Full-Time

Principal Cybersecurity Analyst

Cybersecurity Engineer

Posted on 11/15/2024

Northrop Grumman

Northrop Grumman

10,001+ employees

Aerospace and defense technology solutions provider

Cybersecurity
Aerospace
Defense

Compensation Overview

$97.5k - $146.3kAnnually

+ Bonus

Senior, Expert

No H1B Sponsorship

Colorado Springs, CO, USA

No relocation assistance available.

US Top Secret Clearance, US Citizenship Required

Category
Cybersecurity
IT & Security

You match the following Northrop Grumman's candidate preferences

Employers are more likely to interview you if you match these preferences:

Degree
Experience
Requirements
  • An active Top Secret clearance is required to start.
  • Bachelor’s Degree in a STEM (Science, Technology, Engineering or Mathematics) discipline preferred from an accredited university and 5 years of related experience, or a Master’s degree and 3 years of experience, or a PhD and 1 years of experience, or 9 years of related experience in lieu of a degree may be considered.
  • DoD 8140 certification at IAT Level II / IAM – Level I or higher (Security+, GSEC, SCNP, SSCP, CISSP, CISA, GSE, SCNA) is required at the start.
  • Security engineering skills with a working knowledge of cybersecurity technology and DoD/Federal cybersecurity policy (i.e., DoDI 8500.01, NIST SP 800-53, etc.).
  • Understanding and utilization of Enterprise Mission Assurance Support Service (eMASS).
  • Understanding of Risk Management Framework (RMF) Cybersecurity Lifecycle including: Identifying controls and overlays, Generating testable requirements, identifying resilient architecture design, configuring, running, and scripting audit tools, providing analysis of vulnerability analyses, Conducting verification testing for compliance assessment.
  • Knowledge of Software Assurance (SwA) static and dynamic code analysis (e.g. Fortify).
Responsibilities
  • Process and track DD Form 2875 user account forms and required training for privileged and non-privileged accounts; perform annual account validation; and work with the system administrator to create, modify, and remove accounts.
  • Assess systems and networks within a virtual environment and identify where those systems deviate from acceptable configurations, enclaves, or local policies.
  • Passive evaluations, such as compliance audits using STIG Viewer, SCAP, etc., and active evaluations, such as vulnerability assessments utilizing ACAS.
  • Perform Security Technical Implementation Guide (STIG) assessments and hardening for both Windows, Red Hat Enterprise Linux (RHEL) systems, and networking equipment utilizing ConfigOS.
  • Develop test plans reflecting how STIG checks are implemented and be able to show the expected outcomes of those checks.
  • Update the Risk Management Framework (RMF) artifact documentation to ensure non-compliant system hardening is tracked and remediated.
  • Establish strict program control processes to ensure risk mitigation and support obtaining system assessment and authorization.
  • Support of process, analysis, coordination, control certification test, compliance documentation, and investigations, software research, hardware introduction and release, emerging technology research, inspections, and periodic audits.
  • Assist in implementing the required government policy (e.g., NISPOM, NIST, DoD), make recommendations on process tailoring, and participate in and document process activities.
  • Perform analyses to validate established cybersecurity controls and requirements and to recommend cybersecurity safeguards.
  • Support program test milestones through pre-test preparations, participating in the tests, analysis of the results, and preparation of required artifacts supporting authorization.
  • Prepare artifacts such as Test Results (TR), Authorization Boundary Diagrams (ABD), Network Topologies, Flow Diagrams, Hardware and Software listings, Ports, Protocols, and Services Management documentation.
  • Support Assessment and Authorization activities and maintain the Plan of Action and Milestones (POA&M).
  • Periodically review each program support and operational system's audits and monitor corrective actions until all actions are closed.
  • Coordinate across the program to address identified deficiencies during RMF assessment activities.

Northrop Grumman provides advanced aerospace and defense technology solutions, focusing on areas such as autonomous systems, cybersecurity, and space operations. The company develops and integrates complex systems that support government and commercial clients, particularly the U.S. Department of Defense and international allies. Its products work by combining cutting-edge technology with extensive research and development to create comprehensive solutions tailored to specific needs. Unlike many competitors, Northrop Grumman emphasizes long-term contracts, which offer a stable revenue stream and allow for ongoing collaboration with clients. The company's goal is to maintain its leadership position in the aerospace and defense sector through continuous innovation and by delivering reliable, high-quality solutions.

Company Stage

IPO

Total Funding

$192.2M

Headquarters

Falls Church, Virginia

Founded

1939

Simplify Jobs

Simplify's Take

What believers are saying

  • Growing demand for unmanned systems boosts Northrop Grumman's Manta-Ray drone development.
  • Partnership with Planisware enhances digital transformation and operational efficiency.
  • Involvement in James Webb Space Telescope highlights potential for new government contracts.

What critics are saying

  • Increased competition from international defense contractors like BAE Systems and Thales Group.
  • Potential B-21 Raider program delays due to supply chain issues and technical challenges.
  • U.S. defense budget cuts could lead to fewer contracts and decreased revenue.

What makes Northrop Grumman unique

  • Northrop Grumman excels in autonomous systems, cyber, and space technologies.
  • The company has a strong track record with government contracts and defense solutions.
  • Its diversified revenue streams include Aerospace Systems, Mission Systems, and Technology Services.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Life Insurance

Disability Insurance

Paid Vacation

Paid Holidays

Relocation Assistance

Performance Bonus

INACTIVE