Cyber Analyst (AHT)
Description
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work — and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.Northrop Grumman Defense Systems is seeking a motivated professional to join our team as a Cyber Analyst Level 2. This position is located in Colorado Springs, CO.
Northrop Grumman Defense Systems is seeking a multi-skilled, self-motivated, energetic individual to work at our Colorado Springs, CO location as a Cyber Analyst supporting the JTAGS program. As a cyber team member you should excel in interpersonal, business, and technical domains. Be able to perform comprehensive security assessments, including compliance audits and vulnerability scanning, to pinpoint security weaknesses and policy inconsistencies. You'll identify and support in the addressing of system vulnerabilities and collaborate with system administrators to implement secure configurations aligned with NIST SP800-53 security and privacy controls and customer standards. Strong collaboration and communication skills, both written and verbal, are essential for engaging with internal and external stakeholders.
Responsibilities:
- Contribute to the development and enforcement of strong program controls aimed at effectively mitigating identified security risks
- Assist in the preparation and upkeep of essential documentation for system certification and accreditation processes
- Support the planning, coordination, and documentation of security certification testing activities
- Conduct research on emerging technologies and their potential impact on the program’s security landscape
- Participate in regular security inspections and audits
- Support in the development of technical standard operating processes and procedures as needed
- Provide analysis, design, development, implementation and security assessments to ensure compliance with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, CNSSI 1253, and DoD RMF Knowledge Service guidance
- Hardening and securing information systems and network gear while understanding the operational and security impacts of various security configurations
- Troubleshooting, identifying, and resolving system failures in a timely manner
- Participating in technical interchange meetings
- Providing support for development and enhancement of security engineering inputs to program documentation, security authorization packages, CDRLs, and research & development reports
Basic Qualifications
- 2 years relevant cybersecurity experience with Bachelor’s degree in cybersecurity or related STEM field
- Active IAT Level II (ie. CompTIA Security+) certification or DOD 8140 Foundational Qualification
- Active Secret security clearance
- Basic proficiency in RHEL OS command line and/or Windows PowerShell
- Ability to apply basic technical expertise and skillset under general supervision to work cybersecurity projects and tasks IAW required DoD security and cybersecurity instructions, policies, frameworks, etc., including:
- Scanning and reporting cybersecurity vulnerabilities discovered through use of audit reduction tools and/or the DISA Automated Security Compliance Assessment Solution (ACAS) tool (Tenable Security Center and Tenable NESSUS Scanner)
- Performing STIG compliance scans using Xylok or other STIG scanning tools
- Identifying & applying DISA STIGs/hardening systems
- Understanding of and experience with NIST SP 800-37 RMF for DoD Systems, including IAW NIST/DoD RMF processes, SP 800-53 security and privacy controls
Preferred Qualifications
- Basic knowledge of security risks & strategies, SIEM, antivirus, proxies, firewalls, and intrusion detection concepts, tools, and processes
- Experience in creating, editing, and updating program CDRLs
- Beginner skillset and/or familiarity with Trellix Endpoint Security Solutions (ESS)
- Experience with Hyper-V and/or VMware
- Working knowledge of Splunk
- Experience implementing DevSecOps practices and principles for release management
- Working knowledge and/or experience with JIRA for task assignment, status track
More jobs at Ngc
- Principal Cyber Systems Administrator (TG) — United States-Maryland-Annapolis Junction
- Principal/Sr Principal Manufacturing Analyst Leve 3/4 — United States-Utah-Clearfield
- Project Management/Principal Project Management — United States-Florida-Melbourne
- Modeling Simulation and Analysis Engineer (Engineer or Principal Engineer Level) — United States-California-Redondo Beach
Similar roles
- Head of Government Cyber Integration, OpenAI for Government at OpenAI
- Cyber Operations Integrator at Caci
- Cyber Operations Integrator at Caci
- Cyber Operations Integrator at Caci