Northrop Grumman Defense Systems is seeking Principal Cybersecurity Analyst. This position will be located in Roy, Utah and will support the Sentinel program.
What You’ll Get To Do:
Specific duties to include, but are not limited to the following:
Perform assessments of systems and networks within the networking environment or enclave and identify where those systems and networks deviate from acceptable configurations, enclave policy, or local policy. This is achieved through passive evaluations such as compliance audits and active evaluations such as vulnerability assessments.Establishes strict program control processes to ensure mitigation of risks and supports obtaining certification and accreditation of systems. Includes support of process, analysis, coordination, security certification test, security documentation, as well as investigations, software research, hardware introduction and release, emerging technology research inspections and periodic audits.Assist in the implementation of the required government policy (i.e., NISPOM, DCID 6-3), make recommendations on process tailoring, participate in and document process activities.Perform analyses to validate established security requirements and to recommend additional security requirements and safeguards.Support the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results and preparation of required reports.Document the results of Certification and Accreditation activities and technical or coordination activity and prepare the system Security Plans and update the Plan of Actions and Milestones POA&M.Periodically conduct a complete review of each system's audits and monitor corrective actions until all actions are closed. Interface with Government customers and Northrop Grumman leadership on program initiatives and deliver status updates. Maintain and lead multiple complex efforts with multiple stakeholders and drive Cybersecurity requirements in an effort to further program initiatives.Position Benefits:
As a full-time employee of Northrop Grumman, you are eligible for our robust benefits package including
• Medical, Dental & Vision coverage
• 401k
• Educational Assistance
• Life Insurance
• Employee Assistance Programs & Work/Life Solutions
• Paid Time Off
• Health & Wellness Resources
• Employee Discounts
This position's standard work schedule is a 9/80. The 9/80 schedule allows employees who work a nine-hour day Monday through Thursday to take every other Friday off. This role may offer a competitive relocation assistance package.
Basic Qualifications:
• 5 Years with Bachelor’s in related field of study, 3 Years with Masters, 1 Years with PhD or 4 additional years in lieu of a degree.
• Active DoD Secret security clearance with an adjudication or reinvestigation date within the past 5 years.
• The ability to obtain and maintain Special Access Program (SAP) approval within a reasonable period of time, as determined by the company to meet its business need
• The ability to maintain both your security clearance and program access is required for this position.
• DoD IAT Level II (Sec+ etc)
• Experience in planning and assessing enterprise-level security, including interpreting/applying security tool generated reports such as Splunk, Trellix, Tenable, and STIGs.
• Knowledge of Risk Management Framework (RMF), Security Technical Implementation Guide (STIG), and requirements development from control listings.
• Ability to manage multiple responsibilities related to the creation and publication of artifacts included in a Body of Evidence for submission to support issuance of an Authorization to Operate (ATO).
• Capable of assessing the Program's system security posture in compliance with customer requirements and directives.
Preferred Qualifications:
• Experience reviewing and enforcing JSIG requirements for documenting Body of Evidence for Authority to Operate consideration.
• Experience with RMF (NIST 800-37) accreditation functions, including documentation, scanning, assessment, Plan of Action and Milestones (POAM) management, and all steps of the RMF process.
Experience developing and reviewing Concept of Operations documents for customer approval
• Working knowledge and understanding of auditing, vulnerability scanning/remediation, SIEMs, DISA STIGs, configuration/change control, and implementation of Risk Management Framework.
• Strong verbal and written communication skills to produce coherent and concise documentation required for evaluation.
• Detailed oriented and able to track multiple tasks and status.