Cyber New Professionals Program
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+22 more
Job description
- Develop threat-informed, intelligence-enabled solutions using MITRE ATT&CK®, MITRE Engage , and MITRE Caldera to counter advanced adversaries
- Research novel technical ideas, conduct rigorous analysis, and build proofs of concept that inform sponsor decisions
- Apply threat-informed cybersecurity principles to protect critical systems and infrastructure from cyberattacks and other disruptions
- Model and analyze cyber-physical, physical, human, and organizational systems
- Analyze binaries, firmware, embedded systems, and industrial protocols; conduct vulnerability research, fuzzing, crash analysis, and mitigation assessments
- Develop tested, documented, reproducible research software that integrates cybersecurity, artificial intelligence, systems engineering, and domain expertise
- Collaborate with sponsors, vendors, and academia to advance cybersecurity practices
Example Focus Areas
These areas show the breadth of CNP’s work, not the expected profile of a single candidate. You can be a strong candidate with experience in only one or a few of them. Your assignments will reflect your skills, interests, and available projects.
- Threat operations and analysis: adversary emulation; threat intelligence; defensive operations; deception and adversary engagement; cyber effects; analytics; malware analysis; forensics; assessments; and reverse engineering
- Security architecture, trust, and governance: cloud security; cross-domain solutions; cryptography and trust; enterprise security architecture; identity, credentialing, and access management; privacy; strategy and governance; and supply-chain security
- Critical and connected systems: critical infrastructure resiliency and safety; cyber resiliency and safety; Internet of Things (IoT) and operational technology (OT) security; OT engineering and response; modeling and simulation; adversary emulation; and countermeasures
- Software and device security: security automation and management; software assurance; vulnerability research and exploitability analysis; and embedded, wireless, radio frequency (RF), and cellular security
- Systems and emerging technology: autonomous cyber; systems and mission engineering; AI-enabled cross-domain engineering; and cyber-physical and human-system modeling
Requirements
- Bachelor’s or graduate degree in a relevant field, such as engineering, applied physics, applied mathematics, computer science, or a related discipline, completed by your start date
- Typically requires less than 2 years of related experience with a related bachelor’s degree, or equivalent combination of related education and work experience; internships and co-ops do not count toward this limit
- Hands-on technical experience through employment, internships or co-ops, research laboratories, independent projects, capture-the-flag competitions, or similar work
- Applied knowledge of cybersecurity principles, tools, and devices
- Ability to obtain a U.S. government Top Secret security clearance; an active clearance is not required
- Ability to work independently and collaboratively
- Strong written and verbal communication skills, including presentation skills
- Initiative and sound judgment when addressing novel, complex, or ambiguous problems
- Strong organizational skills, including attention to detail, and the ability to manage multiple project components, Experience in any of the following is helpful, but this is not a checklist. Candidates are not expected to have experience in all, or even most, of these areas:
- Proficiency in one or more scripting or programming languages, such as Python, Java, C/C++, or JavaScript, with an emphasis on testing, continuous integration, reproducibility, and maintainability
- Security across operating systems, computer systems, mobile devices, enterprise and cloud environments, or wireless networks; experience with tools and frameworks such as Nmap, Metasploit, ATT&CK, RMF, CSF, or MITRE Caldera
- Advanced cyber threats, adversary methods, static or dynamic analysis, debugging, disassembly, decomplication, instrumentation, emulation, or symbolic analysis
- Vulnerability research, fuzzing, exploitability assessment, exploit development, or protocol security
- SCADA, distributed control systems, programmable logic controllers, industrial protocols, or other industrial control technologies and physical processes; familiarity with NIST SP 800-82, NERC CIP, IEC 62443, Zero Trust, or ATT&CK for ICS
- Systems or mission engineering and model-based systems engineering methods such as SysML, UAF, BPMN, or STPA-Sec
- Applied cryptography, authentication and key flows, implementation security, or side-channel analysis
- Embedded, wireless, RF, or cellular technologies and security
- An active U.S. government security clearance
About the company
Why choose between doing meaningful work and having a fulfilling life? At MITRE, you can have both. That’s because MITRE people are committed to tackling our nation’s toughest challenges-and we’re committed to the long-term well-being of our employees. MITRE is different from most technology companies. We are a not-for-profit corporation chartered to work for the public interest, with no commercial conflicts to influence what we do. The R&D centers we operate for the government create lasting impact in fields as diverse as cybersecurity, healthcare, aviation, defense, and enterprise transformation. We’re making a difference every day-working for a safer, healthier, and more secure nation and world. Our workplace reflects our values. We offer competitive benefits, exceptional professional development opportunities for career growth, and a culture of innovation that embraces adaptability, collaboration, technical excellence, and people in partnership. If this sounds like the choice you want to make, then choose MITRE - and make a difference with us.
Launch your cybersecurity career through MITRE’s Cyber New Professionals (CNP) Program. You’ll tackle complex national cybersecurity challenges alongside leading experts while gaining hands-on experience, developing new skills, and building your professional network.
CNP combines:
- Structured onboarding to MITRE, its culture and organizational structure, and the CNP program
- Varied project experience that builds broad cybersecurity expertise and depth in your areas of interest
- Curated technical and professional training
- Mentorship from MITRE cybersecurity experts
- A cohort of early-career peers and networking opportunities across MITRE
How the Program Works
CNP is a two-year program for staff at the beginning of their cybersecurity careers, including people who are new to many of the topics below. Project assignments are matched to your skills and interests, as well as project availability. After two years, you will graduate from CNP and transition into another MITRE department.
Roles & Responsibilities may include
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Dev Digest 134 - Where pixels sing?
Understanding and Mitigating Common Web Vulnerabilities
Top 6 Hackathons for Developers in 2023
Is Software Engineering Over-Saturated?