> Markdown version of [/jobs/ext/2511801-sentinel-systems-engineer-scrm-vulnerability](https://www.wearedevelopers.com/jobs/ext/2511801-sentinel-systems-engineer-scrm-vulnerability). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sentinel - Systems Engineer (SCRM Vulnerability... - **Company:** Northrop Grumman - **Location:** Roy, UT, United States - **Salary:** $79,300.0 - $118,900.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Systems Engineering, CompTIA Security+, Computer Engineering, System Configuration, Digital Forensics, Kali Linux, Open Source Intelligence, Comptia Pentest+ CE, Reverse Engineering, SAP (Applications), Software Engineering, Hardware Testing, Information Technology, Metasploit, Nessus, Vulnerability Analysis - **Published:** August 5, 2026 - **Apply:** https://www.juju.com/job/00000000gm3x6s ## About the Role + **BS** in one of the following or equivalent disciplines: Software Engineering, Computer Science, Digital Forensics, Computer Engineering, or Electrical Engineering with **2 years** of related experience, or a Master's degree in the above disciplines with 0 years of related experience + Must be a US Citizen with an **active U.S. Government Secret security clearance** at time of application, current and within scope (<6 years), with an ability to obtain and maintain Special Access Program (SAP) approval within a reasonable period, as determined by the company to meet its business need + Minimum 2 years of combined experience in software engineering, software or hardware testing, systems security engineering, or electrical engineering, or 0 years with a Master's degree in the above fields. + Ability to obtain CompTIA Security+ certification within 6 months of starting in the position. + Familiarity of developing, documenting, and executing formal test plans and procedures, with a specific focus on vulnerability/penetration testing and counterfeit part assurance. Preferred Qualifications: + Top Secret Security Clearance + Any of the following certifications: OSCP, GREM, PenTest+ or comparable industry-recognized certifications + Experience utilizing penetration testing and vulnerability assessment tools (Kali Linux / Metasploit / NESSUS / ACAS / OpenVAS / Etc.) + Experience validating software configurations (STIG / OpenSCAP) + Experience with software forensics activities / processes + Experience with SCRM chain of custody processes / procedures + Experience in software or hardware reverse engineering and exploratory reconnaissance + Experience performing with OSINT analysis + Familiarity with MBSE concepts and tools to trace security requirements to test verification + Experience in bridging SW and HW in cross-disciplinary testing. ## Description Northrop Grumman is seeking to hire a **Systems Engineer SCRM Vulnerability Assessment** to support our **Systems Security Engineering (SSE)** team. In this role, you will be responsible for researching, testing, and documenting the cybersecurity posture of commercial off-the-shelf hardware and software products. This position will be located in **Roy, UT** . Responsibilities Include: + Perform vulnerability assessments against COTs hardware / software + Review, Interpret, and Communicate vulnerability assessment results + Participate in a variety of working groups, customer meetings + Contributes to the ongoing enhancement of assessment capabilities through the development and implementation of improved methodology, processes, infrastructure, tools, and deliverables ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)