Sr Principal Cyber Systems Engineer (Networking)

Northrop Grumman
San Antonio, TX, United States
30 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Compensation
$113,900.0 - $213,200.0
Working hours
Shift work
Job source

Tech stack

Agile Methodology Amazon Web Services Antivirus Softwares Systems Engineering Microsoft Azure Control Objectives for Information and Related Technology (COBIT) Cyber Security Computer Networks Dynamic Host Configuration Protocol Linux Domain Name System (DNS) Federal Information Processing Standards (FIPS)
+37 more
Monitoring of Systems Networking Hardware Internet Protocol Internet Protocol Security (IP SEC) Intrusion Detection Systems Virtual Private Networks (VPN) Python (Programming Language) Key Management Network Security Microsoft Software Network Architecture Network Diagrams Network Planning and Design Routing Network Time Protocols Public Key Infrastructure Windows PowerShell Role-Based Access Control Ansible Zero Trust Network Access Security Information and Event Management Systems Integration Virtual Local Area Networks Software Vulnerability Management Data Logging Network Routers Computer Networking Systems Firewalls (Computer Science) Kubernetes Performance Monitor Multiaccess Edge Computing CIS Benchmarks Terraform Devsecops Docker Vulnerability Analysis Microservices

Job description

Join a multi-disciplinary team designing and securing a launch execution network - a complex, multi-enclave launch and missile test environment. As a cyber-strong systems engineer with solid networking skills, you will own the security architecture and RMF/ATO posture for networked systems, shaping controls, documentation, and automation that keep mission systems both secure and available. This role is on-site full-time in San Antonio, TX and requires an active TS and SCI eligibility.

  • Work with customer ISSMs/ISSOs and other stakeholders to develop, document, and implement changes in environments operating under, or seeking, an ATO/IATT in accordance with DoD RMF.
  • Serve as a cyber systems engineer on a multi disciplinary team, collaborating closely with network, systems, software, and test engineers to design and secure complex, multi enclave launch and test networks (classified and unclassified).
  • Review and influence network architectures and detailed designs (routing, switching, VPN/IPsec, segmentation, boundary defenses) from a cybersecurity perspective, ensuring baked in protections and RMF compliant control implementations.
  • Support the design, planning, configuration, and sustainment of enterprise scale network communications and security services, producing and maintaining engineering artifacts such as security and network diagrams, configuration baselines, and implementation plans.
  • Provide cybersecurity systems engineering guidance and oversight to implementation teams, including secure configuration of Microsoft and Linux systems, network devices, and enclave services (e.g., logging/monitoring, KMS/PKI, endpoint protection).
  • Plan and support end to end testing of security and network designs, validate configurations, and monitor performance to ensure reliability, resiliency, and compliance with security policies and RMF control objectives.
  • Support vulnerability management activities (scanning, analysis, remediation planning, and compensating controls) in mission critical environments with constrained maintenance windows.
  • Leverage automation and scripting (e.g., Python, PowerShell, Ansible, Terraform) to implement and enforce secure configurations, generate compliance evidence, and streamline recurring cyber engineering tasks.
  • Perform or oversee physical layer installation tasks (e.g., fiber, patch panels, encryption devices) as needed to support secure infrastructure builds and changes.
  • Produce periodic status reports, risk/issue summaries, and engineering change documentation; clearly communicate technical options, risks, and trade offs to both technical and non technical stakeholders, including customer representatives.

