Defensive Cybersecurity Engineer/Blue Team at The MITRE Corporation
Huntsville, AL
$158,800–$238,200from the description
Jul 27, 2026
Huntsville, AL
Jul 29, 2026
What this job asks for AI summary
A defensive cyber operations role at MITRE's not-for-profit R&D center, supporting national law enforcement and intelligence community sponsors. The position centers on threat hunting, detection engineering, and AI-enabled cybersecurity tool development — building Splunk analytics, automating security workflows, and applying the MITRE ATT&CK framework to adversary behavior analysis. Requires full on-site presence five days a week and an active TS/SCI clearance with polygraph.
Senior level · 8+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · TS/SCI clearance · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $152,225 (middle half $125,286–$177,673). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 29, 2026. It is a model, not a headcount.
Why we read it this way (9)
The posting lists a salary range with a midpoint: $158,800 – $238,200 annually (midpoint $198,500). Both the floor and ceiling are captured here.
A TS/SCI with polygraph is required at hire; the posting also states that candidates who do not already hold a polygraph must obtain one within one year of hire.
The role title carries no seniority level, but the 8-year minimum experience requirement and the scope of work (trusted advisor to the Federal Government, advanced research, detection engineering) support a Senior classification.
SOC classification is a genuine judgment call: the role is primarily security analysis and threat hunting (15-1212), but a meaningful portion of the work involves building tools, scripts, and automation (15-1252). 15-1212 was chosen because detection engineering, threat hunting, and adversary analysis are the stated primary mission.
'Scripting' and 'REST APIs' are listed as required in the Basic Qualifications section but no specific language or framework is named; they are captured at that level of specificity.
CI/CD and container automation appear in the responsibilities narrative rather than in a qualifications section, so they are marked preferred.
AI/ML techniques (machine learning, deep learning, generative AI, reinforcement learning) are listed as a preferred qualification; captured as a single preferred skill given no specific platform is named.
The Augury platform appears only under Preferred Qualifications.
Requires a TS/SCI clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.