> Markdown version of [/jobs/ext/576922-lead-cybersecurity-assessment-engineer](https://www.wearedevelopers.com/jobs/ext/576922-lead-cybersecurity-assessment-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Lead Cybersecurity Assessment Engineer - **Company:** MITRE Corporation - **Location:** McLean, VA, United States - **Experience:** Expert - **Salary:** $158,800.0 - $198,500.0 - **Contract:** Permanent contract - **Skills:** ASP.NET, Java (Programming Language), PHP (Programming Language), Amazon Web Services, Apple Mac Systems, Software System Penetration Testing, Systems Engineering, Burp Suite, C Sharp (Programming Language), C++ (Programming Language), Cloud Computing, COBOL (Programming Language), CompTIA Network+, CompTIA Security+, Cyber Security, Linux, Perl (Programming Language), Information Systems Security Architecture Professional, Python (Programming Language), Kali Linux, Server Administration, Security Information and Event Management, Software Engineering, Systems Integration, Wireshark, VxWorks, Windows Desktop, QRadar, SC Clearance, Information Technology, Network Support, Vba Programming Language, Nessus, Comptia Linux+, Splunk, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** June 20, 2026 - **Apply:** https://www.juju.com/job/00000000g9p4n8 ## About the Role + Requires a minimum of 8 years of related experience with a Bachelor's degree; or 6 years and a Master's degree; or a PhD with 3 years' experience; or equivalent combination of related education and work experience. + Experience with RMF, NIST SP-800 series, and Security Controls Assessment (SCA). + Experience in software engineering and systems engineering, including requirements analysis and technical writing. + Familiarity with Windows, Linux, macOS/Open BSD, and VxWorks/Tornado operating systems. + Proficiency in programming languages including Java, C#, C++, Python, Perl, Visual Basic, ASP.NET, PHP, COBOL. + Certifications: CISSP, Certified Ethical Hacker (CEH), Network+, AWS Certified Cloud Practitioner. + This position requires a minimum of 50% hybrid on-site + Must be able to successfully obtain a Top-Secret clearance within one year of hire. + Per the U.S. Government's eligibility requirements, you must be a U.S Citizen to be considered for a security clearance Preferred Qualifications: + Active Top Secret Security Clearance. + Graduate-level degree in a technical discipline (Cybersecurity, Information Assurance, etc.). + 12 years related experience as a cybersecurity analyst/systems engineer. + Experience with advanced assessment techniques utilizing Kali Linux, Burp Suite, Wireshark, etc. + Experience with various Security Information and Event Management (SIEM) platforms (Splunk, QRadar, Tenable products, etc.) + Experience with offensive and defensive cybersecurity operations, including penetration testing + Experience with various Information Technology (IT) operations in enterprise environments including system integration, device/network hardening, server administration, network maintenance, etc. + Certified Information Systems Security Professional (CISSP) + GIAC Penetration Tester (GPEN), GIAC Certified Intrusion Analyst (GCIA) + CompTIA Security+, CompTIA Network+, CompTIA Linux+ ## Description The Cyber Assessments and Security Automation department within the Cyber Solutions Innovation Center is seeking a Lead level Cybersecurity Assessment Engineer to lead the department's contributions across our portfolios. The department supports all of MITRE by providing a variety of cyber assessment products plus overall cyber engineering skills. The Lead Cybersecurity Assessment Engineer position will be a core member of the department and government technical team and serve as the first-line support for various sponsors. The position requires direct contributions to our diverse work programs. Roles & Responsibilities: + Expertise conducting cybersecurity assessments and workshops for government agencies. + Develop and implement security strategies, and provide mentorship to junior assessors. + Cybersecurity Risk Management: Expert knowledge of cybersecurity risk management frameworks and methodologies. + Vulnerability Assessment & Penetration Testing: Conduct vulnerability assessments, penetration testing, and ethical hacking of applications and systems to identify and remediate security weaknesses. + Security Controls Assessment: Conduct Security Controls Assessments (SCA), workshops, and audits for internal teams and partner organizations. + Security Tools Utilization: Utilize a variety of security tools-including Burp Suite, Nessus, Splunk, QRadar, WireShark, eMASS, and others-to support security operations and assessments. + Contribute technically to one or more Sponsor tasks. + Collaborate effectively with MITRE, government, and contractors; effectively communicate in writing, presentations, and collaborative discussions; and interface with peers, managers, and sponsors. + Promote collaboration and integration with other organizational elements within the department and across MITRE. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [The best of two worlds - Bringing enterprise-grade Linux to the vehicle](https://www.wearedevelopers.com/videos/67-the-best-of-two-worlds-bringing-enterprise-grade-linux-to-the-vehicle) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)