Cyber New Professional Cyber-Physical Systems
Role details
Job location
Tech stack
Job description
CNP staff have the opportunity to work on a number of projects that provide a breadth of experiences to develop into well-rounded cybersecurity professionals and opportunities to work alongside subject matter experts to develop depth of knowledge in identified areas of interest. Projects enable members to:
- Combine hands-on operational experience with best practices to develop intelligence-enabled solutions (MITRE ATT&CK®, MITRE Engage , and CALDERA ) that counter advanced adversaries.
- Enhance the security, safety, and resiliency of critical cyber systems and infrastructure by applying threat-informed cybersecurity principles.
- Protect critical infrastructure from malicious cyber or non-kinetic attack or disruption.
CNP Training Opportunities
Through their projects and CNP, staff are provided opportunities to participate in classroom-style and cohort-based training to learn new technical or professional skills or to further develop existing ones.
CNP Work Opportunities
Apply cybersecurity skills and expertise to the following areas:
- Cross Domain Solutions
- Critical Infrastructure (CI) Resiliency and Safety
- Industrial Control Systems (ICS)/Supervisory Control and Data Acquisition (SCADA)
- Operational Technology (OT)/Internet of Things (IoT) Device Security
- Operational Technology (OT) Engineering and Response
- Critical Infrastructure (CI) Modeling and Simulation
- Operational Technology (OT) Adversary Emulation
- Countermeasures for Operational Technologies (OT)
- Hardware and software troubleshooting for Operational Technology (OT)
Work will include:
- Conceive of and advance novel technical ideas
- Provide deep analyses whose results drive decision-making by our sponsors
- Build proof-of-concept systems that leverage new technology and concepts
- Engage with the vendor community, academia, and our sponsors to raise the bar on cyber security throughout the industry
Requirements
-
Bachelor or Graduate Degree in a domain-relevant field
-
Less than two years of full-time relevant work experience
-
Prior experience as an intern at MITRE in the last 12 months
-
Applied knowledge of cybersecurity principles, tools, and devices
-
Demonstrated ability to work both independently and collaboratively
-
Ability to demonstrate excellent communication skills (e.g., writing and presenting)
-
Ability to be proactive and take initiative when addressing novel, complex, or ambiguous problems
-
Excellent organizational skills, including attention to detail and a demonstrated ability to manage multiple project components simultaneously
-
Familiarity with common Industrial Control Systems (ICSs) and their interactions with physical processes
-
Knowledge of network protocols (e.g., TCP/IP, Ethernet, etc.) and familiarity with network devices (e.g., switches, routers, firewalls, etc.)
-
Ability to obtain and maintain a US government Top Secret (TS) and DHS Fitness security clearance
-
Per the U.S. Government's eligibility requirements for a clearance, U.S.
-
This position requires a minimum of 50% hybrid on-site
-
Proficiency with scripting and software development language(s) (Python, Java, C/C++, JavaScript, etc.)
-
Knowledge of security across multiple platforms working on a variety of operating systems, computer systems, mobile devices, cloud networks, and wireless networks
-
Experience with cybersecurity tools and frameworks (Nmap, Metasploit, MITRE ATT&CK, MITRE Caldera, etc.)
-
Knowledge of Critical Infrastructure (CI) control systems and advanced cyber threats to CI and adversary methodologies
-
Familiarity with relevant technologies, such as Operational Technology (OT) Protocols (Modbus, DNP3, ProfiNET, etc.) and related protocols (BACnet, CAN, MIL-STD-1553, etc.) as well as development with OT related tools (ladder logic, IEC 61131, PAC Machine Edition, TIA Portal, etc.) and knowledge of security unique to OT and cyber-physical systems
-
Knowledge of cyber adversary tradecraft within IT and/or OT environments
-
Experience with cyber tooling to execute red team/adversary emulation operations and support detection of adversary behavior
-
Introductory level skills and/or a desire to gain experience in Adversary Emulation and/or Detection Engineering
-
Preference will be given to qualified candidates with ACTIVE Security Clearances