Principal / Cyber Systems Engineer

Northrop Grumman
Chantilly, VA, United States
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
0 years minimum
Working hours
Regular working hours

Tech stack

Kubernetes Security Agile Methodology Systems Engineering Cloud Computing Cloud Computing Security Code Review Cyber Security Continuous Integration DevOps Open Web Application Security Scrum Methodology Systems Development Life Cycle
+4 more
Secure Coding Software Engineering Technical Debt Vulnerability Analysis

Job description

Experteer Overview As a Cybersecurity professional on the IPT, you help design and secure mission-critical software and ground segment cloud infrastructure. You’ll work in an Agile environment, guiding secure coding, conducting security assessments, and supporting accreditation and sustainment of a private cloud. You’ll collaborate with development and platform teams to implement security controls and RMF documentation, driving a strong security posture for space programs. This role offers impact across engineering, security, and operations. Compensation / Benefits * Lead design, development, and implementation of secure systems in an Agile setting * Ensure compliance with program security requirements across the lifecycle * Triage and prioritize SCA findings and technical debt in the SDLC backlog * Advise scrum teams on secure coding, container security, and CI/CD security practices * Conduct security assessments including code reviews and vulnerability testing * Develop and implement security tools and automation (SCA, DCA, vulnerability scanning, monitoring) * Create RMF artifacts (SSP, RAR, SCTM, POA&Ms) and security policies * Support system accreditation to achieve Authority to Operate (ATO) * Document SOPs and perform patching, remediation, and ConMon activities * Ensure secure operation, maintenance, and disposal per security authorization package Tasks * Active Top Secret clearance, SCI eligible, U.S. citizenship * Understanding of NIST 800-37, NIST 800-53, OWASP Top 10 * Experience with Cloud Security and best practices * Knowledge of SwDLC and system/software accreditation milestones * 2+ years (or 0-3 years depending on degree) relevant defense/space cybersecurity experience for the ISSE/ISSO tracks * Experience with DevOps, software development, and security in CI/CD environments Key requirements * health insurance coverage * life and disability insurance * savings plan * Company paid holidays * paid time off (PTO) * discretionary bonus

Requirements

U.S. security tools and automation (SCA, DCA, vulnerability scanning, monitoring) * Create RMF artifacts (SSP, RAR, SCTM, POA&Ms) and security policies * Support system accreditation to achieve Authority to Operate (ATO) * Document SOPs and perform patching, remediation, and ConMon activities * Ensure secure operation, maintenance, and disposal per security authorization package Tasks * Active Top Secret clearance, SCI eligible, U.S. citizenship * Understanding of NIST 800-37, NIST 800-53, OWASP Top 10 * Experience with Cloud Security and best practices * Knowledge of SwDLC and system/software accreditation milestones * 2+ years (or 0-3 years depending on degree) relevant defense/space cybersecurity experience for the ISSE/ISSO tracks * Experience with DevOps, software development, and security in CI/CD environments Key requirements * health insurance coverage * life and disability insurance * savings plan * Company paid holidays * paid time off (PTO) * discretionary bonus

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on us.experteer.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho · WWC Europe 2026

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · WWC 2021

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

Videos

See all

Related articles

See all