> Markdown version of [/jobs/ext/1977904-principal-sr-principal-cyber-penetration-tester](https://www.wearedevelopers.com/jobs/ext/1977904-principal-sr-principal-cyber-penetration-tester). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal/Sr Principal Cyber Penetration Tester - **Company:** Northrop Grumman - **Location:** San Antonio, TX, United States - **Experience:** Expert - **Salary:** $103,600.0 - $155,400.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Software System Penetration Testing, Cyber Security, Data Transmissions, Network Protocols, Penetration Tools, Red Team (Cyber Security), SAP (Applications), Software Engineering, Software Requirements Analysis, Systems Architecture, Computer Network Operations, Information Technology - **Published:** August 7, 2026 - **Apply:** https://dejobs.org/x/x/9476979F8CD843D580D887825380C3FB/job/ ## About the Role * Bachelor's Degree in Cybersecurity, Computer Science/Engineering, Software Development/Engineering, or related STEM degree field and 5 years of related experience; or a Master's degree and 3 years of related experience. * US Citizenship is required * Active Department of Defense (DoD) Top Secret Security Clearance is required to be considered with the ability to obtain SCI and SAP access * Must possess a DoD 8570 Certification for IAT Level II or higher or acquire it within 6 months of hire. * Experience with penetration testing, * Bachelor's Degree in Cybersecurity, Computer Science/Engineering, Software Development/Engineering, or related STEM degree field and 8 years of related experience; or a Master's degree and 6 years of related experience. * US Citizenship is required * Active Department of Defense (DoD) Top Secret Security Clearance is required to be considered with the ability to obtain SCI and SAP access * Must possess a DoD 8570 Certification for IAT Level II or higher or acquire it within 6 months of hire. * Experience with penetration testing Preferred Qualifications for both: * Contribute to the preparation of technical reports and briefings * Prior experience as an Offensive Cyber Operator (Red Team, CNO, CNE, or OCO) preferred (i.e. graduate of Computer Network Operations Qualification Course (CNOQC), Remote Interactive Operators Training (RIOT) and Future Operator Readiness, Growth & Enrichment Course (FORGE)). * Prior hand-on cyber test experience in a DoD Cyber Developmental Test or Operational Test (DT/OT) organization i.e. (i.e., 96th Cyber Test Group, 346th Test Squadron). * Possess a Cybersecurity certification related to Red Teaming/Penetration Testing: GPEN, GXPN or OSCP. * DoD Acquisition Professional Development Program (APDP) "Test & Evaluation" Certification, Level 1 or higher. ## Description Northrop Grumman Mission Systems (NGMS) is seeking a Principal/Sr. Principal Cyber Penetration Tester to join our team of qualified, diverse individuals conducting cybersecurity test activities in San Antonio, TX . In this role, the Principal/Sr. Principal Cyber Penetration Tester (Cyber Protection) assesses and tests system cybersecurity requirements, system security architecture, and system security layout. The candidate will operate in a team environment and collaborate across the organization (as required) to accomplish team goals by coordinating with customers and other testing organizations. Duties will include but are not limited to planning, executing, and reporting cyber test activities to develop artifacts in support of authorization packages. The Principal/Sr. Principal Cyber Penetration Tester will perform cyber-attack path analysis of system architectures and is responsible for the security governance, risk management, and compliance of a system while it is under test for the customer. Periodic travel to operational or development sites is anticipated to perform & support cyber test activities. Responsibilities include: * Perform cyber testing, verification, and validation * Validate system security requirements definition and analysis, establish system security designs, implement security designs in hardware, software, data, and procedures * Participate in team reviews of technical requirements, designs and implementation plans prior to deployment of systems, digital communications systems, network protocols, computer architectures, and computer security penetration tools and techniques * Provide cyber security implementation guidance to technical design teams and develop test use cases to meet requirements and architecture model content. * Support development of technical decision-making guidance to the Cybersecurity team to ensure timely, high quality product deliveries supporting flight test events geared to meet mission requirements * Ensure weapon system compliance with all contractually obligated cybersecurity standards and guidance, including but not limited to CNSSI 1253, DoD 8140, DoD 8510, and AFI 17-101 * Ensure weapon system assessments are completed to meet all contractually obligated cybersecurity standards and guidance, including but not limited to RMF and cyber survivability requirements * Provide input to program milestones and metrics, adhering to cybersecurity-relevant plans and schedules * Solve complex problems across disciplines in an Agile environment ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [ShapeShift: Reinventing Agile for a B2B SaaS Scale-Up](https://www.wearedevelopers.com/videos/1655-shapeshift-reinventing-agile-for-a-b2b-saas-scale-up) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023)