Operational Technology Cyber Threat Intelligence, Lead

MITRE

McLean (VA)

On-site

USD 159,000 - 238,000

Full time

19 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

MITRE is seeking an Operational Technology (OT) Cyber Threat Intelligence Lead to bridge OT threat intel and automated adversary emulation. You will analyze adversary TTPs affecting ICS, SCADA, and Space OT, translating findings into operational behaviors for deployment in Caldera-based OT emulations.

The role requires 2+ years in OT threat analysis, strong knowledge of industrial protocols, and active Top Secret/SCI eligibility.

Qualifications

  • 8+ years of related experience with bachelor’s degree (or 6 years with master’s, 3 years with PhD).
  • Degree in Computer Science, Cybersecurity, Information Systems, Intelligence Studies, Strategic Intelligence, or related field.
  • Minimum 2 years in OT/ICS/SCADA/Space OT threat analysis or security.
  • Familiarity with industrial protocols and Purdue Model Levels 0–3.
  • Experience applying ATT&CK for IC, SPARTA, or Cyber Kill Chain to analyze campaigns.
  • Must have active Top Secret and eligible for Top Secret/SCI clearance; U.S. citizen.
  • On-site presence: 3 days/week at MITRE/government locations in NCR.

Responsibilities

  • Adversary Behavior Deconstruction: analyze real-world OT threat intel to identify behaviors and patterns.
  • Emulation Team Alignment: translate OT intel into requirements for emulation capabilities (Caldera for OT).
  • OT Threat Tracking: track APTs targeting critical infrastructure and space OT environments.
  • Sponsor Program Guidance: advise sponsors on OT threat intelligence programs and defense strategies.
  • Risk & Susceptibility Analysis: conduct OT-focused risk assessments using ATT&CK for IC, SPARTA.
  • Technical Artifact Delivery: create briefings and attack flow mappings for engineering and leadership.

Skills

OT threat intelligence
ICS/OT security
Adversary emulation
Caldera for OT
Network protocol knowledge
Threat modeling
ATT&CK for IC / SPARTA

Education

Degree in Computer Science, Cybersecurity, Information Systems, Intelligence Studies, Strategic Intelligence, or related field

Tools

Wireshark
Zeek
Caldera for OT
Industrial protocols knowledge (Modbus TCP, DNP3, OPC UA/DA, Ethernet/IP)

Job description

At MITRE, your passion fuels work that impacts our nation and improves lives. This is where your skills strengthen national security, cybersecurity, health, transportation, and citizen services. We’re a nonprofit engineering, applied research, and advanced technology organization working in the public interest. With objectivity and integrity at our core, we lead federally funded research and development centers for U.S. government agencies – collaborating with industry and academia to deliver integrated, high-impact solutions that advance our nation’s health, security, and prosperity. Our people tackle the toughest technical challenges, supported by competitive benefits, meaningful career development, and a culture of innovation, collaboration, and technical excellence. Choose MITRE for a career with purpose — and help shape the future.

Are you ready to defend national critical infrastructure from evolving non-kinetic threats? The Critical Infrastructure Protection Department (L561), sitting within MITRE’s Cyber-Physical Systems Division, delivers innovative solutions to sponsor challenges critical to national security and public sector missions. Our multidisciplinary team researches, develops, and applies advanced technologies to ensure the operational resilience of vital national assets.

Core Focus Areas
  • Infrastructure Susceptibility Analysis
  • Safety Engineering
  • Threat-Informed Recommendations
  • Critical Infrastructure (CI) Threat Detection, Analytics, & Adversary Emulation
  • Operational Technology (OT) Device Security & Space System OT
  • Cross-Sector Interdependency Analysis
  • Defense Critical Infrastructure Expertise
  • Civilian Critical Infrastructure Sector-Specific Expertise
Job Description

MITRE’s Critical Infrastructure Protection Department (L561) is seeking an Operational Technology (OT) Cyber Threat Intelligence Lead to bridge the gap between deep OT threat intelligence and automated adversary emulation.

In this role, you will analyze real-world adversary TTPs targeting industrial control systems (ICS), SCADA, and Space OT environments. You will distill complex OT threat reporting into operational behaviors, network communication patterns, and protocol mechanics—enabling our software engineering team to automate realistic attack scenarios in platforms like Caldera for OT.

If you want to study real-world adversary behavior in complex cyber-physical/OT systems and strengthen national critical infrastructure alongside federal and industry partners, this role is for you.

