Cyber Systems Engineer – Cyber A&A Engineer (25-166)
Colorado Springs, CO
Full-time
Hybrid
$89K/yr - $134K/yr
Entry, Mid Level
Northrop Grumman is an aerospace, defense and security company that provides training and satellite ground network communications software. They are seeking a Cyber Systems Engineer – Cyber A&A Engineer to support the C2BMC program, which is vital for planning and managing ballistic missile defense operations. The role involves working closely with various stakeholders to ensure system compliance and assist with cyber product analysis and vulnerability management.
Will need to work closely with System owners, Cyber peers, Program Office technical/management staff, and other C2BMC Functional Areas to ensure the C2BMC fielded system attains and maintains appropriate Authorization for Connection, Test, and Operational purposes.
Must assist with Cyber Products analysis, Vulnerability mitigation, and POA&M Management to assist the team in the successful delivery of eMASS Packages, Ports Protocols, and Services (PPS) in accordance with contract schedules
Primary focus for the qualified candidate will rotate and blend technical documentation, surge support for authorization packages in eMASS, assess vulnerabilities, engineer responses for system POA&Ms, provide proposal support, and conduct risk analysis for Risk Acceptance Requests (RARs)
Requires a strong working knowledge of Cyber capabilities such as:
Patch management, multi-factor authentication, host-based security, intrusion detection, security event management, active/passive system scanning, and defense-in-depth
Recent experience and familiarity with creating/updating Assessment and Authorization (A&A) packages for RMF Authority to Operate (ATOs) is required
Qualification
Required
Bachelor’s Degree in a Computer Science, Technology, Cyber Engineering, Software Engineer, Systems Engineering, or Mathematics discipline preferred from an accredited university and 2 years of related experience or a Master’s degree in a related discipline and 0 years of experience, or 6 years of related experience instead of a degree may be considered.
Applicants must have a current active in-scope DoD-issued Secret security clearance at the time of application, which is required to start.
DoD 8140 certification at IAT Level II or higher (Security+, GSEC, SCNP, SSCP, CISSP, CISA, GSE, SCNA, etc.).
Requires security engineering skills with a working knowledge of Information Assurance (IA) technology, NIST standards, DoDI 8500.2, and Risk Management Framework (RMF) Security Controls.
Must have experience in the Agile Development Lifecycle, including generating requirements, designing architecture, configuring Cyber audit tools, conducting verification, and performing Cyber vulnerability and configuration activities.
Leadership experience and effective interpersonal skills are required, with a demonstrated ability to support complex organizational relationships.
Excellent technical document preparation and verbal communication skills are required for the presentation of technical Cyber issues and reports to the Government, Program Management, and other C2BMC Functional Areas.
Will need to work closely with System owners, Cyber peers, Program Office technical/management staff, and other C2BMC Functional Areas to ensure the C2BMC fielded system attains and maintains appropriate Authorization for Connection, Test, and Operational purposes.
Must assist with Cyber Products analysis, Vulnerability mitigation, and POA&M Management to assist the team in the successful delivery of eMASS Packages, Ports Protocols, and Services (PPS) in accordance with contract schedules.
Primary focus for the qualified candidate will rotate and blend technical documentation, surge support for authorization packages in eMASS, assess vulnerabilities, engineer responses for system POA&Ms, provide proposal support, and conduct risk analysis for Risk Acceptance Requests (RARs).
Requires a strong working knowledge of Cyber capabilities such as: Patch management, multi-factor authentication, host-based security, intrusion detection, security event management, active/passive system scanning, and defense-in-depth.
Recent experience and familiarity with creating/updating Assessment and Authorization (A&A) packages for RMF Authority to Operate (ATOs) is required.
Preferred
Recent hands-on experience with Agile execution, tools, and methodologies is highly preferred.
In-depth cyber vulnerability analysis experience is highly desired.
Application experience hardening Windows and Linux servers and workstations in accordance with GPOs, IAVMs, and STIGs is desired.
Network design and software engineering backgrounds are a plus.
Benefits
Health Plan
Savings Plan
Paid Time Off
Education Assistance
Training and Development
Flexible Work Arrangements
Northrop Grumman is an aerospace, defense and security company that provides training and satellite ground network communications software.
Glassdoor
4.0
Founded in 1994
Falls Church, Virginia, USA
10001+ employees
https://www.northropgrumman.com
Northrop Grumman is an aerospace, defense and security company that provides training and satellite ground network communications software.