Sr. Principal Cybersecurity Engineer Lead
Relocation assistance may be available. Active Top Secret (TS) security clearance required at the time of application; SCI eligible and U.S. citizenship required. Travel: 10% of the time.
About the role
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. We look for people who have bold new ideas, courage, and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity, and bringing your whole self to work.
We are looking for an Experienced Cybersecurity Professional to join our Cybersecurity Integrated Product team (IPT) who will maintain an enhanced focus on ground segment cloud infrastructure and lead the cybersecurity posture of mission-critical information systems in a 100% Agile Development and Operational environment(s) from design through decommissioning. In this role, you will operate as the Deputy Cybersecurity Lead and Deputy Information System Security Manager. You will work closely with the integrated product teams to develop and decompose software security requirements, technical architectures, and system designs, and provide technical oversight to the organization. You will collaborate with the Platform Deployment team supporting the implementation of secure infrastructure, Continuous Integration/Continuous Deployment (CI/CD) pipelines, and achieving accreditation and sustainment of a private cloud infrastructure.
Responsibilities
- Lead Risk Management Framework (RMF) activities, including Assessment and Authorization (A&A), Continuous Monitoring, and Vulnerability Management.
- Work in an Agile engineering environment to lead the design, development, and/or implementation of secure systems, ensuring compliance with program security requirements.
- Assist in identifying, prioritizing, and guiding strategic oversight of software security requirements, including triage of Static Code Analysis (SCA) tool findings (e.g., Fortify) and prioritizing findings as technical debt in the Software Development LifeCycle (SwDLC) backlog.
- Advise internal and external program stakeholders on cybersecurity approaches for cloud systems, security-focused engineering trade studies, and other security best practices.
- Assist in the identification, development, and implementation of security tools and automation processes, including Static and Dynamic Code Analysis, Software Dependency Scanning, Compliance and Vulnerability Scanning, and Auditing & Event Monitoring Solutions (Splunk).
- Develop standard Risk Management Framework (RMF) artifacts, such as System Security Plan (SSP), Risk Assessment Report (RAR), Security Controls Traceability Matrix (SCTM), Plans of Action & Milestones (POA&Ms), and additional security policies and best practices for application and system security.
- Oversee the system accreditation process to achieve Authority to Operate (ATO), including conducting system security assessments outlined through the RMF process.
- Conduct system vulnerability scanning, remediation, and patch management activities on Windows and Red Hat operating systems and various COTS/GOTS applications, including those within virtualized and/or cloud environments.
- Document Standard Operating Procedures (SOPs) and perform software patch installation, flaw remediation, antivirus updates, and continuous monitoring (ConMon) activities as needed.
- Ensure systems are operated, maintained, and disposed of in accordance with security policies and procedures as outlined in the system security authorization package.
- Manage security assessments of mission software applications, including code reviews, vulnerability assessments, and application security testing.
Requirements
- Bachelor’s Degree in a STEM field with 8 years of relevant experience, Master’s Degree in a STEM field with 6 years of relevant experience, or PhD in a STEM field with 4 years of relevant experience.
- Active Top Secret (TS) security clearance at the time of application; SCI eligible and U.S. citizenship required.
- Possess CISSP, CSSLP, CASP, CISM, or equivalent certification.
- Strong understanding of NIST 800-37 (Risk Management Framework), NIST 800-53 (Security and Privacy Controls for Information Systems), and OWASP Top 10 (Web Application Security) security controls.
- Experience with Cloud Security and Best Practices.
- Strong understanding of Event Monitoring architectures, components, and deployment options; experience building and maintaining an Event Monitoring solution (e.g., Splunk) in a cloud environment.
- Demonstrated knowledge of Software Development Lifecycle (SwDLC), Systems Engineering Review Processes, and System/Software Accreditation Milestones.
- Technical leadership and/or mentorship experience.
Preferred Qualifications
- Bachelor’s and/or Master’s Degree in Computer Science, Cybersecurity, or Information Systems Management.
- 2+ years of experience in the Defense Space Industry.
- Experience and/or certification in Earned Value Management (EVM).
- Experience in Application Security, Software Development, DevOps, and/or related fields.
- Experience with Embedded (C/C++), Scripting (Python), and Object-Oriented Programming languages (Java); previous development experience preferred.
- Familiarity with Zero-Trust Security Principles and Implementation Approaches.
Pay
Primary level salary range: $156,400.00 - $234,600.00. The above salary range represents a general guideline; Northrop Grumman considers a number of factors when determining base salary offers, such as the scope and responsibilities of the position and the candidate's experience, education, skills, and current market conditions. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives.
Benefits
- Health insurance coverage.
- Life and disability insurance.
- Savings plan.
- Company-paid holidays and paid time off (PTO) for vacation and/or personal business.