Northrop Grumman
Sr Principal Cybersecurity Analyst - R10204408
Northrop Grumman, Huntsville, Alabama, United States, 35824
Sr Principal Cybersecurity Analyst
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work — and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history. Description Northrop Grumman is seeking a Sr Principal Cybersecurity Analyst . Roles And Responsibilities Provide security oversight to NG classified environments that have information system(s). Conduct system assessments and audits to ensure controls are implemented according to internal and external policies, ensuring systems in classified environments supporting the business meet customer requirements. Ensure configuration management, policy, and procedures meet both security compliance and system mission requirements in accordance with the governance structure of the accrediting customer. Responsible for coordinating and supporting company requirements under Information Security Governance (ISG) for classified systems. Coordinate with the customer on categorization, schedules and approvals Drafts documentation for system authorization/re-authorizations, as required by government regulatory agencies. Ensures systems are operated, maintained, and disposed of in accordance with internal security policies and practices outlined in the security plan Communicates with Industrial Security to ensure that all users have the requisite security clearances, authorization, and need-to-know, and are aware of their security responsibilities before granting access Ensures all information system security-related documentation is current and accessible to properly authorized individuals Working with security, follows documented sanitization/declassification procedures to remove/dispose/calibrate classified hardware within program Require each user to sign proper documentation prior to system access Mark and label all system media in accordance with Industrial Security/government requirements Evaluate proposed changes or additions to the information system, and advises the Information Systems Security Manager (ISSM) or Alternate ISSM of their security relevance Participates in internal/external security audits/inspections Maintains copies of audit logs and maintenance logs required by government agencies Validates system technical security controls to ensure operating systems are hardened according to government requirements Report incidents (security, procedures, anomalies) to Industrial Security Support Government audits (as required) Deliverables: Comprehensive risk assessment reports (quarterly), Incident response reports within 48 hours of an event, Updated cybersecurity policies and procedures (biannually), Documentation for system authorization and re-authorization (as required), Monthly threat landscape reports, Audit and maintenance logs (regularly updated for compliance) Basic Qualifications Bachelor's degree with 8 years of Information Systems Security experience; OR Master’s degree with 6 years of Information Systems Security experience or 4 years with a PhD. Must have an active U.S. Government DoD Secret security clearance at time of application, current and within scope, with an ability to obtain and maintain Special Access Program (SAP) approval within a reasonable period of time, as determined by the company to meet its business need Must have a current DOD 8570 IAM Level III security certification (Examples: CISSP, GSLC, CISM) Front-end Tenable knowledge - Building Reports for different execution levels 3+ years Tenable backend experience in administration, configuration and troubleshooting Demonstrated expert knowledge of cybersecurity practices, network technologies, system development life-cycles understanding of information technology infrastructure management/monitoring and applications Experience developing cybersecurity tools for cybersecurity frameworks and industry best practices supporting National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 and DoD Risk Management Framework (RMF) for SAP systems. Preferred Qualifications Back-end Splunk experience for a large WAN with over 3000 systems a large R&D footprint and a containerized environment for software development. Strong STIG compliance using various tools like SCAP Tool and Trellix Policy Auditor Basic knowledge of other security tools Tenable, Trellix, Titus Scripting/Ansible abilities Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit http://www.northropgrumman.com/EEO. U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.
#J-18808-Ljbffr
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work — and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history. Description Northrop Grumman is seeking a Sr Principal Cybersecurity Analyst . Roles And Responsibilities Provide security oversight to NG classified environments that have information system(s). Conduct system assessments and audits to ensure controls are implemented according to internal and external policies, ensuring systems in classified environments supporting the business meet customer requirements. Ensure configuration management, policy, and procedures meet both security compliance and system mission requirements in accordance with the governance structure of the accrediting customer. Responsible for coordinating and supporting company requirements under Information Security Governance (ISG) for classified systems. Coordinate with the customer on categorization, schedules and approvals Drafts documentation for system authorization/re-authorizations, as required by government regulatory agencies. Ensures systems are operated, maintained, and disposed of in accordance with internal security policies and practices outlined in the security plan Communicates with Industrial Security to ensure that all users have the requisite security clearances, authorization, and need-to-know, and are aware of their security responsibilities before granting access Ensures all information system security-related documentation is current and accessible to properly authorized individuals Working with security, follows documented sanitization/declassification procedures to remove/dispose/calibrate classified hardware within program Require each user to sign proper documentation prior to system access Mark and label all system media in accordance with Industrial Security/government requirements Evaluate proposed changes or additions to the information system, and advises the Information Systems Security Manager (ISSM) or Alternate ISSM of their security relevance Participates in internal/external security audits/inspections Maintains copies of audit logs and maintenance logs required by government agencies Validates system technical security controls to ensure operating systems are hardened according to government requirements Report incidents (security, procedures, anomalies) to Industrial Security Support Government audits (as required) Deliverables: Comprehensive risk assessment reports (quarterly), Incident response reports within 48 hours of an event, Updated cybersecurity policies and procedures (biannually), Documentation for system authorization and re-authorization (as required), Monthly threat landscape reports, Audit and maintenance logs (regularly updated for compliance) Basic Qualifications Bachelor's degree with 8 years of Information Systems Security experience; OR Master’s degree with 6 years of Information Systems Security experience or 4 years with a PhD. Must have an active U.S. Government DoD Secret security clearance at time of application, current and within scope, with an ability to obtain and maintain Special Access Program (SAP) approval within a reasonable period of time, as determined by the company to meet its business need Must have a current DOD 8570 IAM Level III security certification (Examples: CISSP, GSLC, CISM) Front-end Tenable knowledge - Building Reports for different execution levels 3+ years Tenable backend experience in administration, configuration and troubleshooting Demonstrated expert knowledge of cybersecurity practices, network technologies, system development life-cycles understanding of information technology infrastructure management/monitoring and applications Experience developing cybersecurity tools for cybersecurity frameworks and industry best practices supporting National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 and DoD Risk Management Framework (RMF) for SAP systems. Preferred Qualifications Back-end Splunk experience for a large WAN with over 3000 systems a large R&D footprint and a containerized environment for software development. Strong STIG compliance using various tools like SCAP Tool and Trellix Policy Auditor Basic knowledge of other security tools Tenable, Trellix, Titus Scripting/Ansible abilities Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit http://www.northropgrumman.com/EEO. U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.
#J-18808-Ljbffr