Principal/Cyber Systems Engineer (Top Secret) Space Systems (Dulles) - R10194647
Dulles, VA
Full-time
Onsite
$98K/yr - $148K/yr
Entry, Mid, Senior Level, Lead/Staff
Northrop Grumman is an aerospace, defense and security company that provides training and satellite ground network communications software. They are seeking a Principal Cyber Systems Engineer to focus on ground segment cloud infrastructure security and mission application software development in an Agile environment, collaborating with integrated software product teams to ensure secure software solutions.
Working in an Agile engineering environment, where the Cyber Systems Engineer may assist identifying and prioritizing security requirements; triage of Static Code Analysis (SCA) tool findings (e.g. Fortify) and assist in prioritizing the findings as technical debt in the Software Development LifeCycle (SwDLC) backlog.
Advising software development scrum teams on secure coding practices, security-focused engineering trade studies, and other security best practices.
Conducting security assessments of mission software applications to include code reviews, vulnerability assessments, application security testing, while contributing to the overall security posture of the system and software architecture
Assist in the development and implementation of security tools and automation processes; to include Static and Dynamic Code Analysis, Software Dependency Scanning, Compliance and Vulnerability Scanning
Developing standard Risk Management Framework (RMF) artifacts, such as System Security Plan (SSP), Risk Assessment Report (RAR), Security Controls Traceability Matrix (SCTM), Plans of Action & Milestones (POA&Ms), and additional security policies and best practices for application security
Familiarity with the system accreditation process to achieve Authority to Operate (ATO) and experience in conducting system security assessments outlined through the RMF process
Conducting system vulnerability scanning, remediation and patch management activities on Windows and Red Hat operating systems and various COTS/GOTS applications, including those within virtualized and/or cloud environments.
Documenting Standard Operating Procedures (SOPs), and when needed, performing software patch installation, other flaw remediation, antivirus updates, and continuous monitoring (ConMon) activities.
Ensuring systems are operated, maintained, and disposed of in accordance with security policies and procedures as outlined in the system security authorization package.
Qualification
Required
Bachelor’s Degree (STEM) with 2 Years of relevant experience, or a Master’s Degree (STEM) with 1 year of professional experience (excluding graduate assistant/internships/etc.) Experience can be considered in lieu of degree
Bachelor’s Degree (STEM) with 5 Years of relevant experience, or a Master’s Degree (STEM) with 3 years of relevant experience, or a PhD (STEM) with 1 year of professional experience (excluding graduate assistant/internships/etc.) Experience can be considered in lieu of degree
Active Top Secret (TS) Security Clearance and U.S. Citizenship required
Possess or ability to obtain any DoD 8570 baseline cybersecurity certifications
Exposure to NIST 800-37 (Risk Management Framework), NIST 800-53 (Security and Privacy Controls for Information Systems) and OWASP Top 10 (Web Application Security) security controls and the Systems Engineering requirements analysis, decomposition, and analysis process
Experience in Application Security, Software Development, DevOps, Vulnerability Management and/or related field
Demonstrated knowledge of Software Development Lifecycle (SwDLC), Systems Engineering Review Processes, and System/Software Accreditation Milestones
Flexible Schedules (For example the ability to work a 9/80 work schedule, which allows an employee to work a nine-hour day Monday through Thursday and take every other Friday off of work)
Northrop Grumman is an aerospace, defense and security company that provides training and satellite ground network communications software.
Glassdoor
4.0
Founded in 1994
Falls Church, Virginia, USA
10001+ employees
https://www.northropgrumman.com
Northrop Grumman is an aerospace, defense and security company that provides training and satellite ground network communications software.