Cyber New Professionals Program

MITRE Corporation
Washington, DC, United States
8 days ago
Apply on careers.mitre.org
Prepare application

Role details

Contract type
Internship / Graduate position
Employment type
Full-time (> 32 hours)
Compensation
$85,200.0 - $106,500.0
Working hours
Regular working hours

Tech stack

Java (Programming Language) JavaScript (Programming Language) Artificial Intelligence Systems Engineering Business Process Model and Notation C++ (Programming Language) Cloud Computing Security Cyber Security Continuous Integration Software Debugging Dynamic Program Analysis Emulators
+23 more
Firmware Fuzz Testing Supervisory Control and Data Acquisition (SCADA) Identity and Access Management Python (Programming Language) Nmap Zero Trust Network Access Reverse Engineering Systems Modeling Language Wireless Networks EndPointSecurity Scripting Cloud Platform System Mitre Att&ck Malware Information Technology Metasploit Cybercrime Modeling and Simulation Workday Security Orchestration, Automation & Response Vulnerability Analysis Programming Languages

Requirements

want to make, then choose MITRE - and make a difference with us.<p style="text-align:inherit"></p><h3></h3><p>Launch your cybersecurity career through MITRE’s Cyber New Professionals (CNP) Program. You’ll tackle complex national cybersecurity challenges alongside leading experts while gaining hands-on experience, developing new skills, and building your professional network.</p><p></p><p>CNP combines:</p><ul><li>Structured onboarding to MITRE, its culture and organizational structure, and the CNP program</li><li>Varied project experience that builds broad cybersecurity expertise and depth in your areas of interest</li><li>Curated technical and professional training</li><li>Mentorship from MITRE cybersecurity experts</li><li>A cohort of early-career peers and networking opportunities across MITRE</li></ul><p></p><p>How the Program Works</p><p>CNP is a two-year program for staff at the beginning of their cybersecurity careers, including people who are new to many of the topics below. Project assignments are matched to your skills and interests, as well as project availability. After two years, you will graduate from CNP and transition into another MITRE department.</p><p></p><p>Roles & Responsibilities may include:</p><ul><li>Develop threat-informed, intelligence-enabled solutions using MITRE ATT&CK®, MITRE Engage , and MITRE Caldera to counter advanced adversaries</li><li>Research novel technical ideas, conduct rigorous analysis, and build proofs of concept that inform sponsor decisions</li><li>Apply threat-informed cybersecurity principles to protect critical systems and infrastructure from cyberattacks and other disruptions</li><li>Model and analyze cyber-physical, physical, human, and organizational systems</li><li>Analyze binaries, firmware, embedded systems, and industrial protocols; conduct vulnerability research, fuzzing, crash analysis, and mitigation assessments</li><li>Develop tested, documented, reproducible research software that integrates cybersecurity, artificial intelligence, systems engineering, and domain expertise</li><li>Collaborate with sponsors, vendors, and academia to advance cybersecurity practices</li></ul><p></p><p>Example Focus Areas</p><p>These areas show the breadth of CNP’s work, not the expected profile of a single candidate. You can be a strong candidate with experience in only one or a few of them. Your assignments will reflect your skills, interests, and available projects.</p><ul><li>Threat operations and analysis: adversary emulation; threat intelligence; defensive operations; deception and adversary engagement; cyber effects; analytics; malware analysis; forensics; assessments; and reverse engineering</li><li>Security architecture, trust, and governance: cloud security; cross-domain solutions; cryptography and trust; enterprise security architecture; identity, credentialing, and access management; privacy; strategy and governance; and supply-chain security</li><li>Critical and connected systems: critical infrastructure resiliency and safety; cyber resiliency and safety; Internet of Things (IoT) and operational technology (OT) security; OT engineering and response; modeling and simulation; adversary emulation; and countermeasures</li><li>Software and device security: security automation and management; software assurance; vulnerability research and exploitability analysis; and embedded, wireless, radio frequency (RF), and cellular security</li><li>Systems and emerging technology: autonomous cyber; systems and mission engineering; AI-enabled cross-domain engineering; and cyber-physical and human-system modeling</li></ul><p></p><p>Basic Qualifications</p><ul><li>Bachelor’s or graduate degree in a relevant field, such as engineering, applied physics, applied mathematics, computer science, or a related discipline, completed by your start date</li><li>Typically requires less than 2 years of related experience with a related bachelor’s degree, or equivalent combination of related education and work experience; internships and co-ops do not count toward this limit</li><li>Hands-on technical experience through employment, internships or co-ops, research laboratories, independent projects, capture-the-flag competitions, or similar work</li><li>Applied knowledge of cybersecurity principles, tools, and devices</li><li>Ability to obtain a U.S. government Top Secret security clearance; an active clearance is not required</li><li>Ability to work independently and collaboratively</li><li>Strong written and verbal communication skills, including presentation skills</li><li>Initiative and sound judgment when addressing novel, complex, or ambiguous problems</li><li>Strong organizational skills, including attention to detail, and the ability to manage multiple project components</li></ul><p></p><p>Preferred Qualifications</p><p>Experience in any of the following is helpful, but this is not a checklist. Candidates are not expected to have experience in all, or even most, of these areas:</p><ul><li>Proficiency in one or more scripting or programming languages, such as Python, Java, C/C++, or JavaScript, with an emphasis on testing, continuous integration, reproducibility, and maintainability</li><li>Security across operating systems, computer systems, mobile devices, enterprise and cloud environments, or wireless networks; experience with tools and frameworks such as Nmap, Metasploit, ATT&CK, RMF, CSF, or MITRE Caldera</li><li>Advanced cyber threats, adversary methods, static or dynamic analysis, debugging, disassembly, decomplication, instrumentation, emulation, or symbolic analysis</li><li>Vulnerability research, fuzzing, exploitability assessment, exploit development, or protocol security</li><li>SCADA, distributed control systems, programmable logic controllers, industrial protocols, or other industrial control technologies and physical processes; familiarity with NIST SP 800-82, NERC CIP, IEC 62443, Zero Trust, or ATT&CK for ICS</li><li>Systems or mission engineering and model-based systems engineering methods such as SysML, UAF, BPMN, or STPA-Sec</li><li>Applied cryptography, authentication and key flows, implementation security, or side-channel analysis</li><li>Embedded, wireless, RF, or cellular technologies and security</li><li>An active U.S. government security clearance</li></ul><p></p><div><div><div><div><div><div><div><div><div><p>NOTE: Thank you for your interest in MITRE’s CNP opportunities. Please be aware that this is not an application for a specific position. By submitting your information and providing your resume, you will be included in a pool of candidates for various CNP roles. If you are selected for consideration for a particular opportunity, a member of MITRE’s University Recruiting team will reach out to you. You can monitor your application status here: Workday

