> Markdown version of [/jobs/ext/2078824-critical-infrastructure-systems-security-and-resilience-principal](https://www.wearedevelopers.com/jobs/ext/2078824-critical-infrastructure-systems-security-and-resilience-principal). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Critical Infrastructure Systems Security and Resilience, Principal - **Company:** MITRE Corporation - **Location:** McLean, VA, United States - **Experience:** Expert - **Salary:** $172,800.0 - $216,000.0 - **Contract:** Permanent contract - **Skills:** Java (Programming Language), JavaScript (Programming Language), Data Analysis, C++ (Programming Language), Communications Protocols, Cyber Security, Data Fusion, Emulators, Firmware, Supervisory Control and Data Acquisition (SCADA), Intrusion Detection and Prevention, Python (Programming Language), Ladder Logic, Modbus, Operational Data Store, Open Source Technology, Real-Time Operating Systems, Zero Trust Network Access, Cyber-physical Systems, Software Engineering, Systems Architecture, EndPointSecurity, Mitre Att&ck, Cyber Threat Analysis, Tia Portal, Information Technology, SDN Network, Bacnet, Process Control Systems, Data Analytics, Operational Systems, Fortinet, Cyber Warfare - **Published:** August 16, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3355987143&tx=KL3737FFF&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Experience: Typically requires a minimum of 10 years of related experience with a bachelor's degree; or 8 years and a master's degree; or a PhD with 5 years' experience; or equivalent combination of related education and work experience. * Education: Degree in Electrical, Mechanical, or Civil Engineering, Computer Science, Cybersecurity, Intelligence Studies, or a related technical field (equivalent utility, intelligence, military, or industrial experience may be considered). * Core Technical Domain: Significant experience with industrial control systems (ICS), Operational Technology (OT), SCADA, cyber-physical systems, or other critical infrastructure technologies in engineering, cyber defense, intelligence, research, or operational environments. * OT Cyber Tooling: Experience with OT threat monitoring platforms (e.g., Dragos, Nozomi, Claroty, Malcolm), the MOSAICS framework, industrial firewalls (e.g., Fortinet), OT Software-Defined Networking (SDN), OT Zero Trust architectures (e.g., BlastWave), OT device hardening best practices and research, and Cyber-Informed Engineering (CIE) principles * Analytical Capability: Experience applying engineering or intelligence expertise to analyze CI dependencies, threats, vulnerabilities, adversary behaviors, and mission risks. * Team Leadership: Evidence of accountability and impact when leading customer engagement, technical strategy, planning, budgeting, execution, and mentorship for teams of 4+ technical staff. * DoW Domain Expertise: Previous government or contractor experience supporting the Department of War (DoW). * Executive Presence & Lead-by-Influence: Demonstrated ability to operate within senior leadership circles (GS-15, SES, or O-6+ ranks) to lead through influence, build trusted relationships, and advocate for government interests among diverse stakeholders with competing priorities. * Technical Translation & Communication: Mastery in synthesizing highly complex technical findings into crystal-clear presentations, graphics, formal reports, and data-driven recommendations tailored precisely for both technical engineers and non-technical executive stakeholders. * Clearance Requirement: Must have an active Top Secret U.S Government issued Security Clearance and must be eligible to obtain and maintain a Top Secret/SCI U.S Government issued Security Clearance. Per the U.S. Government's eligibility requirements, you must be a U.S Citizen to be considered for a security clearance * Work Location & Presence: This position requires a minimum of 4 days a week on-site. A minimum of 2 of those days must be spent at the Mark Center (Alexandria, VA); the remaining required on-site time may be fulfilled at the Mark Center, MITRE campuses, or other government facilities. Preferred Qualifications * Clearance: Active or recent (within 2 years) TS/SCI preferred. * Sector-Specific Expertise: Operational, engineering, or cyber defense experience related to electric power, oil and gas, nuclear energy, transportation, water, telecommunications, manufacturing, space systems, or weapons systems. * System Architecture & Tooling: Significant knowledge and hands-on experience with ICS/OT architectures (SCADA, DCS, PLCs) and proficiency with native industrial development environments (e.g., TIA Portal, PAC Machine Edition, ladder logic, IEC 