Northrop Grumman Aeronautics Systems has an opening for a Principal Cybersecurity Systems Engineer or Senior Principal Cybersecurity Systems Engineer (CSSE) supporting the Triton program. A Cybersecurity Systems Engineer (CSSE) assess/evaluates the customers’/stakeholders’ cybersecurity requirements to decompose, derive, and refine with clarity the system’s cybersecurity requirements to drive the built-in cybersecurity protections to the architecture and design. The CSSE also guides/supports the security layout / architecture and influences the security tools selection and development. The CSSE evaluates/assess the proposed and realized implementation to identify security risks and verify the cybersecurity protections from the design are realized and integrated. The CSSE guides/supports the development of verification efforts to ensure the cybersecurity protections / capabilities are functional, effective, and complete. A CSSE supports the definition of security governance, and risk management.
As a Principal Cybersecurity Systems Engineer or Senior Principal Cybersecurity Systems Engineer on this team, you will have the following responsibilities:
• Perform software vulnerability assessment utilizing static code analysis tools.
• Experience with the RMF process. Generating and maintaining appropriate artifacts for Navy authorization decisions on several related systems.
• Experience performing and assessing system vulnerability scans utilizing tools such ACAS, and automated SCAP tools such as Evaluate STIG and Security Compliance Checker.
• Experience performing manual STIG / SRG verifications on disparate types of equipment including collecting and evaluating findings.
• Familiarity with agile and DevSecOps processes including work control tools such as JIRA
• Familiarity with DoD and Navy cybersecurity workforce requirements including certification and training, DoD 8140 and SECNAV M-5239.2.
This requisition may be filled as a Principal Cybersecurity Systems Engineer or Senior Principal Cybersecurity Systems Engineer.
Basic Qualifications for a Principal Cyber Systems Engineer
• Bachelor’s Degree in Systems Engineering, Cybersecurity Engineering, Computer Engineering, Computer Science or another STEM degree with a minimum 5 years of relevant experience; Master’s degree with at least 3 years of relevant experience, or a PhD with 0 years of experience.
• Direct Experience utilizing NIST 800-160 system security engineer and/or the system development life cycle.
• Foundational knowledge and hand-on experience with core systems engineering principles, including:
• Automate security related processes and tools utilizing scripting and resources such as Ansible, Python and PowerShell
• Experience supporting or leading cybersecurity impact assessments during design changes, capability upgrades, and baseline reviews
• Demonstrated experience performing and assessing system vulnerability scans utilizing tools such ACAS, and automated SCAP tools such as Evaluate STIG and Security Compliance Checker.
• A current/active DoD Secret clearance.
• Must have ability to obtain and maintain Program Access (PAR) within a reasonable period of time, as determined by the company to meet its business needs..
• In possession of a current IASAE II certification (CISSP preferred) in accordance with DoD 8140 or able to obtain within six months of hire.
Basic Qualifications for a Senior Principal Cyber Systems Engineer
•Bachelor’s Degree in Systems Engineering, Cybersecurity Engineering, Computer Engineering, Computer Science or another STEM degree with a minimum 5 years of relevant experience; Master’s degree with at least 6 years of relevant experience, or a PhD with 4 years of experience.
• Direct Experience utilizing NIST 800-160 system security engineer and/or the system development life cycle.
• Foundational knowledge and hand-on experience with core systems engineering principles, including:
• Automate security related processes and tools utilizing scripting and resources such as Ansible, Python and PowerShell
• Experience supporting or leading cybersecurity impact assessments during design changes, capability upgrades, and baseline reviews
• Demonstrated experience performing and assessing system vulnerability scans utilizing tools such ACAS, and automated SCAP tools such as Evaluate STIG and Security Compliance Checker.
• A current/active DoD Secret clearance.
• Must have ability to obtain and maintain Program Access (PAR) within a reasonable period of time, as determined by the company to meet its business needs.
• In possession of a current IASAE II certification (CISSP preferred) in accordance with DoD 8140 or able to obtain within six months of hire.
Preferred Qualifications
• System security architecture experience
• Experience with networking technologies, router and switch configurations, troubleshooting and security / vulnerability assessments
• Familiarity with Systems Security Engineering (SSE) documentation (e.g. Cybersecurity Strategies, Information Support Plans, Program Protection Plans (PPPs)
• DoDI 8140 certification for IASAE III (ISSEP, ISSAP)
• Active TS/SCI clearance