Cyber Defense Intern N554 operational depth and warfighter access has generated considerable expertise in the development and analysis of CONOPS, mission threads, use cases, and operational requirements. The Department establishes links between DoW sponsors and Coalition Partner development activities
Job Title: Cyber Defense Intern
Start Dates: August 24th; September 7th or September 24th. This will be a full-time (40 hours per week) internship working 50% onsite. The length of the internship will be 8-12 weeks and will conclude on November 20th. Preference given to candidates who hold an active Secret Clearance.
Job Responsibilities:
- Write and maintain Python scripts that pull in security data (IDS/IPS alerts, vulnerability feeds, threat‑intel) and clean/format it for analysis.
- Help review and finetune Suricata or Snort rule sets, linking alerts to common attack techniques (e.g., MITRE ATT&CK) and known exploits (CISA KEV).
- Use Git for version control, add clear comments, and create simple tests so work can move safely into an air‑gapped environment.
- Work with analysts and engineers in short, agile sprints to turn their needs into usable data dashboards or reports and assist in pulling feeds from Splunk/MISP for enrichment.
Basic Qualifications:
- Sustained excellence in academic performance
- Must be a student enrolled full-time in an accredited degree-seeking program in Cybersecurity and Information Security, Computer Science, Software Engineering, Data Science, or a related degree and continue to be enrolled full-time the semester following the internship.
- Understanding of network IDS/IPS concepts and basic rules writing of Suricata or Snort.
- Python programming skills for data parsing, transformation, and exporting a
- Familiarity with the CVE lifecycle and basic threat‑modeling ideas (MITRE ATT&CK, CISA KEV). Ability to map CVE coverage to ATT&CK techniques.
Preferred Qualifications:
- Demonstrated interest in serving the public
- Exposure to Palantir Foundry (or interest in learning its data‑modeling and pipeline tools).
- Experience with a SIEM (Splunk, Elastic, QRadar) or a threat‑intelligence platform (MISP).
- Knowledge of how to map detections to MITRE ATT&CK tactics/techniques.
- Comfortable working in an agile team and adapting quickly to changing sponsor needs.
- Obtained CAC
This requisition requires the candidate to have a minimum of the following clearance(s):
Not ApplicableThis requisition requires the hired candidate to have or obtain, within one year from the date of hire, the following clearance(s):
Not ApplicableSalary compensation range and midpoint:
$46,500 - $58,000 - $69,500 AnnualWork Location Type:
HybridCommitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local or international law.
MITRE intends to maintain a website that is fully accessible to all individuals. If you are unable to search or apply for jobs and would like to request a reasonable accommodation for any part of MITRE’s employment process, please email recruitinghelp@mitre.org for general support and collegerecruiting@mitre.org for intern positions. This service is for individuals requiring reasonable accommodation requests. Please note that vendor solicitations will not receive a reply.
Benefits information may be found here.
Copyright © 1997-2026, The MITRE Corporation. All rights reserved. MITRE is a registered trademark of The MITRE Corporation. Material on this site may be copied and distributed with permission only.Learn more about this Employer on their Career Site
