Lead IC Security Engineer
Overview
As a Lead IC Security Engineer, you will own the security design and authorization for a geospatial and identity intelligence platform prototype. You’ll drive ICD-503 and RMF/NIST 800-53 Rev. 5 compliance, shaping secure cloud architectures and evidence packages for ATO readiness. You’ll partner with cloud and software teams to embed security into design, development, and operations, delivering a defensible security posture throughout prototyping and transition. This role offers meaningful impact on national security challenges within MITRE’s mission-driven culture.
Compensation / Benefitscompetitive benefitsexceptional professional development opportunitiesculture of innovationcollaboration-focused environment
ResponsibilitiesLead the security engineering approach and map architecture to ICD-503 and NIST SP 800-53 Rev. 5 controlsOversee implementation, validation, and documentation of security controls across cloud, apps, data services, and platform componentsDevelop and maintain ATO evidence package and required authorization artifactsReview changes for security impact and maintain traceability to controlsCollaborate with cloud engineers to implement secure configurations, automated checks, and logs for repeatable complianceCoordinate with sponsor security stakeholders for control assessments and remediation actionsWork with cross-functional teams to integrate security into design, development, testing, deployment, and operations
Key requirements8+ years of related experience with a Bachelor’s; or 6+ with a Master; or 3+ with a PhD; or equivalentBachelor's degree in Cybersecurity, Computer Science, Computer Engineering, Systems Engineering, Information Systems, Engineering, or related fieldHands-on experience with NIST SP 800-53 and RMF authorization activities and ATO artifactsExperience with AWS, Terraform/OpenTofu, Ansible, Docker/Kubernetes, Linux scripting, and CI/CD pipelinesKnowledge of ICD-503 and IC cybersecurity, authorization, security control implementationExperience securing cloud environments and DevSecOps, with IAM, encryption, logging, vulnerability managementStrong written/verbal communication to document security decisions for sponsors and teamsActive Top Secret/SCI with Polygraph clearance (U.S. citizen required)On-site work requirement: 5 days/weekclear technical documentationrisk assessment and communication with sponsorsability to work with multidisciplinary teamsNIST SP 800-53 Rev. 5RMF authorizationICD-503 security expectations