> Markdown version of [/jobs/ext/2000027-principal-cyber-systems-engineer](https://www.wearedevelopers.com/jobs/ext/2000027-principal-cyber-systems-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal / Cyber Systems Engineer - **Company:** Northrop Grumman - **Location:** Chantilly, VA, United States - **Experience:** Starter - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Agile Methodology, Systems Engineering, Cloud Computing, Cloud Computing Security, Code Review, Cyber Security, Continuous Integration, DevOps, Open Web Application Security, Scrum Methodology, Systems Development Life Cycle, Secure Coding, Software Engineering, Technical Debt, Vulnerability Analysis - **Published:** August 9, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/principal-cyber-systems-engineer-chantilly-va-usa-58871193 ## About the Role U.S. security tools and automation (SCA, DCA, vulnerability scanning, monitoring) * Create RMF artifacts (SSP, RAR, SCTM, POA&Ms) and security policies * Support system accreditation to achieve Authority to Operate (ATO) * Document SOPs and perform patching, remediation, and ConMon activities * Ensure secure operation, maintenance, and disposal per security authorization package Tasks * Active Top Secret clearance, SCI eligible, U.S. citizenship * Understanding of NIST 800-37, NIST 800-53, OWASP Top 10 * Experience with Cloud Security and best practices * Knowledge of SwDLC and system/software accreditation milestones * 2+ years (or 0-3 years depending on degree) relevant defense/space cybersecurity experience for the ISSE/ISSO tracks * Experience with DevOps, software development, and security in CI/CD environments Key requirements * health insurance coverage * life and disability insurance * savings plan * Company paid holidays * paid time off (PTO) * discretionary bonus ## Description Experteer Overview As a Cybersecurity professional on the IPT, you help design and secure mission-critical software and ground segment cloud infrastructure. You'll work in an Agile environment, guiding secure coding, conducting security assessments, and supporting accreditation and sustainment of a private cloud. You'll collaborate with development and platform teams to implement security controls and RMF documentation, driving a strong security posture for space programs. This role offers impact across engineering, security, and operations. Compensation / Benefits * Lead design, development, and implementation of secure systems in an Agile setting * Ensure compliance with program security requirements across the lifecycle * Triage and prioritize SCA findings and technical debt in the SDLC backlog * Advise scrum teams on secure coding, container security, and CI/CD security practices * Conduct security assessments including code reviews and vulnerability testing * Develop and implement security tools and automation (SCA, DCA, vulnerability scanning, monitoring) * Create RMF artifacts (SSP, RAR, SCTM, POA&Ms) and security policies * Support system accreditation to achieve Authority to Operate (ATO) * Document SOPs and perform patching, remediation, and ConMon activities * Ensure secure operation, maintenance, and disposal per security authorization package Tasks * Active Top Secret clearance, SCI eligible, U.S. citizenship * Understanding of NIST 800-37, NIST 800-53, OWASP Top 10 * Experience with Cloud Security and best practices * Knowledge of SwDLC and system/software accreditation milestones * 2+ years (or 0-3 years depending on degree) relevant defense/space cybersecurity experience for the ISSE/ISSO tracks * Experience with DevOps, software development, and security in CI/CD environments Key requirements * health insurance coverage * life and disability insurance * savings plan * Company paid holidays * paid time off (PTO) * discretionary bonus ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Build a CI/CD pipeline to automate code reviews and ensure code quality](https://www.wearedevelopers.com/videos/349-build-a-ci-cd-pipeline-to-automate-code-reviews-and-ensure-code-quality) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)