Cyber New Professionals Program | MITRE
The Tone:
This is a two-year program at MITRE, with a hybrid work location, designed for early-career staff. MITRE is a not-for-profit corporation dedicated to public interest, operating R&D centers for the government across diverse fields like cybersecurity, healthcare, and defense. This program offers the opportunity to launch a cybersecurity career by tackling complex national challenges alongside leading experts, contributing to a safer, healthier, and more secure nation and world. You can develop new skills, build a professional network, and engage in meaningful work while enjoying competitive benefits and professional development.
The TL;DR
- Role: Early Career
- Type: Full-time
- Location: Hybrid
- Pay: $85200–$127800 annual
- Team: Within the Cyber New Professionals (CNP) Program, you will have a cohort of early-career peers, mentorship from MITRE cybersecurity experts, and varied project experience. After two years, you will transition into another MITRE department.
- Mission: To launch cybersecurity careers by providing structured training, mentorship, and project experience to address complex national cybersecurity challenges.
- Tech Stack: MITRE ATT&CK, MITRE Engage, MITRE Caldera, Nmap, Metasploit, RMF, CSF, Python, Java, C/C++, JavaScript, NIST SP 800-82, NERC CIP, IEC 62443, Zero Trust, SysML, UAF, BPMN, STPA-Sec
What You'll Actually Do
- Develop: Threat-informed, intelligence-enabled solutions using MITRE ATT&CK, MITRE Engage, and MITRE Caldera to counter advanced adversaries.
- Research: Novel technical ideas, conduct rigorous analysis, and build proofs of concept that inform sponsor decisions.
- Apply: Threat-informed cybersecurity principles to protect critical systems and infrastructure from cyberattacks and other disruptions.
- Analyze: Binaries, firmware, embedded systems, and industrial protocols; conduct vulnerability research, fuzzing, crash analysis, and mitigation assessments.
- Collaborate: With sponsors, vendors, and academia to advance cybersecurity practices.
The Must-Haves
- Background: Bachelors or graduate degree in engineering, applied physics, applied mathematics, computer science, or a related discipline, completed by your start date.
- Experience: Less than 2 years of related experience with a bachelor’s degree, or equivalent combination of related education and work experience (internships and co-ops do not count toward this limit); hands-on technical experience through employment, internships or co-ops, research laboratories, independent projects, or capture-the-flag competitions.
- Skills: Applied knowledge of cybersecurity principles, tools, and devices; ability to obtain a U.S. government Top Secret security clearance; strong written and verbal communication skills, including presentation skills; initiative and sound judgment when addressing novel, complex, or ambiguous problems; strong organizational skills, including attention to detail, and the ability to manage multiple project components.
- Bonus: Proficiency in one or more scripting or programming languages such as Python, Java, C/C++, or JavaScript; experience with security across operating systems, computer systems, mobile devices, enterprise and cloud environments, or wireless networks; experience with tools and frameworks such as Nmap, Metasploit, ATT&CK, RMF, CSF, or MITRE Caldera; advanced cyber threats, adversary methods, static or dynamic analysis, debugging, disassembly, decomplication, instrumentation, emulation, or symbolic analysis; vulnerability research, fuzzing, exploitability assessment, exploit development, or protocol security; SCADA, distributed control systems, programmable logic controllers, industrial protocols, or other industrial control technologies and physical processes; familiarity with NIST SP 800-82, NERC CIP, IEC 62443, Zero Trust, or ATT&CK for ICs; systems or mission engineering and model-based systems engineering methods such as SysML, UAF, BPMN, or STPA-Sec; applied cryptography, authentication and key flows, implementation security, or side-channel analysis; embedded, wireless, RF, or cellular technologies and security; an active U.S. government security clearance.