Sr Principal Cyber Systems Engineer
Description
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work — and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.Northrop Grumman Aeronautics Systems is currently seeking a Senior Principal Cyber Systems Engineer for a new and exciting effort located in Melbourne, FL.
We're looking for a highly motivated, team-oriented individual that understands cybersecurity and the importance to our mission. The candidate will be responsible for the secure operations of cloud infrastructure, platforms, and software, including the installation, maintenance, and improvement of cloud computing environments. They will also help develop new designs and security strategies across cloud-based applications and Infrastructure as Code (IaC). The candidate will have hands-on deployment, integration, and configuration experience, and will act as a Cyber Subject Matter Expert (SME) to ensure compliance with the Risk Management Framework.
Responsibilities:
- Serve as an Information System Security Engineer (ISSE), leveraging advanced technical expertise to inform cyber engineering practices and ensuring adherence to cybersecurity disciplines such as COMSEC, COMPUSEC, EMSEC, OPSEC, and effective use of penetration tools and techniques.
- Design, plan, and implement security tooling configurations to ensure compliance with NIST Special Publication (SP) 800-53, CNSSI 1253, and DoD RMF Knowledge Service guidance.
- Assess system security controls, validate the effective implementation of controls, identify vulnerabilities, and propose corrective measures.
- Document the results of Authorization and Accreditation (A&A) activities, prepare System Security Plans (SSPs), and maintain updated Plans of Action and Milestones (POA&Ms).
- Manage the implementation, automation, configuration, and maintenance of security tools, including centralized authentication solutions, IDS/IPS systems, and compliance baselines.
- Provide expert technical analysis of cybersecurity infrastructure challenges, developing innovative technical solutions tailored to customer requirements.
- Collaborate on technical reviews of requirements, to include generating test plans, as well as designing and implementing plans prior to system deployment.
- Recommend and implement enhancements to security systems aimed at improving performance, reliability, and overall security posture, encompassing installation, upgrades, monitoring, troubleshooting, and configuration.
Basic Qualifications:
- Must have a Bachelor’s degree in a STEM-related field with 8 years of experience to include a background in cyber systems engineering, systems engineering or cyber security; or Master’s degree with 6 years of experience; or PhD with 4 years of experience
- Active Secret Clearance with a Personnel Security Investigation (PR) completed within the last 5 years.
- Ability to obtain and maintain Special Program Access prior to commensuration of employment.
- Must have a security certification in CAP/CGRC, CASP/SecurityX, CISM, or CISSP (or Associate) to be considered.
- Experience in preparing, reviewing, and delivering technical and programmatic documentation.
- Prior experience with the planning, design, and implementation processes necessary to support large enterprise systems.
- Working knowledge of NIST 800-37 RMF artifacts, including SSPs, Security Control Traceability Matrices (SCTMs), SARs, RARs, and other documentation.
- Hands-on experience deploying and configuring Linux and Windows systems per DoD STIG requirements.
- Hands on experience configuring Security Incident Event Monitoring (SIEM) and IDS/IPS tools such as ACAS, HBSS, and Splunk within Linux RedHat and Windows environments.
- Familiarity with vulnerability and compliance scanning tools such as Tenable.SC and SCAP.
- Prior experience with scripting security processes to establish consistent, automated baselines across multiple systems for redundancy and efficiency.
Preferred Qualifications
- Active Top Secret Clearance with a Personnel Security Investigation (PR) completed within the last 5 years.
- Strong familiarity with DoD 8500-series and 8510.01 IA policy directives, including IATT and ATO requirements, and general approaches to cybersecurity.
- Exceptional communication (written and oral), negotiation, and interpersonal skills to effectively support ISSE initiatives and collaborate with engineering teams, management, clients, partners, and government stakeholders.
- Experience with next-generation security technologies including Dell, Cisco, Palo Alto, and other advanced networking equipment.
- Knowledge of Software Development Life Cycle (SDLC) processes and tools such as DOORS.
- Experience with cloud service providers like Azure and AWS, focusing on configuration, integration, and sustainability of cloud-based systems.
- Ability to clearly translate complex technical concepts and information for a variety of stakeholders.
- Knowledge of Cross-Domain Solution (CDS) technology and compliance requirements.
- Experience designing, integrating, maintaining, and retiring systems within cloud environments.
More jobs at Ngc
- Sr Principal Engineer Field Secret Clearance - 19167 — United States-Utah-Roy
- Manager Manufacturing Operations 2 — United States-Ohio-Cincinnati
- Lead Test Automation Engineer - Level 4 — United States-Colorado-Schriever AFB
- Principal Systems Engineer - Fault Management & System Autonomy — United States-Virginia-Dulles
Similar roles
- Cyber Operations Integrator at Caci
- Cyber Operations Integrator at Caci
- Cyber Network Defense Analyst III at Nwis
- N3 Cyber Operations Analyst at Pae