> Markdown version of [/jobs/ext/1427313-principal-sr-principal-penetration-tester](https://www.wearedevelopers.com/jobs/ext/1427313-principal-sr-principal-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal/Sr Principal Penetration Tester - **Company:** Northrop Grumman - **Location:** San Antonio, TX, United States - **Experience:** Expert - **Salary:** $103,600.0 - $155,400.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Continuous Integration, Linux, Github, Identity and Access Management, Python (Programming Language), Networking Basics, Windows PowerShell, Comptia Pentest+ CE, Ansible, Security Content Automation Protocol, Software Deployment, Virtualization Technology, Software Vulnerability Management, Data Logging, Scripting, Cloudformation, Containerization, Gitlab-ci, Kubernetes, Terraform, Splunk, Serverless Computing, Azure Resource Manager, Docker, Jenkins, Vulnerability Analysis, Vmware - **Published:** July 24, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8956076/principalsr-principal-penetration-tester ## About the Role * Bachelor's Degree and 5 years of related experience; or a Master's degree and 3 years of related experience. Note: 9 years of related experience may be considered in lieu of degree. * US Citizenship is required * Active US Government Top Secret Security Clearance is required with the ability to obtain an SCI. * Must possess a DoD 8570 Certification for IAT Level II or higher(Sec+, SSNA, CySA or CNS). * Experience conducting penetration testing, vulnerability analysis, or security assessments against cloud, enterprise, or hybrid environments. * Experience with cloud platforms such as AWS and Azure, including familiarity with IAM, networking, storage, logging, and security services. * Familiarity with CI/CD pipeline technologies and concepts, including GitHub Actions, GitLab CI/CD, Jenkins, Azure DevOps, or similar platforms. * Experience or familiarity with containerization and virtualization technologies such as Docker, Kubernetes, or VMware. * Knowledge of Windows and Linux operating systems, networking fundamentals, and common enterprise architecture. * Experience using scripting or automation languages such as Python, Bash, or PowerShell to support testing, analysis, or operational workflows. * Familiarity with offensive security methodologies, vulnerability management processes, and common attacker TTPs. * Bachelor's Degree and 8 years of related experience; or a Master's degree and 6 years of related experience. Note:12 years of related experience may be considered in lieu of degree. * US Citizenship is required * Active US Government Top Secret Security Clearance is required with the ability to obtain an SCI. * Must possess a DoD 8570 Certification for IAT Level II or higher(Sec+, SSNA, CySA or CNS). * Experience conducting penetration testing, vulnerability analysis, or security assessments against cloud, enterprise, or hybrid environments. * Experience with cloud platforms such as AWS and Azure, including familiarity with IAM, networking, storage, logging, and security services. * Familiarity with CI/CD pipeline technologies and concepts, including GitHub Actions, GitLab CI/CD, Jenkins, Azure DevOps, or similar platforms. * Experience or familiarity with containerization and virtualization technologies such as Docker, Kubernetes, or VMware. * Knowledge of Windows and Linux operating systems, networking fundamentals, and common enterprise architecture. * Experience using scripting or automation languages such as Python, Bash, or PowerShell to support testing, analysis, or operational workflows. * Familiarity with offensive security methodologies, vulnerability management processes, and common attacker TTPs. * Ability to analyze technical findings and contribute to assessment reports, presentations, and client deliverables, and communicate findings to both technical and non-technical stakeholders. * Experience assessing cloud-native technologies, including Kubernetes, containers, serverless functions, or Infrastructure-as-Code deployments. * Familiarity with cloud security assessment tools, vulnerability scanners, and offensive security frameworks. * Familiarity with Terraform, Ansible, ARM templates, CloudFormation, or Infrastructure-as-Code concepts. * Experience with logging, monitoring, and detection technologies such as Splunk, Sentinel, ELK, Defender, or CrowdStrike. * Familiarity with RMF, A&A activities, STIGs, SCAP, ACAS, or cybersecurity compliance frameworks. * Ability to rapidly learn emerging technologies, cloud attack methodologies, and evolving threat landscapes. * Relevant certifications such as AWS Security Specialty, Azure Security Engineer Associate, PenTest+, CySA+, CEH, AZ-500, SC-200, CRTO, GPEN, GXPN, OSCP, or similar cybersecurity certifications preferred. ## Description Northrop Grumman Mission Systems (NGMS) is seeking a to join our team of qualified, diverse individuals conducting cybersecurity test activities in . In this role, the assesses and tests system cybersecurity requirements, system security architecture, and system security layout. The candidate will operate in a team environment and collaborate across the organization (as required) to accomplish team goals by coordinating with customers and other testing organizations. * Conduct cloud-focused penetration testing and security assessment activities to identify vulnerabilities, attack paths, and potential threat vectors across cloud-native and hybrid environments. * Support offensive security operations targeting cloud infrastructure, CI/CD pipelines, containerized workloads, applications, and enterprise services within AWS, Azure, and related platforms. * Assists with development of attack methodologies, testing procedures, and technical analysis while collaborating with senior operators and engineers. * Apply cybersecurity knowledge to evaluate cloud security posture, validate security controls, and contribute to technical reporting, operational recommendations, and remediation guidance. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [The 8 Best Code Testing Tools](https://www.wearedevelopers.com/magazine/402-the-8-best-code-testing-tools) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)