Cyber Defense Intern
Indexed description
Cyber Defense Intern N554 operational depth and warfighter access has generated considerable expertise in the development and analysis of CONOPS, mission threads, use cases, and operational requirements. The Department establishes links between DoW sponsors and Coalition Partner development activities
Job Title: Cyber Defense Intern
Start Dates: The internship will begin on September 21st, 2026, and conclude on December 4th, 2026. Preference given to candidates who hold an active Secret Clearance.
Job Responsibilities:
- Write and maintain Python scripts that pull in security data (IDS/IPS alerts, vulnerability feeds, threat‑intel) and clean/format it for analysis.
- Help review and finetune Suricata or Snort rule sets, linking alerts to common attack techniques (e.g., MITRE ATT&CK) and known exploits (CISA KEV).
- Use Git for version control, add clear comments, and create simple tests so work can move safely into an air‑gapped environment.
- Work with analysts and engineers in short, agile sprints to turn their needs into usable data dashboards or reports and assist in pulling feeds from Splunk/MISP for enrichment.
- Sustained excellence in academic performance
- Must be a student enrolled full-time in an accredited degree-seeking program in Cybersecurity and Information Security, Computer Science, Software Engineering, Data Science, or a related degree and continue to be enrolled full-time the semester following the internship.
- Understanding of network IDS/IPS concepts and basic rules writing of Suricata or Snort.
- Python programming skills for data parsing, transformation, and exporting a
- Familiarity with the CVE lifecycle and basic threat‑modeling ideas (MITRE ATT&CK, CISA KEV). Ability to map CVE coverage to ATT&CK techniques.
- This position requires a minimum of 3 days per week onsite.
- Demonstrated interest in serving the public
- Exposure to Palantir Foundry (or interest in learning its data‑modeling and pipeline tools).
- Experience with a SIEM (Splunk, Elastic, QRadar) or a threat‑intelligence platform (MISP).
- Knowledge of how to map detections to MITRE ATT&CK tactics/techniques.
- Comfortable working in an agile team and adapting quickly to changing sponsor needs.
- Obtained CAC.
This requisition requires the candidate to have a minimum of the following clearance(s):
Not Applicable
This requisition requires the hired candidate to have or obtain, within one year from the date of hire, the following clearance(s):
Not Applicable
Salary compensation range and midpoint:
$46,500 - $58,000 - $69,500 Annual
Work Location Type:
Onsite
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local or international law.
MITRE intends to maintain a website that is fully accessible to all individuals. If you are unable to search or apply for jobs and would like to request a reasonable accommodation for any part of MITRE’s employment process, please email [email protected] for general support and [email protected] for intern positions. This service is for individuals requiring reasonable accommodation requests. Please note that vendor solicitations will not receive a reply.
Benefits information may be found here.
Copyright © 1997-2026, The MITRE Corporation. All rights reserved. MITRE is a registered trademark of The MITRE Corporation. Material on this site may be copied and distributed with permission only.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search