CybersecurityJobs.io
← Back to all jobs

Job Description

Northrop Grumman is seeking a Sr. Principal Classified Cybersecurity Analyst (ISSM) to support information systems lifecycle activities for Northrop Grumman CIDO Classified Solutions. This role requires on-site, full-time work in Baltimore, MD and will oversee cybersecurity program execution, including Assessment and Authorization (A&A) and Security Test and Evaluation (ST&E) activities.

Location and Work Schedule

  • Location: Baltimore, MD (onsite)
  • Work arrangement: On-site, full-time only (no virtual or telecommute options due to classified work)
  • Schedule: 9/80 work schedule
  • Travel: 10% of the time

Role Overview

As the ISSM for several programs, you will manage cybersecurity program activities across assigned information systems. Responsibilities include conducting audits and continuous monitoring reviews, identifying configuration and policy deviations, validating security requirements, and driving required government policy implementation with documentation and program controls. You will also lead formal ST&E efforts and support A&A documentation submission to the appropriate cognizant authority.

Key Responsibilities

  • Manage the cybersecurity program for all assigned information systems and execute cybersecurity-related tasks.
  • Conduct and lead regular reviews of system audits and continuous monitoring activities across security controls and configurations to improve the operational effectiveness of the information system security posture.
  • Assess systems and networks within the networking environment or enclave and identify deviations from acceptable configurations, enclave policy, and local policy.
  • Analyze established security requirements, and recommend additional requirements and safeguards.
  • Drive implementation of required government policy, recommend process tailoring, and participate in and document process activities.
  • Establish and oversee strict program control processes that mitigate risk and support system A&A, including process support, analysis, coordination, security certification testing, security documentation, investigations, software research, hardware introduction and release, emerging technology research, inspections, and periodic audits.
  • Lead formal Security Test and Evaluation (ST&E) efforts required by each government accrediting authority, including pre-test preparations, participation in tests, analysis of results, and preparation of required reports.
  • Document A&A and inspection results, along with technical or corrective actions, and support the security team in submitting responses to the appropriate cognizant authority.
  • Prepare, review, and submit A&A documentation such as System Security Plan, Risk Acceptance Report, Security Controls Traceability Matrix, and Plan of Action and Milestones for review and approval.
  • Act as the ISSM for several programs.

Salary Range

  • Annual salary: USD 135,800 - 203,600
  • Primary level salary range: $135,800.00 - $203,600.00

Required Qualifications

  • Education and experience: Master’s degree with 6 years of relevant experience, or Bachelor’s degree with 8 years of relevant experience, or Associate’s degree with 10 years of relevant experience. High School Diploma/GED with 12 years of relevant experience may be considered in lieu of a completed degree.
  • DoD 8140 certification requirements: Must meet U.S. Government 8140 requirements for Sr. Principal Classified Cybersecurity Analyst (ISSM) equivalent to CISSP or IAM III, and the certification must be maintained as a condition of continued employment.
  • Clearance: Current U.S. Government Top Secret clearance at a minimum, including a closed investigation date completed within the last 6 years, or enrollment in the U.S. Government Continuous Evaluation (CE) Program. Clearance must be maintained as a condition of continued employment.
  • SAP/SAR clearance: Obtain Special Access Program (SAP/SAR) clearance before a start date can be established; maintained as a condition of continued employment.

Technologies and Frameworks

  • ACAS, Nessus, Splunk, Trellix
  • SCAP, NIST, JSIG, DAAG
  • RMF

Benefits

  • Flexible work arrangements
  • Phenomenal learning opportunities
  • Exposure to a wide variety of projects and customers
  • Friendly team environment
  • Exceptional benefits/healthcare
  • 401k matching program
  • Depending on the position, potential eligibility for overtime, shift differential, and a discretionary bonus in addition to base pay
  • Annual bonuses designed to reward individual contributions and allow employees to share in company results
  • Long Term Incentives eligibility for employees in Vice President or Director positions
  • Health insurance coverage
  • Life and disability insurance
  • Savings plan
  • Company paid holidays
  • Paid time off (PTO) for vacation and/or personal business

Additional Information

  • Clearance required for start: Yes
  • Clearance type: Top Secret
  • Relocation assistance: No relocation assistance available
  • Application period: Estimated to be 20 days from the job posting date

Preferred Qualifications

  • Bachelor’s degree in Cybersecurity or related field
  • Experience in cybersecurity compliance (example: Assessment & Authorization under RMF)
  • Knowledge of security tools such as ACAS, Nessus, Splunk, Trellix, and SCAP
  • Knowledge of security frameworks and documentation such as NIST, JSIG, DAAG, SSPs, POA&Ms, and SCTMs

Similar Jobs