Sr Principal Cybersecurity Analyst - R10206100 jobs in United States
cer-icon
Apply on Employer Site
company-logo

Northrop Grumman · 20 hours ago

Sr Principal Cybersecurity Analyst - R10206100

Northrop Grumman is a leading technology company with a focus on revolutionary systems that impact lives globally. They are seeking a Senior Principal Cybersecurity Analyst to support information systems security lifecycle activities, ensuring compliance with security policies and managing risks associated with cybersecurity.

AerospaceData IntegrationManufacturingRemote SensingSecurity
check
Growth Opportunities
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Guide assessments of systems and networks within the networking environment or enclave and identify where those systems and networks deviate from acceptable configurations, enclave policy, or local policy. This is achieved through passive evaluations such as compliance audits and active evaluations such as vulnerability assessments
Enforce strict program control processes to ensure mitigation of risks and supports obtaining certification and accreditation of systems. Includes support of process, analysis, coordination, security certification test, security documentation, as well as investigations, software research, hardware introduction and release, emerging technology research inspections and periodic audits
Implement the required government RMF policy (i.e. ICD 503, JSIG, DAAPM), make recommendations on process tailoring, participate in and document process activities
Perform analyses to validate established security controls and to recommend additional security requirements and safeguards
Support the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results and preparation of required reports
Ensure completion all associated Assessment and Authorization activities, which includes all RMF Body Of Evidence (BOE) documentation: System Security Plan (SSP), Security Controls Traceability Matrix (SCTM), Control Family Security Operating Plans (SOPs), Continuous Monitoring (ConMon) Plan, Plan of Actions and Milestones (POA&M), etc…
Lead the recurring cybersecurity SOW to completion; includes auditing, configuration management, hardware inventory, software inventory, user training, POA&M updates, ConMon checklists, Self-Inspections, etc…

Qualification

DoD 8140 security certificationRisk Management FrameworkAssessmentAuthorizationCyber Security degreeCORA preparationCommunication skills

Required

Master's Degree with 7 years of experience; OR a Bachelor's Degree with 9 years of experience; OR an Associate's Degree with 11 years of experience; OR a High School Diploma/GED with 13 years of experience
Must have an advanced level DoD 8140 security certification (CISM, GSLC, CCISO, CISSP)
Candidates must have a current DOD Secret security clearance (at a minimum) to include a closed investigation date completed within the last 6 years OR must be enrolled in the DOD Continuous Evaluation Program (CEP), in order to be considered

Preferred

The ideal candidate will have a Bachelor's degree in Cyber Security, a DoD 8570 IAM level III security certification (CISM, GSLC, CCISO, CISSP), and 9 years of experience with Assessment and Authorization of classified systems and Risk Management Framework
Experience with Cyber Operational Readiness Assessment (CORA) preparation – reviewing and implementation of extensive compliance guidance
Demonstrable experience: Replying to DISA and other authoritative agency data calls and tasking orders
Supporting Plan of Action and Milestones (POA&M) maintenance to include documentation and adjustment of mitigation/remediation schedules for open items as well as the addition of new deficiencies and removal of resolved items
Maintaining Security Technical Implementation Guide (STIG) checklists and associated compliance items; includes assessment of Defense Information Systems Agency (DISA) quarterly STIG releases for impact on current configurations
Reviewing Assured Compliance Assessment Solution (ACAS) scan results, determining fix actions
Communication with a diverse team of Program, Engineers, Cyber, IT, and Security SMEs to ensure strict Network compliance requirements are met

Benefits

Health insurance coverage
Life and disability insurance
Savings plan
Company paid holidays
Paid time off (PTO) for vacation and/or personal business

Company

Northrop Grumman

company-logo
Northrop Grumman is an aerospace, defense and security company that provides training and satellite ground network communications software.

Funding

Current Stage
Public Company
Total Funding
$3.7B
Key Investors
U.S. Department of DefenseNASA
2025-05-27Post Ipo Debt· $1B
2024-01-29Post Ipo Debt· $2.5B
2023-12-20Grant· $72M

Leadership Team

leader-logo
Tom Wilson
Corporate Vice President, Enterprise Business Development
linkedin
leader-logo
Jeffrey Worsham
Chief Product Owner - Advanced Technology Development
linkedin
Company data provided by crunchbase