Posted:
12/4/2025, 4:00:00 PM
Location(s):
Golden, Colorado, United States ⋅ Colorado, United States
Experience Level(s):
Mid Level ⋅ Senior
Field(s):
IT & Security ⋅ Operations & Logistics
Workplace Type:
Hybrid
.
.
.
.
Join the National Laboratory of the Rockies (NLR), where world-class scientists, engineers, and experts are accelerating energy innovation through breakthrough research and systems integration. From our mission to our collaborative culture, NLR stands out in the research community for its commitment to an affordable and secure energy future. Spanning foundational science to applied systems engineering and analysis, we focus on solving complex challenges to deliver advanced, secure, reliable, and cost-effective energy solutions. Our work helps strengthen U.S. industries, support job creation, and promote national economic growth.
At NLR, you'll find a mission-driven environment supported by state-of-the-art facilities, multidisciplinary research teams, and strong collaborations with industry, academia, and other national laboratories. We offer robust professional development opportunities, and a competitive benefits package designed to support your career and well-being.
NLR is seeking a mid-career cyber defense operations researcher to join its Cybersecurity Research Center (CRC). The CRC conducts applied research at the intersection of cybersecurity, energy systems, and national resilience—developing the tools, methods, and scientific foundations necessary to secure and sustain the nation’s evolving energy infrastructure.
CRC research spans incident response (IR) and threat detection, operational technology (OT) risk analysis, cyber-physical resilience testing, malware and artifact analysis, and defense science. Working across NLR’s energy, grid, and systems integration missions, the CRC leverages unique laboratory assets—including the ARIES Cyber Range—to conduct high-fidelity cyber defense exercises and modeling that integrate Information Technology (IT), OT, and hybrid energy system architectures.
We are seeking a technically strong and research-focused professional to advance incident response science, detection engineering, and defensive experimentation. The successful candidate will possess hands-on experience responding to cyber incidents, conducting forensic analysis, and translating findings into improved detection logic, playbooks, and system-level resilience strategies.
Key Research Responsibilities:
Researcher IV
Researcher III
.
* Must meet educational requirements prior to employment start date.
Researcher IV
Advanced experience in Incident Response, threat hunting, forensics, malware analysis, preferably in critical infrastructure environments.
Deep understanding of detection engineering and monitoring at enterprise/OT scale; ability to architect solutions.
Strong proficiency in automation/scripting applied to tooling development and scalable IR workflows.
Applied expertise in Industrial Control Systems (ICS)/OT systems and energy sector architectures; recognized in this technical space.
Demonstrated record of producing reproducible research-grade results (peer-reviewed publications, conference papers).
Skilled communicator able to brief DOE sponsors, industry partners, and senior leadership.
Proven ability to lead cross-functional research efforts, secure research funding, and mentor staff.
Researcher III
Hands-on experience in incident response, Security Operation Center (SOC) operations, threat hunting, forensics, or malware analysis.
Working knowledge of detection and monitoring architectures (SIEM, EDR/XDR, packet capture tools, basic OT visibility).
Proficiency with scripting/automation languages (Python, PowerShell, Bash) to support workflows.
Familiarity with ICS/OT and energy sector concepts (Modbus, DNP3, IEC standards) or willingness to learn.
Demonstrated ability to produce defensible IR findings and contribute to reports and after-action documentation.
Effective written and verbal communication in multidisciplinary research environments.
Ability to work independently while collaborating across functional research teams.
.
The anticipated closing window for application submission is up to 30 days and may be extended as needed.
NLR takes into consideration a candidate’s education, training, and experience, expected quality and quantity of work, required travel (if any), external market and internal value, including seniority and merit systems, and internal pay alignment when determining the salary level for potential new employees. In compliance with the Colorado Equal Pay for Equal Work Act, a potential new employee’s salary history will not be used in compensation decisions.
* Based on eligibility rules
NLR is committed to maintaining a drug-free workplace in accordance with the federal Drug-Free Workplace Act and complies with federal laws prohibiting the possession and use of illegal drugs. Under federal law, marijuana remains an illegal drug.
If you are offered employment at NLR, you must pass a pre-employment drug test prior to commencing employment. Unless prohibited by state or local law, the pre-employment drug test will include marijuana. If you test positive on the pre-employment drug test, your offer of employment may be withdrawn.
Please note that in order to be considered an applicant for any position at NLR you must submit an application form for each position for which you believe you are qualified. Applications are not kept on file for future positions. Please include a cover letter and resume with each position application.
.
All qualified applicants will receive consideration for employment without regard basis of age (40 and over), color, disability, gender identity, genetic information, marital status, domestic partner status, military or veteran status, national origin/ancestry, race, religion, creed, sex (including pregnancy, childbirth, breastfeeding), sexual orientation, and any other applicable status protected by federal, state, or local laws.
E-Verify is a registered trademark of the U.S. Department of Homeland Security. This business uses E-Verify in its hiring practices to achieve a lawful workforce.
Website: https://www.nrel.gov/
Headquarter Location: Golden, Colorado, United States
Employee Count: 1001-5000
Year Founded: 1977
IPO Status: Private
Last Funding Type: Grant
Industries: Clean Energy ⋅ CleanTech ⋅ Energy ⋅ Renewable Energy