Lead IC Security Engineer

MITRE Corporation
McLean, VA, United States
8 days ago
Apply on www.juju.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$158,800.0 - $198,500.0
Working hours
Regular working hours
Job source

Tech stack

Xacta Amazon Web Services Computing Platforms Systems Engineering Audit Trail Cloud Computing Cloud Engineering Cyber Security Information Systems Computer Engineering Data as a Services Document Management Systems
+25 more
Distributed Systems Data Flow Control Geospatial Intelligence Identity and Access Management Ansible Security Software Shell Script Security Information and Event Management Software Engineering Systems Architecture Systems Integration Software Vulnerability Management Data Logging Data Processing Cloud Platform System Software Security Kubernetes Information Technology Data Management CIS Benchmarks Terraform Devsecops Docker Static Application Security Testing Microservices

Job description

MITRE’s National Intelligence Division is seeking a Lead IC Security Engineer to provide hands-on security engineering and authorization support for a prototype geospatial intelligence and identity intelligence platform composed of several integrated systems for an Intelligence Community sponsor. This full-time role will oversee the implementation of security controls, secure configurations, and authorization documentation needed for the prototype to meet ICD-503 requirements and NIST SP 800-53 Rev. 5 controls and to support an Authority to Operate (ATO) submission.

The successful candidate will serve as the security engineering focal point for the prototype, reviewing and documenting engineering and development changes, assessing their security impact, and ensuring that system design, implementation, and operation remain aligned with the approved security baseline. The engineer will work closely with the cloud infrastructure engineer, who will lead cloud environment setup and workflow implementation, to translate security requirements into secure cloud configurations, pipeline controls, automated checks, logging, evidence collection, and repeatable deployment practices.

Roles & Responsibilities:

  • Lead the security engineering approach for the prototype platform, mapping system architecture, components, services, and configurations to applicable ICD-503 requirements, NIST SP 800-53 Rev. 5 controls, and sponsor security expectations.

  • Oversee implementation, validation, and documentation of technical, operational, and management security controls across cloud infrastructure, applications, interfaces, data services, and supporting platform components.

  • Develop and maintain the security documentation and evidence package supporting the ATO submission, including control implementation statements, architecture and data-flow artifacts, configuration evidence, test results, risk decisions, remediation status, and other sponsor-required authorization artifacts.

  • Review and document system, software, infrastructure, and configuration changes; assess security and authorization impacts; maintain traceability to requirements and controls; and help keep the system security baseline current as the prototype evolves.

  • Partner directly with the cloud infrastructure engineer responsible for cloud setup and workflows to implement secure infrastructure configurations, pipeline security gates, automated security testing, vulnerability and dependency scanning, secrets handling, audit logging, and repeatable compliance evidence collection.

  • Collaborate with software developers, systems engineers, architects, data engineers, and test teams to integrate security into design, development, integration, test, deployment, and operations; identify findings and technical risks; and drive practical remediation actions.

  • Coordinate with sponsor security and authorization stakeholders to prepare for control assessments, respond to questions and findings, track corrective actions to closure, and maintain an authorization-ready security posture throughout prototype development and transition.

Requirements

  • Typically requires a minimum of 8 years of related experience with a Bachelor’s degree; or 6 years with a Master’s degree; or 3 years with a PhD; or an equivalent combination of education and relevant experience.

  • Bachelor’s degree in Cybersecurity, Computer Science, Computer Engineering, Systems Engineering, Information Systems, Engineering, or a related technical field, or equivalent combination of education and experience.

  • Demonstrated security engineering experience supporting complex software-intensive, cloud-based, or distributed systems in classified or other high-assurance environments.

  • Hands-on experience interpreting, implementing, documenting, and assessing NIST SP 800-53 security controls and supporting Risk Management Framework (RMF) authorization activities, including preparation of ATO artifacts and evidence.

  • Must have experience with the following technologies: wide range of AWS services, Terraform/OpenTofu, Ansible, containers and container orchestration (Docker, Kubernetes), Linux shell scripting, and CI/CD pipelines.

  • Working knowledge of ICD-503 and Intelligence Community cybersecurity, authorization, and security control implementation expectations.

  • Experience reviewing system and software changes for security impact and maintaining configuration, control, and authorization documentation as systems evolve.

  • Experience securing cloud environments and modern development platforms, including identity and access management, network protections, encryption, logging/monitoring, vulnerability management, secure configuration, and data protection.

  • Experience collaborating with cloud infrastructure and software engineering teams in DevSecOps environments, including integrating security requirements and automated checks into infrastructure-as-code and workflows.

  • Strong written and verbal communication skills, including the ability to produce clear technical security documentation, explain risk and control decisions, and work effectively with government sponsors and multidisciplinary technical teams.

  • Must have an active Top Secret/SCI with Poly U.S Government issued Security Clearance. Per the U.S. Government’s eligibility requirements, you must be a U.S Citizen to be considered for a security clearance.

  • This position has an on-site requirement of 5 days a week on-site.

Preferred Qualifications:

  • Prior experience serving as an Information Systems Security Engineer (ISSE), security engineer, ISSO, or comparable cybersecurity role supporting an IC or DoD system authorization.

  • Experience leading security engineering and ATO activities for cloud-native prototypes, data platforms, microservices, or multi-system integration efforts.

  • Experience with automated compliance and evidence collection, infrastructure-as-code security, SAST/SCA/container/IaC scanning, vulnerability management, SIEM/logging platforms, and DevSecOps security tooling.

  • Experience applying secure configuration guidance such as DISA STIGs, CIS benchmarks, or sponsor-specific hardening standards where applicable.

  • Experience with authorization/GRC tooling such as Xacta, eMASS, or sponsor-equivalent platforms.

  • Familiarity with security considerations for geospatial, identity, intelligence, and sensitive data platforms, including access control, data handling, auditing, and cross-system interfaces.

  • Relevant cybersecurity certification such as CISSP, CCSP, Security+, or equivalent technical/security credential.

  • Ability to build trust quickly with senior sponsors, operate with sound judgment and minimal direction, and balance mission delivery with security and authorization requirements.

This requisition requires the candidate to have a minimum of the following clearance(s):

Top Secret/SCI/Polygraph

About the company

Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That’s because MITRE people are committed to tackling our nation’s toughest challenges-and we’re committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work for the public interest, with no commercial conflicts to influence what we do. The R&D centers we operate for the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation. We’re making a difference every day-working for a safer, healthier, and more secure nation and world. Our workplace reflects our values. We offer competitive benefits, exceptional professional development opportunities for career growth, and a culture of innovation that embraces adaptability, collaboration, technical excellence, and people in partnership. If this sounds like the choice you want to make, then choose MITRE - and make a difference with us.

The Mission Operations Department supports national intelligence mission centers by strengthening warning, collection, analysis, enterprise coordination, and strategy execution. The department helps senior government sponsors identify seams across mission areas, reduce fragmentation, and build integrated responses to complex national security challenges. It provides the policy, analytic, operational, cybersecurity, and technical depth required to help mission partners work as a unified enterprise advancing intelligence integration and national security outcomes., Copyright © 1997-2026, The MITRE Corporation. All rights reserved. MITRE is a registered trademark of The MITRE Corporation. Material on this site may be copied and distributed with permission only.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.juju.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · World Congress 2024

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:19 min

Executing complex workflows using Ansible Automation Platform

Goetz Rieger Goetz Rieger · World Congress 2025

2:34 min

Docker sandbox architecture and microVM environment integration

Manuel de la Peña Manuel de la Peña · World Congress 2026 Europe

Videos

See all

Related articles

See all