CybersecurityJobs.io
← Back to all jobs

Job Description

Northrop Grumman is seeking a Cybersecurity Analyst 3/4 to support information systems lifecycle activities in a classified environment. This full-time role is on-site at the Cincinnati, OH location and requires a U.S. Secret clearance, with the ability to obtain and maintain Top Secret access plus Special Access Programs (SAP) and SCI access as required.

Working within established cybersecurity governance, you will help teams evaluate system security posture, support assessment and authorization activities, and contribute to Security Test and Evaluation execution through government-accrediting authorities.

Role & Responsibilities

  • Conduct system audits and continuous monitoring across security controls, configurations, and operational processes to evaluate information system security posture.
  • Assess systems and networks within a networking environment or enclave, identifying deviations from acceptable configurations, enclave policy, or local policy.
  • Assist with implementation of required government policy, provide recommendations on process tailoring, and participate in and document process activities.
  • Establish program control processes that support risk mitigation and the Assessment and Authorization (A&A) of systems, including process support, security certification testing, security documentation, investigations, software research, hardware introduction and release, emerging technology research, inspections, and periodic audits.
  • Support formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparation, test participation, results analysis, and report preparation.
  • Document results from A&A activities and technical or coordination activities, and prepare the Risk Management Framework (RMF) body of evidence.
  • Coordinate with Program Managers, system administrators, and customer Security Control Assessors (SCA) to meet required cybersecurity standards while supporting mission needs.
  • Partner with customer security teams to develop solutions for evolving program needs in a specialized work environment.
  • Develop and adhere to project plans while communicating progress and blockers to program leadership and management.
  • Collaborate with cross-functional partners including Engineering and Program Management.
  • Mentor junior staff by reviewing work products, providing guidance and performance feedback, and promoting best practices for testing and documentation.
  • Create and maintain documentation for required RMF artifacts, including diagrams, lists, memorandums, agreements, and more.

Required Qualifications

  • Master’s degree with 3 years of relevant experience, or Bachelor’s degree with 5 years, or Associate’s degree with 7 years, or High School Diploma/GED with 9 years (degree equivalencies accepted).
  • Meet U.S. Government 8140 requirements for Principal Cybersecurity Analyst (for example, Security+ or equivalent).
  • Hold a current U.S. Government Secret clearance (minimum), including a closed investigation date completed within the last 6 years, or be enrolled in the U.S. Government Continuous Evaluation (CE) Program with ability to obtain and maintain Top Secret as a condition of continued employment.
  • Principal Cybersecurity Analyst candidates must be able to obtain and maintain access to Special Access Programs and SCI Programs as a condition of employment.
  • Additional education/experience pathway for Sr Principal Cybersecurity Analyst: Master’s degree with 6 years, or Bachelor’s degree with 8 years, or Associate’s degree with 10 years, or High School Diploma/GED with 12 years.
  • Meet U.S. Government 8140 requirements for Sr Principal Cybersecurity Analyst (for example, CISSP or equivalent).
  • Because the work is classified, the position does not offer virtual or telecommute options; applicants are encouraged to apply only if they are willing to work on-site.

Technologies & Frameworks

  • EMASS, Xacta, ACAS, Nessus, Splunk, SEPM, SCAP
  • NIST, JSIG, DAAG, RMF, ST&E, A&A

Preferred Qualifications

  • Bachelor’s degree in Cybersecurity or related field.
  • Experience in cybersecurity compliance, such as Assessment & Authorization under RMF.
  • Top Secret access, SAP/SAR access, SCI access, and a Polygraph.
  • Knowledge of security tools including EMASS, Xacta, ACAS, Nessus, Splunk, SEPM, and SCAP.
  • Knowledge of security frameworks and documentation such as NIST, JSIG, DAAG, SSPs, POA&Ms, and SCTMs.

Work Location, Travel, and Clearance

  • Location: Cincinnati, OH (on-site)
  • Travel: Yes, 10% of the time
  • Clearance required for start: Yes
  • Clearance type: Secret
  • Relocation assistance: No relocation assistance available

Compensation & Benefits

  • Salary range (primary): USD 103,600 - 155,400 per year
  • Salary range (secondary): USD 129,300 - 193,900 per year
  • Exceptional benefits/healthcare
  • 9/80 work schedule
  • 401k matching program
  • Eligible for overtime, shift differential, and a discretionary bonus in addition to base pay (depending on the position)
  • Annual bonuses designed to reward individual contributions and allow employees to share in company results
  • Long Term Incentives may be available for employees in Vice President or Director positions
  • Health insurance coverage, life and disability insurance, savings plan, company paid holidays, and paid time off (PTO) for vacation and/or personal business

Application Timeline

The application period is estimated to be 20 days from the job posting date. This timeline may be shortened or extended based on business needs and the availability of qualified candidates.

Similar Jobs