61131). * Protocols & Cyber-Physical Security: Strong understanding of security principles unique to cyber-physical systems, including the analysis of industrial (Modbus, DNP3, ProfiNET) and specialized communications protocols (BACnet, CAN, MIL-STD-1553). * Standards & Frameworks: Familiarity with cybersecurity policies and standards (NIST SP 800-82, NERC-CIP, DoD Zero Trust Strategy, IEC 62443) and threat frameworks like MITRE ATT&CK for ICS. * All-Source Threat Research: Demonstrated experience conducting technical research across open-source, classified, and all-source intelligence to accurately characterize industrial technologies, infrastructure dependencies, and evolving adversary TTPs. * Threat-Informed Defense & Frameworks: Proven capability translating threat intelligence and vulnerability data into actionable security controls, risk modeling, and resilience planning; includes hands-on familiarity with frameworks like MITRE ATT&CK to inform defensive postures. * Advanced Technical Skills: Experience with embedded system firmware, real-time operating systems (RTOS), or software development languages (Python, Java, C/C++, JavaScript). * Emerging Technology: Knowledge of state-of-the-art methods to support data analytics and intelligence, including the deployment and design of generative and agentic AI. * Business Acumen: Demonstrated success shaping new work, contributing to winning proposals, growing sponsor relationships, or managing multi-stakeholder agreements. This requisition requires the candidate to have a minimum of the following clearance(s) ## Description * Safety Engineering * Threat-Informed Recommendations * Critical Infrastructure (CI) Threat Detection, Analytics, & Adversary Emulation * Operational Technology (OT) Device Security & Space System OT * Cross-Sector Interdependency Analysis * Defense Critical Infrastructure Expertise * Civilian Critical Infrastructure Sector-Specific Expertise Roles & Responsibilities Team & Strategic Leadership * Shape & Lead the Work: Own accountability for staffing, mentorship, execution, quality, and mission impact for a 5-person technical team. * Sponsor Engagement: Engage frequently with the DoW sponsor and report directly to senior business leaders at MITRE. * Strategic Advisory: Guide government stakeholders and private owner/operators in building and advancing their capabilities and policy for CI cyber threat intelligence, risk-to-mission analysis, detection engineering, attack recognition, threat hunting, and threat-informed mitigation. * Internal Collaboration: Coordinate internally with cross-MITRE efforts to improve DoW cyber resilience; contribute to thought leadership and inform MITRE's CI capability stewardship. * External Influence: Foster alignment across diverse government and contractor stakeholders to achieve sponsor goals. * Agility: Pivot fluidly between team leadership, individual technical contribution, and informing department-level strategy. Technical & Mission Execution * Threat Analysis: Track and analyze adversary tactics, techniques, and procedures (TTPs) relevant to industrial control systems (ICS), Operational Technology (OT), space system OT, and cyber-physical technologies. * OT Cybersecurity: Produce evidence-based recommendations to inform stakeholder decisions about OT protection and monitoring. * All-Source Research: Lead technical research using open-source, classified, and all-source information to characterize infrastructure systems, dependencies, and potential attack paths. * Apply Adversary Thinking: Assess how threat actors could target critical infrastructure systems, exploit technologies, and cause operational impacts; identify intelligence gaps; prioritize analyses and mitigations. * Risk & Resilience Assessments: Lead and perform cyber threat modeling, mission impact analyses, and supply chain risk analyses for critical infrastructure and space systems. * Intelligence and Data Fusion: Fuse intelligence, technical, and operational data into products that support mission assurance and risk-informed decision-making. * Actionable Insights: Work closely with OT engineers, infrastructure SMEs, and Mission SMEs to synthesize and translate complex all-source information into clear, decision-focused insights and recommendations (reports, white papers, strategic briefings, graphics) for senior leaders. ## Related Videos - [WeAreDevelopers LIVE - Back to CODE100](https://www.wearedevelopers.com/videos/1909-wearedevelopers-live-back-to-code100) - [Optimizing Land-Based Fish Feeding with Node-RED](https://www.wearedevelopers.com/videos/2032-optimizing-land-based-fish-feeding-with-node-red) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)