Principal Classified Cybersecurity Analyst
Job Description
Northrop Grumman is seeking a Principal Classified Cybersecurity Analyst (ISSO) to support information systems lifecycle activities on-site full-time in Dulles, VA. This role will manage classified cybersecurity program activities, including audits, continuous monitoring, RMF-related processes, and A&A documentation and reporting.
Location and Work Model
Dulles, VA (onsite)
Due to the classified nature of the work being performed, this position does not offer any virtual or telecommute working options. Applicants are encouraged to apply only if they are willing to work on-site.
Role Summary
Manage classified cybersecurity program activities for assigned information systems. Lead system audit reviews and continuous monitoring, support RMF-related processes, coordinate Security Test and Evaluation (ST&E) activities, and produce and submit A&A documentation for review and approval.
Key Responsibilities
- Manage the cybersecurity program for all assigned information systems and execute all cybersecurity-related tasks.
- Conduct and lead regular reviews of system audits and continuous monitoring activities, covering security controls and configurations to improve the information system security posture.
- Assess systems and networks within the networking environment or enclave and identify deviations from acceptable configurations, enclave policy, or local policy.
- Perform analyses to validate security requirements and recommend additional security requirements and safeguards.
- Drive implementation of required government policy, recommend process tailoring, and participate in and document process activities.
- Establish and oversee program control processes that mitigate risk and support system Assessment and Authorization (A&A), including process support, certification testing, security documentation, investigations, software research, hardware introduction and release, emerging technology research, inspections, and periodic audits.
- Lead the formal Security Test and Evaluation (ST&E) required by each government accrediting authority, including pre-test preparation, test participation, analysis of results, and preparation of required reports.
- Document results from A&A activities and inspections, including technical or corrective actions, and coordinate responses with the security team for submission to the appropriate cognizant authority.
- Prepare, review, and submit A&A documentation (including System Security Plan, Risk Acceptance Report, Security Controls Traceability Matrix, Plan of Action and Milestones, etc.) for review and approval.
Required Qualifications
- Education and experience: Master’s degree with 3 years of relevant technical experience; or Bachelor’s degree with 5 years; or Associate’s degree with 7 years; or High School Diploma/GED with 9 years.
- DoD 8140 / 8570 equivalent: Must meet U.S. Government 8140 requirements for a Principal Classified Cybersecurity Analyst – IAM level I certification or higher (examples include Security+, CND, Cloud+, CAP or CGRC, CASP+ or CompTIA Security X, GSLC, CISSP-Associate, CISM, CISSP, GSLC, CCISO).
- Security clearance: Must have a current U.S. Government Top Secret security clearance (minimum), including SCI eligibility based on a closed investigation date completed within the last 6 years, or be enrolled in the U.S. Government Continuous Evaluation (CE) Program.
- SAP access: Must be able to obtain and maintain access to Special Access Programs as a condition of continued employment.
Preferred Qualifications
- Bachelor’s degree in Cybersecurity or related field with 7 years of ISSO/ISSM experience in classified environment.
- CISSP.
- Experience in cybersecurity compliance (e.g., Assessment & Authorization under RMF).
- Knowledge of security tools such as ACAS, Nessus, Splunk, Trellix, and SCAP.
- Knowledge of security frameworks and documentation such as NIST, JSIG, DAAG, SSPs, POA&Ms, and SCTMs.
- Current TS/SCI with SAP access and a CI-Polygraph.
Security Clearance Information
- Required for start: Yes
- Clearance type: SCI
Travel
- Yes: 10% of the Time
Compensation
Primary level salary range: USD 114,000 - 171,000 per yearly
Benefits
- Flexible work arrangements
- Phenomenal learning opportunities
- Exposure to a wide variety of projects and customers
- Very friendly team environment
- Exceptional benefits/healthcare
- 9/80 work schedule
- 401k matching program
- Health insurance coverage
- Life and disability insurance
- Savings plan
- Company paid holidays
- Paid time off (PTO) for vacation and/or personal business
- Potential eligibility for overtime, shift differential, and a discretionary bonus in addition to base pay
- Annual bonuses designed to reward individual contributions and allow employees to share in company results
- Long Term Incentives for employees in Vice President or Director positions
Relocation Assistance
No relocation assistance available.
Application Period
Estimated to be 20 days from the job posting date.
Technologies and Documentation
- ACAS, Nessus, Splunk, Trellix
- SCAP
- NIST, JSIG, DAAG
- RMF
- System Security Plan
- Risk Acceptance Report
- Security Controls Traceability Matrix
- Plan of Action and Milestones (POA&Ms), SCTMs
- CISSP
- Security+, CND, Cloud+, CAP, CGRC, CASP+, CompTIA Security X
- GSLC, CISSP-Associate, CISM, CCISO