> Markdown version of [/jobs/ext/1768798-cyber-protection-principal-sr-principal](https://www.wearedevelopers.com/jobs/ext/1768798-cyber-protection-principal-sr-principal). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Protection Principal/Sr. Principal... - **Company:** Northrop Grumman - **Location:** Rome, NY, United States - **Experience:** Expert - **Salary:** $98,400.0 - $155,400.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Cloud Computing, Cloud Engineering, Code Review, Cyber Security, Continuous Integration, Github, Identity and Access Management, Python (Programming Language), OAuth, Windows PowerShell, Comptia Pentest+ CE, Red Team (Cyber Security), Software Engineering, Scripting, Mitre Att&ck, Gitlab, Kubernetes, Atlassian Tools, Jenkins - **Published:** July 12, 2026 - **Apply:** https://www.juju.com/job/00000000gfvsue ## About the Role + **Level 3:** Bachelor's degree in Science with 5+ years of software development experience; Master's with 3+ years of relative experience; or an additional 4 years of experience may be considered in lieu of degree. + **Level 4:** Bachelor's degree in Science with 8+ years of software development experience; Master's with 6+ years of relative experience; or an additional 4 years of experience may be considered in lieu of degree. + This position requires an active Top Secret/SCI clearance and the ability to obtain an IAT Level II or III certification (Security+, Pentest+, SecurityX,) within 60 days of start. + Deep knowledge of cloud attack paths - IAM privilege escalation, metadata service abuse, misconfigured storage, cross-account trust exploitation, and OAuth/token abuse - is required. + Proficiency with cloud-native offensive tooling including Pacu (AWS exploitation framework) and AADInternals (Azure/M365 offensive toolkit), alongside enumeration platforms such as ScoutSuite, CloudFox, Prowler, and ROADtools. Preferred Qualifications: + Prior DoD or IC classified environment experience and familiarity with adversary simulation platforms such as Cobalt Strike, Sliver, or Havoc are a strong plus. + Hands-on practitioner who has operated tools at depth across real engagements, documented findings under active assessment constraints, and can communicate risk clearly to both technical teams and senior leadership. + Experience developing and executing cyber tabletop exercises including threat scenario design, threat actor emulation planning, and after-action reporting is highly valued. + Hands-on experience with Docker and Kubernetes security assessments, including container escape techniques, privileged container abuse, K8s RBAC misconfigurations, service account taken abuse, and CI/CD pipeline security across GitLab, GitHub Actions, and Jenkins environments. + Strong scripting skills in Bash, Python, and PowerShell are expected, and a working knowledge of MITRE ATT&CK as applied to cloud and hybrid environments + Preferred certifications include OSCP, CPTS, PNPT, GPEN, GXPN, GCPN, AWS Security Specialty, or AZ-500. + Day-to-day work Jira and Confluence for sprint and documentation workflows, and GitHub for version controlled tooling and collaborative code review. ## Description Northrop Grumman Defense Systems (NGDS) is seeking a Cyber Protection Principal Engineer to maintain and enhance capabilities in support of DAF CLOUDworks at the Air Force Research Lab (AFRL) in Rome, NY, Warner Robins, GA, or Wright Patterson Air Force Base, OH. DAF CLOUDworks is a rapidly growing secure cloud program that encompasses 10+ teams. These teams span all different areas of cloud engineering including information security, infrastructure development, and cloud migration. You will be an active part of one of these teams providing technical support of customers leveraging DAF CLOUDworks. Along with operations and sustainment, DAF CLOUDworks focuses on modifying and enhancing offerings to implement new requirements, enhance functionality, increase efficiency, or lower operating/deployment. This role is focused on cloud penetration testing, adversarial emulation, red team operations, and container security assessments within a cleared DoD environment. The ideal candidate has a strong offensive security background and deep expertise in AWS and Azure environments. This position is contingent on customer funding and approval and may be filled at a level 3 or level 4. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)