Principal Classified Cybersecurity Analyst
Job Description
Northrop Grumman is seeking a Principal Classified Cybersecurity Analyst (ISSO) to support information systems lifecycle activities in a classified environment. The position requires on-site work in Colorado Springs, CO and frequent travel to the East Coast (up to 25%).
Location and Work Schedule
- Location: Colorado Springs, CO (onsite)
- Schedule: 9/80 work schedule
- Travel: Yes, up to 25% of the time
- On-site requirement: Full-time on-site at the Colorado Springs, CO location
- Telecommute: Not available due to the classified nature of the work
Salary
Primary level salary range: USD 103,600 to 155,400 per year.
Role Responsibilities
- Conduct system audits and continuous monitoring activities across security controls, configurations, and operational processes to evaluate the security posture of information systems.
- Perform assessments of systems and networks within a networking environment or enclave, identifying deviations from acceptable configurations, enclave policy, or local policy.
- Analyze and validate established security requirements, and recommend additional security requirements and safeguards.
- Assist with implementation of required government policy, including recommendations for process tailoring and participation in and documentation of process activities.
- Establish strict program control processes to support mitigation of risks and the Assessment and Authorization (A&A) of systems, including process support, analysis, coordination, security certification testing, security documentation, investigations, software research, hardware introduction and release, emerging technology research, inspections, and periodic audits.
- Support the Security Test and Evaluation (ST&E) required by each government accrediting authority, including pre-test preparations, test participation, result analysis, and preparation of required reports.
- Document the results of A&A activities and related technical or coordination activities, and prepare the Risk Management Framework (RMF) body of evidence.
Minimum Qualifications
- Education and experience requirement: Master’s degree with 3 years of relevant technical experience; or Bachelor’s degree with 5 years; or Associate degree with 7 years; or High School Diploma/GED with 9 years.
- U.S. Government 8140 requirements: Must meet the 8570 equivalent for Principal Classified Cybersecurity Analyst – IAM level II certification or higher (examples: CAP or CGRC, CASP+ or CompTIA Security X, GSLC, CISSP-Associate, CISM, CISSP, GSLC, CCISO).
- Security clearance: Must have a current U.S. Government Secret level security clearance (minimum) to be considered.
Preferred Qualifications
- Bachelor’s degree in Cybersecurity or related field.
- U.S. Government 8140 IAM III certification (e.g., CISM, CISSP (or Associate), GSLC, etc.).
- Experience in cybersecurity compliance with DCSA, including Assessment & Authorization under RMF.
- Knowledge of security tools such as ACAS, Nessus, Splunk, Trellix, and SCAP.
- Knowledge of security frameworks and documentation including NIST, NISPOM, JSIG, DAAG, SSPs, POA&Ms, and SCTMs.
- Top Secret, SAP/SAR access, SCI access, and/or Polygraph preferred.
Security Clearance for Start
- Required: Yes
- Type: Secret
Benefits
- 401k matching program
- Health insurance coverage
- Life and disability insurance
- Savings plan
- Company paid holidays
- Paid time off (PTO) for vacation and/or personal business
Travel Requirements
Business travel is required, with an estimated frequency of up to 25% to the East Coast.