat hunting, detection engineering, and cyber deception and adversary engagement with increasing emphasis on Artificial Intelligence (AI) to support mission-driven cybersecurity initiatives for government sponsors.

This role blends hands-on defensive operations with advanced research and applied development in AI-enabled cybersecurity. The successful candidate will help design, implement, and evaluate next-generation defensive capabilities that leverage machine learning, large language models, autonomous systems, and advanced analytics to protect mission-critical systems and national infrastructure.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

5:11 min

Deploying manual Seccomp profiles to block malware

Dimitrij Klesev +1 · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:27 min

Differences between autonomous AI agents and traditional malware

Michele Zuccala Michele Zuccala +4 · WWC Europe 2026

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

Videos

See all

Related articles

See all