Principal Classified Cybersecurity Analyst
Job Description
Northrop Grumman’s CIDO Classified Solutions team is seeking a Principal Classified Cybersecurity Analyst (ISSO) to support information systems lifecycle activities in a classified environment. This full-time role is based on-site in Gilbert, AZ and works across audit, monitoring, assessments, and Security Test & Evaluation (ST&E) support, with required compliance and authorization documentation.
Key details: USD 98,400 - 147,600 per year, Top Secret clearance required for start, and up to 10% travel.
Role overview
- Support system security lifecycle activities, including audits, continuous monitoring, assessments, A&A support, and ST&E.
- Operate within government accreditation requirements by producing and maintaining A&A evidence and related documentation.
- Maintain alignment with enclave policy, local policy, and acceptable security configurations.
Responsibilities
- Conduct system audits and continuous monitoring across security controls, configurations, and operational processes to evaluate information system security posture.
- Perform assessments of systems and networks within a networking environment or enclave, identifying deviations from acceptable configurations, enclave policy, or local policy.
- Validate established security requirements through analysis and recommend additional requirements and safeguards.
- Assist in implementing required government policy, including recommendations on process tailoring, and participate in and document process activities.
- Establish program control processes to support Assessment and Authorization (A&A), including process support, analysis, coordination, security certification testing, security documentation, investigations, software research, hardware introduction and release, emerging technology research, inspections, and periodic audits.
- Support formal Security Test and Evaluation (ST&E) for each government accrediting authority through pre-test preparations, test participation, result analysis, and required report preparation.
- Document A&A activity outcomes and prepare Risk Management Framework (RMF) body of evidence from technical and coordination efforts.
Requirements
- Master’s degree with 3 years relevant technical experience; OR Bachelor’s degree with 5 years; OR Associates degree with 7 years; OR High School Diploma/GED with 9 years relevant technical experience.
- Meet U.S. Government 8140 (8570) requirements for a Principal Classified Cybersecurity Analyst IAM level II equivalent (or higher) security certification (examples provided: CAP or CGRC, CASP+ or CompTIA Security X, GSLC, CISSP-Associate, CISM, CISSP, CCISO).
- Maintain a current U.S. Government Top Secret clearance (minimum), including a closed investigation date within the last 6 years, OR be enrolled in the U.S. Government Continuous Evaluation (CE) Program to be considered.
- Ability to obtain and maintain access to Special Access Programs as a condition of continued employment.
Technologies
- ACAS, Nessus, Splunk, Trellix, SCAP, RMF, NIST, JSIG, DAAG
Benefits
- Exceptional benefits and healthcare
- 9/80 work schedule
- 401k matching program
- Eligibility for overtime, shift differential, and a discretionary bonus in addition to base pay (depending on position)
- Annual bonuses
- Potential Long Term Incentives for Vice President or Director positions
- Health insurance coverage
- Life and disability insurance
- Savings plan
- Company paid holidays
- Paid time off (PTO) for vacation and/or personal business
Travel and work model
- Travel: Yes, 10% of the Time
- On-site requirement: This position does not offer virtual or telecommute options due to the classified nature of the work.
- Clearance required for start: Yes
- Clearance type: Top Secret
- Relocation assistance: No relocation assistance available
Preferred qualifications
- Bachelor’s degree in Cybersecurity or a related field
- CISM / CASP+ / SecurityX
- Experience with cybersecurity compliance (example: Assessment & Authorization under RMF)
- SAP/SAR access, SCI access, and/or a Polygraph
- Knowledge of security tools such as ACAS, Nessus, Splunk, Trellix, and SCAP
- Knowledge of security frameworks and documentation such as NIST, JSIG, DAAG, SSPs, POA&Ms, and SCTMs