×
Register Here to Apply for Jobs or Post Jobs. X

Operational Technology Cyber Threat Intelligence, Lead

Job in McLean, Fairfax County, Virginia, USA
Listing for: MITRE
Full Time position
Listed on 2026-09-16
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer, Network Security, Security Management & Operations
Salary/Wage Range or Industry Benchmark: 158800 - 238200 USD Yearly USD 158800.00 238200.00 YEAR
Job Description & How to Apply Below

At MITRE, your passion fuels work that impacts our nation and improves lives. This is where your skills strengthen national security, cybersecurity, health, transportation, and citizen services. We’re a nonprofit engineering, applied research, and advanced technology organization working in the public interest. With objectivity and integrity at our core, we lead federally funded research and development centers for U.S. government agencies – collaborating with industry and academia to deliver integrated, high-impact solutions that advance our nation’s health, security, and prosperity.

Our people tackle the toughest technical challenges, supported by competitive benefits, meaningful career development, and a culture of innovation, collaboration, and technical excellence. Choose MITRE for a career with purpose — and help shape the future.

Are you ready to defend national critical infrastructure from evolving non-kinetic threats? The Critical Infrastructure Protection Department (L561), sitting within MITRE’s Cyber-Physical Systems Division, delivers innovative solutions to sponsor challenges critical to national security and public sector missions. Our multidisciplinary team researches, develops, and applies advanced technologies to ensure the operational resilience of vital national assets.

Core Focus Areas
  • Infrastructure Susceptibility Analysis
  • Safety Engineering
  • Threat-Informed Recommendations
  • Critical Infrastructure (CI) Threat Detection, Analytics, & Adversary Emulation
  • Operational Technology (OT) Device Security & Space System OT
  • Cross-Sector Interdependency Analysis
  • Defense Critical Infrastructure Expertise
  • Civilian Critical Infrastructure Sector-Specific Expertise
Job Description

MITRE’s Critical Infrastructure Protection Department (L561) is seeking an Operational Technology (OT) Cyber Threat Intelligence Lead to bridge the gap between deep OT threat intelligence and automated adversary emulation.

In this role, you will analyze real-world adversary TTPs targeting industrial control systems (ICS), SCADA, and Space OT environments. You will distill complex OT threat reporting into operational behaviors, network communication patterns, and protocol mechanics—enabling our software engineering team to automate realistic attack scenarios in platforms like Caldera for OT.

If you want to study real-world adversary behavior in complex cyber-physical/OT systems and strengthen national critical infrastructure alongside federal and industry partners, this role is for you.

Roles & Responsibilities
  • Adversary Behavior Deconstruction:
    Analyze real-worldICS/OT threat intelligence (e.g., PIPEDREAM, IN CONTROLLER, Industroyer) to identify specific adversary behaviors, target device types, and network communication patterns.
  • Emulation Team Alignment:
    Translate OT threat intelligence into concrete technical requirements, attack flows, and protocol parameters for developers building automated emulation capabilities (e.g., Caldera for OT).
  • OT Threat Tracking:
    Track and characterize advanced persistent threats (APTs) targeting critical infrastructure, defense industrial base assets, and space system OT environments using unclassified and classified intel sources.
  • Sponsor Program Guidance:
    Advise government sponsors and critical infrastructure owner/operators on developing OT-specific threat intelligence programs and adopting threat-informed defense strategies.
  • Risk & Susceptibility Analysis:
    Conduct OT-focused threat modeling, mission impact analyses, and cyber-physical risk assessments using frameworks such as ATT&CK for IC, SPARTA.
  • Technical Artifact Delivery:
    Produce actionable technical briefs, attack flow mappings, and strategic briefings tailored for both technical engineering teams and leadership
Basic…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary