Sr. Principal Classified Cybersecurity Analyst
Job Description
Northrop Grumman is seeking a Sr. Principal Classified Cybersecurity Analyst to support information systems lifecycle activities for the Northrop Grumman Classified Solutions CIDO team. This full-time, on-site role is based in Redondo Beach, CA and is focused on cybersecurity program execution, continuous monitoring, and assessment and authorization support within classified environments requiring SCI access.
The position supports assigned systems through reviews, security testing and evaluation, documentation, and coordination with the security team to address findings with appropriate cognizant authorities. Employment is contingent on having the required clearance and maintaining counterintelligence polygraph eligibility.
Responsibilities
- Manage the cybersecurity program of all assigned information systems and perform all cybersecurity-related tasks.
- Conduct and lead regular reviews of system audits and continuous monitoring activities across security controls and configurations to improve the information system security posture.
- Assess systems and networks within a networking environment or enclave, identifying deviations from acceptable configurations, enclave policy, or local policy.
- Analyze and validate established security requirements, recommending additional security requirements and safeguards.
- Support implementation of required government policy, including recommendations on process tailoring and participation in and documentation of process activities.
- Establish and oversee program control processes that mitigate risk and support system Assessment and Authorization (A&A), including process support, analysis, coordination, security certification testing, security documentation, investigations, software research, hardware introduction and release, emerging technology research, inspections, and periodic audits.
- Lead formal Security Test and Evaluation (ST&E) activities required by each government accrediting authority, including pre-test preparations, participation, results analysis, and required reporting.
- Document the results of A&A and inspection activities, including technical or corrective actions, and coordinate with the security team to submit responses to the cognizant authority.
- Prepare, review, and submit A&A documentation (including System Security Plan, Risk Acceptance Report, Security Controls Traceability Matrix, Plan of Action and Milestones, and others) for review and approval.
Requirements
- Master’s degree with 6 years of relevant technical experience, OR Bachelor’s degree with 8 years, OR Associate’s degree with 10 years, OR High School Diploma/GED with 12 years of relevant technical experience.
- Must meet 8140 requirements for a Sr. Principal Classified Cybersecurity Analyst – IAM Level III (examples: CISSP, CISM, CCISO, GSLC).
- Must have a U.S. Government Top Secret security clearance including SCI access level eligibility at a minimum.
- Ability to obtain and maintain a Counter Intelligence Polygraph as a condition of continued employment.
Technologies
- CISSP, CISM, CCISO, GSLC
- ACAS, Nessus, Splunk, Trellix
- SCAP, RMF, NIST, JSIG, DAAG
- SSPs, POA&Ms, SCTMs
Benefits
- Health insurance coverage
- Life and disability insurance
- Savings plan
- 9/80 work schedule
- 401k matching program
- Company paid holidays
- Paid time off (PTO) for vacation and/or personal business
Additional Information
- Travel: No
- Relocation assistance: No relocation assistance available
- Clearance required for start: Yes
- Clearance type: SCI
- Remote/telecommute options: None. Due to the classified nature of the work, applicants should be prepared for on-site work.
Salary: USD 142,200 - 213,400 per year. Experience minimum: 6 years. Education: Master’s degree.
Preferred Qualifications
- Bachelor’s degree in Cybersecurity or related field
- Experience in cybersecurity compliance (example: Assessment & Authorization under RMF)
- Current TS/SCI with CI-Polygraph
- Knowledge of security tools such as ACAS, Nessus, Splunk, Trellix, and SCAP
- Knowledge of security frameworks and documentation such as NIST, JSIG, DAAG, SSPs, POA&Ms, and SCTMs