Principal Cyber Systems Engineer Lead

Northrop Grumman
Chantilly, VA, United States
3 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Kubernetes Security Agile Methodology Antivirus Softwares Systems Engineering Cloud Computing Cloud Computing Security Code Review Information Systems Continuous Integration Open Web Application Security Scrum Methodology Systems Development Life Cycle
+4 more
Secure Coding Software Engineering Software Security Technical Debt

Job description

Experteer Overview In this role you will lead cybersecurity for ground segment cloud infrastructure within an Agile development environment, shaping the security posture of mission-critical information systems. You will collaborate with cross-functional teams to translate security requirements into architectures and oversee implementation and accreditation activities. You’ll drive secure development practices, risk management artifacts, and automation to sustain a private cloud. This position offers hands-on impact across design to decommissioning, with a clear path to technical leadership on a major program. Compensation / Benefits * Lead design, development, and implementation of secure systems in an Agile setting, ensuring compliance with program security requirements * Collaborate with ground security teams and space vehicle vendors to ensure integration aligns with accreditation * Triaging and prioritizing software security requirements and technical debt in the SDLC backlog * Advise Scrum teams on secure coding, container security, CI/CD security, and security trade studies * Conduct security assessments of mission software, including code reviews and vulnerability testing * Develop and implement security tools and automation (SCA, V/V scanning, auditing, monitoring) * Create RMF artifacts (SSP, RAR, SCTM, POA&Ms) and security policies for application security * Support system accreditation processes to achieve ATO and perform RMF-based assessments * Document SOPs and manage patching, remediation, anti-virus updates, and continuous monitoring * Ensure secure operation, maintenance, and disposal according to security policies Tasks * Active Top Secret security clearance, SCI Eligible, U.S. citizenship * CISSP, CSSLP, CASP, CISM or equivalent certification * Understand NIST 800-37, NIST 800-53, OWASP Top 10; systems engineering and acquisition processes * Experience with Cloud Security and best practices * Knowledge of Software Development Lifecycle, systems engineering reviews, and accreditation milestones * Technical leadership or mentorship experience * Experience with security tooling, RMF artifacts, and security assessments Key requirements * health insurance * life and disability insurance * savings plan * Company paid holidays * paid time off (PTO)

Requirements

tools Scrum teams on secure coding, container security, CI/CD security, and security trade studies * Conduct security assessments of mission software, including code reviews and vulnerability testing * Develop and implement security tools and automation (SCA, V/V scanning, auditing, monitoring) * Create RMF artifacts (SSP, RAR, SCTM, POA&Ms) and security policies for application security * Support system accreditation processes to achieve ATO and perform RMF-based assessments * Document SOPs and manage patching, remediation, anti-virus updates, and continuous monitoring * Ensure secure operation, maintenance, and disposal according to security policies Tasks * Active Top Secret security clearance, SCI Eligible, U.S. citizenship * CISSP, CSSLP, CASP, CISM or equivalent certification * Understand NIST 800-37, NIST 800-53, OWASP Top 10; systems engineering and acquisition processes * Experience with Cloud Security and best practices * Knowledge of Software Development Lifecycle, systems aaaa coding, reviews, and accreditation milestones * Technical leadership or mentorship experience * Experience with security tooling, RMF artifacts, and security assessments Key requirements * health insurance * life and disability insurance * savings plan * Company paid holidays * paid time off (PTO)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · WWC Europe 2026

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

3:06 min

The lack of responsibility over technical debt

Stefan Priebsch · WWC 2021

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · WWC 2021

56 sec

The hidden costs of delayed peer code reviews

Tim Gilboy Tim Gilboy

Videos

See all

Related articles

See all