Sr Principal Cybersecurity Analyst Job at Northrop Grumman Corp. (JP) in Huntsvi
Northrop Grumman Corp. (JP), Huntsville, AL, United States, 35824
Overview
Northrop Grumman is seeking a Sr Principal Cybersecurity Analyst. Relocation assistance may be available. Clearance type: Secret. Travel: Yes, 10% of the time.
At Northrop Grummo n, our employees have incredible opportunities to work on revolutionary systems that impact people’s lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation’s history. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work — and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they\'re making history.
Role
Northrop Grumman is seeking a Sr Principal Cybersecurity Analyst
Responsibilities
- Provide security oversight to NG classified environments that have information system(s).
- Conduct system assessments and audits to ensure controls are implemented according to internal and external policies, ensuring systems in classified environments supporting the business meet customer requirements.
- Ensure configuration management, policy, and procedures meet security compliance and system mission requirements in accordance with the governance structure of the accrediting customer.
- Coordinate and support company requirements under Information Security Governance (ISG) for classified systems. Provide guidance for designing security solutions to ensure selected controls provide adequate compliance with governing standards.
- Coordinate with the customer on categorization, schedules and approvals.
- Draft documentation for system authorization/re-authorizations as required by government regulatory agencies.
- Ensure systems are operated, maintained, and disposed of in accordance with internal security policies and practices outlined in the security plan.
- Communicate with Industrial Security to ensure users have requisite security clearances, authorization, and need-to-know before granting access.
- Ensure all information system security-related documentation is current and accessible to properly authorized individuals.
- Follow documented sanitization/declassification procedures to remove/dispose/calibrate classified hardware within program.
- Require each user to sign proper documentation prior to system access.
- Mark and label all system media in accordance with Industrial Security/government requirements.
- Evaluate proposed changes or additions to the information system and advise the Information Systems Security Manager (ISSM) or Alternate ISSM of their security relevance.
- Participate in internal/external security audits/inspections.
- Maintain copies of audit logs and maintenance logs required by government agencies.
- Validate system technical security controls to ensure operating systems are hardened according to government requirements.
- Report incidents (security, procedures, anomalies) to Industrial Security.
- Support Government audits (as required).
- Deliverables: Comprehensive risk assessment reports (quarterly), Incident response reports within 48 hours of an event, Updated cybersecurity policies and procedures (biannually), Documentation for system authorization and re-authorization (as required), Monthly threat landscape reports, Audit and maintenance logs (regularly updated for compliance).
Basic Qualifications
- Bachelor\'s degree with 8 years of Information Systems Security experience; OR Master\'s degree with 6 years of Information Systems Security experience or 4 years with a PhD.
- Active U.S. Government DoD Secret security clearance at time of application, current and within scope, with ability to obtain and maintain Special Access Program (SAP) approval within a reasonable period of time.
- Current DoD 8570 IAM Level III security certification (e.g., CISSP, GSLC, CISM).
- Front-end Tenable knowledge - Building Reports for different execution levels.
- 3+ years Tenable backend experience in administration, configuration and troubleshooting.
- Demonstrated expert knowledge of cybersecurity practices, network technologies, SDLC understanding of IT infrastructure management/monitoring and applications.
- Experience developing cybersecurity tools for cybersecurity frameworks and industry best practices supporting NIST SP 800-53 and DoD RMF for SAP systems.
Preferred Qualifications
- Back-end Splunk experience for a large WAN with over 3000 systems, large R&D footprint and a containerized environment for software development.
- Strong STIG compliance using tools like SCAP Tool and Trellix Policy Auditor.
- Basic knowledge of other security tools Tenable, Trellix, Titus.
- Scripting/Ansible abilities.
Salary and Benefits
Primary Level Salary Range: $118,600.00 - $178,000.00
The above salary range represents a general guideline; Northrop Grumman considers factors such as scope and responsibilities, candidate experience, education, skills and current market conditions when determining base offers.
Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses reward individual contributions and company results. VP or Director positions may be eligible for Long Term Incentives. Northrop Grumman provides benefits including health insurance, life and disability insurance, a savings plan, company-paid holidays and paid time off (PTO).
Application Window
The application period for the job is estimated to be 20 days from the job posting date. This timeline may be shortened or extended depending on business needs and candidate availability.
EEO Statement
Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit http://www.northropgrumman.com/EEO. U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.