> Markdown version of [/jobs/ext/1017581-principal-sr-principal-cyber-information-assurance-analyst](https://www.wearedevelopers.com/jobs/ext/1017581-principal-sr-principal-cyber-information-assurance-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal/Sr Principal Cyber Information Assurance Analyst - **Company:** Northrop Grumman - **Location:** McClellan Park, CA, United States - **Experience:** Expert - **Salary:** $142,200.0 - $213,400.0 - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Data Transmissions, File Transfer, Security Information and Event Management, Splunk, Vulnerability Analysis - **Published:** June 20, 2026 - **Apply:** https://dejobs.org/x/x/C9CD4C5039BB4B2E9B713DC29E0F9B6E/job/ ## About the Role * Bachelor's degree and 5 years of relevant experience; 3 years with a Masters; 1 year with a PhD. An additional 4 years of relevant experience may be considered in lieu of a degree. * Active Top Secret clearance with SCI eligibility * Must possess an IAT Level II (DoD 8570) certification * Experience with Risk Management Framework accreditation functions, including documentation, scanning, assessment, POAM management, through all steps of the RMF * Experience with Continuous Monitoring to comply with RMF * Experience with cybersecurity, information security and information assurance roles * Experience executing and monitoring security tools, such as SIEM, Splunk, and vulnerability and compliance scanners * Demonstrated ability to handle multiple levels of classified systems and data and follow data transfer/trusted download/assured file transfer processes, * Bachelor's degree and 8 years of relevant experience; 6 years with a Masters. 4 years with a PhD. An additional 4 years of relevant experience may be considered in lieu of a degree. * Active Top Secret clearance with SCI eligibility * Must possess an IAT Level II (DoD 8570) certification * Experience with Risk Management Framework accreditation functions, including documentation, scanning, assessment, POAM management, through all steps of the RMF * Experience with Continuous Monitoring to comply with RMF * Experience with cybersecurity, information security and information assurance roles * Experience executing and monitoring security tools, such as SIEM, Splunk, and vulnerability and compliance scanners * Demonstrated ability to handle multiple levels of classified systems and data and follow data transfer/trusted download/assured file transfer processes, * Bachelor's degree in a STEM discipline * Active TS/SCI clearance * Active DoD 8570 IAT Level II, or higher, certification such as CompTIA Security+; required to start and must be maintained ## Description * Perform assessments of systems and networks within the networking environment or enclave and identify where those systems and networks deviate from acceptable configurations, enclave policy, or local policy. * This is achieved through passive evaluations such as compliance audits and active evaluations such as vulnerability assessments. * Establishes strict program control processes to ensure mitigation of risks and supports obtaining certification and accreditation of systems. * Includes support of process, analysis, coordination, security certification test, security documentation, as well as investigations, software research, hardware introduction and release, emerging technology research inspections and periodic audits. * Assist in the implementation of the required government policy (i.e., NISPOM, ICD 503), make recommendations on process tailoring, participate in and document process activities. * Perform analyses to validate established security requirements and to recommend additional security requirements and safeguards. * Support the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results and preparation of required reports. * Document the results of Certification and Accreditation activities and technical or coordination activity and prepare the system Security Plans and update the Plan of Actions and Milestones POA&M. * Periodically conduct a complete review of each system's audits and monitor corrective actions until all actions are closed. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Devouring APIs with Python](https://www.wearedevelopers.com/videos/355-devouring-apis-with-python) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)