> Markdown version of [/jobs/ext/1248793-cyber-protection-principal-sr-principal-engineer-aht](https://www.wearedevelopers.com/jobs/ext/1248793-cyber-protection-principal-sr-principal-engineer-aht). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Protection Principal/Sr. Principal Engineer-AHT - **Company:** Northrop Grumman - **Location:** Warner Robins, GA, United States - **Experience:** Expert - **Salary:** $98,400.0 - $155,400.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Engineering, Code Review, Continuous Integration, Github, Identity and Access Management, Python (Programming Language), OAuth, Windows PowerShell, Comptia Pentest+ CE, Software Engineering, Scripting, Mitre Att&ck, Gitlab, Kubernetes, Atlassian Tools, Jenkins - **Published:** July 12, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9025834/cyber-protection-principalsr-principal-engineer-aht ## About the Role * Bachelor's degree in Science with 5+ years of software development experience; Master's with 3+ years of relative experience; or an additional 4 years of experience may be considered in lieu of degree. * Bachelor's degree in Science with 8+ years of software development experience; Master's with 6+ years of relative experience; or an additional 4 years of experience may be considered in lieu of degree. * This position requires an active Top Secret/SCI clearance and the ability to obtain an IAT Level II or III certification (Security+, Pentest+, SecurityX,) within 60 days of start. * Deep knowledge of cloud attack paths - IAM privilege escalation, metadata service abuse, misconfigured storage, cross-account trust exploitation, and OAuth/token abuse - is required. * Proficiency with cloud-native offensive tooling including Pacu (AWS exploitation framework) and AADInternals (Azure/M365 offensive toolkit), alongside enumeration platforms such as ScoutSuite, CloudFox, Prowler, and ROADtools. * Prior DoD or IC classified environment experience and familiarity with adversary simulation platforms such as Cobalt Strike, Sliver, or Havoc are a strong plus. * Hands-on practitioner who has operated tools at depth across real engagements, documented findings under active assessment constraints, and can communicate risk clearly to both technical teams and senior leadership. * Experience developing and executing cyber tabletop exercises including threat scenario design, threat actor emulation planning, and after-action reporting is highly valued. * Hands-on experience with Docker and Kubernetes security assessments, including container escape techniques, privileged container abuse, K8s RBAC misconfigurations, service account taken abuse, and CI/CD pipeline security across GitLab, GitHub Actions, and Jenkins environments. * Strong scripting skills in Bash, Python, and PowerShell are expected, and a working knowledge of MITRE ATT&CK as applied to cloud and hybrid environments * Preferred certifications include OSCP, CPTS, PNPT, GPEN, GXPN, GCPN, AWS Security Specialty, or AZ-500. * Day-to-day work Jira and Confluence for sprint and documentation workflows, and GitHub for version controlled tooling and collaborative code review. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)