> Markdown version of [/jobs/ext/1986816-principal-cyber-systems-engineer-lead](https://www.wearedevelopers.com/jobs/ext/1986816-principal-cyber-systems-engineer-lead). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Cyber Systems Engineer Lead - **Company:** Northrop Grumman - **Location:** Chantilly, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Agile Methodology, Antivirus Softwares, Systems Engineering, Cloud Computing, Cloud Computing Security, Code Review, Information Systems, Continuous Integration, Open Web Application Security, Scrum Methodology, Systems Development Life Cycle, Secure Coding, Software Engineering, Software Security, Technical Debt - **Published:** August 8, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/principal-cyber-systems-engineer-lead-chantilly-va-usa-58846943 ## About the Role tools Scrum teams on secure coding, container security, CI/CD security, and security trade studies * Conduct security assessments of mission software, including code reviews and vulnerability testing * Develop and implement security tools and automation (SCA, V/V scanning, auditing, monitoring) * Create RMF artifacts (SSP, RAR, SCTM, POA&Ms) and security policies for application security * Support system accreditation processes to achieve ATO and perform RMF-based assessments * Document SOPs and manage patching, remediation, anti-virus updates, and continuous monitoring * Ensure secure operation, maintenance, and disposal according to security policies Tasks * Active Top Secret security clearance, SCI Eligible, U.S. citizenship * CISSP, CSSLP, CASP, CISM or equivalent certification * Understand NIST 800-37, NIST 800-53, OWASP Top 10; systems engineering and acquisition processes * Experience with Cloud Security and best practices * Knowledge of Software Development Lifecycle, systems aaaa coding, reviews, and accreditation milestones * Technical leadership or mentorship experience * Experience with security tooling, RMF artifacts, and security assessments Key requirements * health insurance * life and disability insurance * savings plan * Company paid holidays * paid time off (PTO) ## Description Experteer Overview In this role you will lead cybersecurity for ground segment cloud infrastructure within an Agile development environment, shaping the security posture of mission-critical information systems. You will collaborate with cross-functional teams to translate security requirements into architectures and oversee implementation and accreditation activities. You'll drive secure development practices, risk management artifacts, and automation to sustain a private cloud. This position offers hands-on impact across design to decommissioning, with a clear path to technical leadership on a major program. Compensation / Benefits * Lead design, development, and implementation of secure systems in an Agile setting, ensuring compliance with program security requirements * Collaborate with ground security teams and space vehicle vendors to ensure integration aligns with accreditation * Triaging and prioritizing software security requirements and technical debt in the SDLC backlog * Advise Scrum teams on secure coding, container security, CI/CD security, and security trade studies * Conduct security assessments of mission software, including code reviews and vulnerability testing * Develop and implement security tools and automation (SCA, V/V scanning, auditing, monitoring) * Create RMF artifacts (SSP, RAR, SCTM, POA&Ms) and security policies for application security * Support system accreditation processes to achieve ATO and perform RMF-based assessments * Document SOPs and manage patching, remediation, anti-virus updates, and continuous monitoring * Ensure secure operation, maintenance, and disposal according to security policies Tasks * Active Top Secret security clearance, SCI Eligible, U.S. citizenship * CISSP, CSSLP, CASP, CISM or equivalent certification * Understand NIST 800-37, NIST 800-53, OWASP Top 10; systems engineering and acquisition processes * Experience with Cloud Security and best practices * Knowledge of Software Development Lifecycle, systems engineering reviews, and accreditation milestones * Technical leadership or mentorship experience * Experience with security tooling, RMF artifacts, and security assessments Key requirements * health insurance * life and disability insurance * savings plan * Company paid holidays * paid time off (PTO) ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Resolving technical debts in software architecture](https://www.wearedevelopers.com/videos/1680-resolving-technical-debts-in-software-architecture) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [The Hidden Cost of AI Coding: Technical Debt You Can’t See](https://www.wearedevelopers.com/videos/100304-the-hidden-cost-of-ai-coding-technical-debt-you-can-t-see) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)