Benefits & conditions

Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That’s because MITRE people are committed to tackling our nation’s toughest challenges-and we’re committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work for the public interest, with no commercial conflicts to influence what we do. The R&D centers we operate for the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation. We’re making a difference every day-working for a safer, healthier, and more secure nation and world. Our workplace reflects our values. We offer competitive benefits, exceptional professional development opportunities for career growth, and a culture of innovation that embraces adaptability, collaboration, technical excellence, and people in partnership. If this sounds like the choice you, (myworkdayjobs.com).</p></div></div></div></div></div></div></div></div></div><p style="text-align:inherit"></p><p style="text-align:left">This requisition requires the candidate to have a minimum of the following clearance(s):</p><p style="text-align:inherit"></p><p style="text-align:left">This requisition requires the hired candidate to have or obtain, within one year from the date of hire, the following clearance(s):</p><p style="text-align:inherit"></p><p style="text-align:left">Salary compensation range and midpoint:</p>$85,200 - $106,500 - $127,800 Annual<p style="text-align:inherit"></p><p style="text-align:left">Work Location Type:</p>Hybrid<p style="text-align:inherit"></p><p style="text-align:left">It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
<br

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on careers.mitre.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

6:22 min

Eliminating HR bureaucracy and trusting employees

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

1:52 min

Refining the agent by automating physical hardware restarts

Marc Plogas Marc Plogas · World Congress 2026 Europe

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

5:06 min

Primary reasons for capability gaps in modern recruitment systems

Rudi Bauer Rudi Bauer +1 · Cappuccino with HR

6:18 min

Architecting asynchronous malware scanning for uploaded file contents

Austin Gil · LIVE

Videos

See all

Related articles

See all