Cyber Systems Engineer/ Principal Cyber Systems Engineer
Northrop Grumman · Colorado Springs, CO · 1 wk ago
On-siteInformation Technology$92k–$138k/yrFull-time
About the role
This position is contingent upon the candidate obtaining final clearances and program access(es) within a reasonable period of time as determined by the company.
Responsibilities
- Develop systems using current technologies and others yet to come.
- Conduct annual security controls assessment to support continuous monitoring.
- Prepare and update artifacts, supporting Assessment and Authorization activities and Plan of Actions and Milestones (POA&M).
- Perform assessments of RMF artifacts and identify where those artifacts deviate RMF control requirements.
- Coordinate, collect, prepare, and maintain RMF body of evidence documentation relevant to operational processes, procedures, and site-specific information.
- Support the implementation of the required government policy (e.g., NISPOM, NIST, DoD, AFI).
- Perform analyses to validate established cybersecurity controls and requirements and to recommend cybersecurity safeguards.
- Coordinate across the program to address identified deficiencies during RMF assessment activities.
Requirements
- Active U.S. Government Secret security clearance at time of application.
- Current DoD 8570.01M IAT II certification (Security+ CE, CCNA Security, GSEC, SSCP).
- Security engineering skills with a working knowledge of cybersecurity technology and DoD/Federal cybersecurity policy.
- Familiarity in the Risk Management Framework (RMF) Cybersecurity Lifecycle to include generating testable requirements, identifying resilient architecture design, providing analysis of vulnerability findings, conducting verification testing of compliance assessments, and configuring, running, and scripting audit tools.
- Technical documentation and analysis experience; proficient with Microsoft Office tool suite.
- Experience performing vulnerability and compliance scans utilizing Assured Compliance Assessment Solution (ACAS) / Nessus / tenable.sc.
- Linux Sys Admin Experience.
Qualifications
- Level 2: Bachelor’s degree with 2 years of professional experience – OR – Master’s degree with 0 years of professional experience.
- Level 3: Bachelor’s degree with 5 years of professional experience – OR – Master’s degree with 3 years of professional experience – OR – PhD with 1 year of professional experience.
Skills
- Penetration testing focuses on certification e.g., OSCP, OSCE, GPEN, GWAPT, GXPN.
- Experience using and/or configuring SIEM & Log Aggregation software.
- Experience conducting cybersecurity assessments of RHEL environments.
- Familiarity with STIG/SCAP compliance scanning (SCC) and implementation using Evaluate-STIG, STIG Manager, Xylok, and automation of scanning using Ansible or Python.
- Familiarity or experience with Agile development methodologies, i.e., Scrum, Kanban, SAFe.
- Familiarity with Jira and/or other Atlassian tools.
- VMWare/Container Experience.
- eMASS experience and familiarization with ATOE.
- Elastic Stack experience.
- Cross-Domain Solution (CDS) experience and its authorization, working with Cross-Domain Support Element (CDSE) and the National Cross Domain Strategy & Management Office (NCDSMO).
- IAT III Certification (CISSP).