Roles & Responsibilities
  • Adversary Behavior Deconstruction: Analyze real-worldICS/OT threat intelligence (e.g., PIPEDREAM, INCONTROLLER, Industroyer) to identify specific adversary behaviors, target device types, and network communication patterns.
  • Emulation Team Alignment: Translate OT threat intelligence into concrete technical requirements, attack flows, and protocol parameters for developers building automated emulation capabilities (e.g., Caldera for OT).
  • OT Threat Tracking: Track and characterize advanced persistent threats (APTs) targeting critical infrastructure, defense industrial base assets, and space system OT environments using unclassified and classified intel sources.
  • Sponsor Program Guidance: Advise government sponsors and critical infrastructure owner/operators on developing OT-specific threat intelligence programs and adopting threat-informed defense strategies.
  • Risk & Susceptibility Analysis: Conduct OT-focused threat modeling, mission impact analyses, and cyber-physical risk assessments using frameworks such as ATT&CK for IC, SPARTA.
  • Technical Artifact Delivery: Produce actionable technical briefs, attack flow mappings, and strategic briefings tailored for both technical engineering teams and leadership
Basic Qualifications
  • Experience: Typically requires a minimum of 8 years of related experience with a bachelor’s degree; or 6 years and a master’s degree; or a PhD with 3 years’ experience; or equivalent combination of related education and work experience.
  • Education: Degree in Computer Science, Cybersecurity, Information Systems, Intelligence Studies, Strategic Intelligence, or related field.
  • Direct OT Environment Experience: Minimum 2 years of hands‑on experience analyzing, securing, or threat‑modeling Operational Technology (OT), Industrial Control Systems (ICS), SCADA environments, or Space OT systems. (Experience limited to enterprise IT security will not satisfy this requirement.)
  • Industrial Protocol & Control Architecture Familiarity: Working understanding of common industrial communication protocols (e.g., Modbus TCP, DNP3, OPC UA/DA, Ethernet/IP) and lower-level control architecture (Purdue Model Levels 0–3).
  • ICS Threat Framework Application: Demonstrated experience applying ATT&CK for IC, SPARTA, or Cyber Kill Chain for IC to dissect adversary campaigns and analyze cyber-physical attack paths.
  • Clearance Requirement: Must have an active Top Secret U.S Government issued Security Clearance and must be eligible to obtain and maintain a Top Secret/SCI U.S Government issued Security Clearance. Per the U.S. Government’s eligibility requirements, you must be a U.S Citizen to be considered for a security clearance.
  • On‑Site Requirement: This position requires a minimum of 3 days a week on‑site. 60% on‑site presence required at MITRE or government locations in the National Capital Region.
Preferred Qualifications
  • Education: Advanced degree in a relevant technical field.
  • Active Clearance: Active TS/SCI security clearance.
  • PCAP & Traffic Analysis: Experience performing network packet capture analysis (e.g., Wireshark, Zeek) on industrial protocol traffic to differentiate normal operations from malicious commands.
  • Emulation & Red Teaming Collaboration: Experience partnering with red teams, penetration testers, or adversary emulation developers on threat simulation exercises.
  • Industry Certifications: Relevant OT/ICS certifications such as GIAC Global Industrial Cybersecurity Professional (GICSP), GIAC Response and Industrial Defense (GRID), or GIAC Critical Infrastructure Protection (GCIP).
  • Government & Sector Advisory: Experience partnering with organizations such as CISA, DoD, or Sector Risk Management Agencies (SRMAs) on threat reporting and mitigation guidance.
This requisition requires the candidate to have a minimum of the following clearance(s):

Top Secret

This requisition requires the hired candidate to have or obtain, within one year from the date of hire, the following clearance(s):

Top Secret/SCI

Salary compensation range and midpoint

$158,800 - $198,500 - $238,200 Annual

Work Location Type

Onsite

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local or international law.

MITRE intends to maintain a website that is fully accessible to all individuals. If you are unable to search or apply for jobs and would like to request a reasonable accommodation for any part of MITRE’s employment process, please email recruitinghelp@mitre.org for general support and collegerecruiting@mitre.org for intern positions. This service is for individuals requiring reasonable accommodation requests. Please note that vendor solicitations will not receive a reply.

Benefits information may be found here.

Copyright © 1997-2026, The MITRE Corporation. All rights reserved. MITRE is a registered trademark of The MITRE Corporation. Material on this site may be copied and distributed with permission only.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Operational Technology (OT) Cybersecurity Engineer
Senior Operational Technology (OT) Cybersecurity Engineer

MITRE • Bedford (MA)

On-site
USD 129,000 - 194,000
Operational Technology (OT) Adversary Emulation Engineer
Operational Technology (OT) Adversary Emulation Engineer

MITRE • Aberdeen (MD)

On-site
USD 159,000 - 238,000
Cyber Threat Intelligence, Senior
Cyber Threat Intelligence, Senior

The MITRE Corporation • Colorado Springs (CO)

Hybrid
USD 129,000 - 194,000
Critical Infrastructure Systems Security and Resilience Analyst
Critical Infrastructure Systems Security and Resilience Analyst

MITRE • Fort Meade (MD)

On-site
USD 159,000 - 238,000
Project Analyst
Project Analyst

MITRE • Colorado Springs (CO)

On-site
USD 83,000 - 125,000
Project Analyst
Project Analyst

MITRE • Bedford (MA)

On-site
USD 83,000 - 125,000
Project Analyst
Project Analyst

MITRE • El Segundo (CA)

On-site
USD 83,000 - 125,000
Project Analyst
Project Analyst

MITRE • McLean (VA)

On-site
USD 83,000 - 125,000
Competitive benefits
Career development
Defensive Cybersecurity Engineer/Blue Team
Defensive Cybersecurity Engineer/Blue Team

MITRE • Bedford (MA)

On-site
USD 159,000 - 238,000
Principal C5ISRT Operations and Policy
Principal C5ISRT Operations and Policy

MITRE • McLean (VA)

On-site
USD 162,000 - 242,000