Requirements

  • Bachelor’s degree in a Science in a STEM discipline from an accredited institution and 5 years of related experience in engineering; or a Master’s degree in a STEM discipline and 3 years of related experience; or a Ph.D. in a STEM discipline and 1 year of related experience.
  • US Citizenship is required
  • Active, current DoD Top Secret security clearance and SCI eligibility
  • DoD 8570 IAT Level II certification (e.g., Security+ CE) or equivalent prior to start.
  • Hands-on experience as a cyber/security engineer or cyber systems engineer for complex networked systems (preferably DoD or similar)
  • Experience applying the Risk Management Framework (RMF)
  • Experience developing and/or implementing security controls for Microsoft and Linux systems
  • Working knowledge of IP networking (e.g., routing, switching, VLANs, firewalls) sufficient to read, understand, and critique network designs in collaboration with dedicated network engineers., * Bachelor’s degree in a Science in a STEM discipline from an accredited institution and 8 years of related experience in engineering; or a Master’s degree in a STEM discipline and 6 years of related experience; or a Ph.D. in a STEM discipline and 3 year of related experience.
  • US Citizenship is required
  • Active, current DoD Top Secret security clearance and SCI eligibility
  • DoD 8570 IAT Level II certification (e.g., Security+ CE) or equivalent prior to start.
  • Hands-on experience as a cyber/security engineer or cyber systems engineer for complex networked systems (preferably DoD or similar)
  • Experience applying the Risk Management Framework (RMF)
  • Experience developing and/or implementing security controls for Microsoft and Linux systems
  • Working knowledge of IP networking (e.g., routing, switching, VLANs, firewalls) sufficient to read, understand, and critique network designs in collaboration with dedicated network engineers., * Strong working knowledge of IP networking (e.g., routing, switching, VPN/IPsec, DNS, DHCP, NTP, segmentation) and secure network design principles (defense-in-depth, least privilege), with experience applying host and network hardening standards (e.g., DISA STIGs, CIS benchmarks) across servers, endpoints, and network devices.
  • Experience building baseline security control sets and secure configurations for core infrastructure (e.g., routers/switches, firewalls, IDS/IPS, EDR/antivirus, logging) and integrating these into a SIEM-driven NOC/SOC construct for unified monitoring and incident response.
  • Hands-on experience with vulnerability scanning and remediation in mission-critical or real-time environments with constrained maintenance windows, including implementing compensating controls when direct remediation is not immediately feasible.
  • Strong understanding of Zero Trust concepts, access-control models (RBAC/ABAC), and secure management-plane design for networked mission systems.
  • Experience architecting and implementing enterprise Key Management Systems (KMS) and Public Key Infrastructure (PKI), including HSM integration (FIPS 140-2/3), key hierarchies (root, KEK, DEK), certificate lifecycle management, and repeatable deployment patterns for enclave services (KMS, PKI, logging, monitoring).
  • Familiarity with NIST cryptographic guidance (e.g., SP 800-57, SP 800-38 series) and experience aligning cryptographic implementations to DoD/IC requirements.
  • Demonstrated experience executing the RMF lifecycle (Steps 0-6) for complex systems, including development of SSPs, security assessment/test plans, POA&Ms, and other authorization artifacts, and responding to AO/ISSM/ISSO comments and findings.
  • Experience using automation and infrastructure-as-code (e.g., Python, PowerShell, Ansible, Terraform) to manage network and security configurations, enforce standards, and generate repeatable compliance evidence.
  • Experience securing cloud or edge-computing environments (e.g., AWS, Azure, GovCloud and/or containerized/microservices architectures such as Kubernetes and Docker), including segmentation, control-plane protection, and integration with enterprise monitoring.
  • Experience working in Agile or DevSecOps environments, collaborating with network, systems, and software teams to integrate security into architecture/design and CI/CD pipelines; familiarity with MBSE/digital engineering tools to capture security requirements and behaviors.
  • Strong interpersonal, written, and verbal communication skills, with demonstrated ability to produce clear engineering artifacts (designs, diagrams, ICDs, risk summaries) and to brief leadership, customer representatives, and authorization officials on risk trade-offs, mitigations, and accreditation posture.

We understand that candidates may not possess every preferred skill. If you meet all of the basic qualifications, have a solid background in many of the preferred qualifications, and are enthusiastic about our mission, we encourage you to apply.

Benefits & conditions

4.04.0 out of 5 stars San Antonio, TX $113,900 - $213,200 a year, Pulled from the full job description

  • Health insurance
  • Paid time off
  • Relocation assistance
  • Disability insurance
  • Paid holidays, Primary Level Salary Range: $113,900.00 - $170,900.00

Secondary Level Salary Range: $142,200.00 - $213,200.00

The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate’s experience, education, skills and current market conditions.

Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.

About the company

At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people’s lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation’s history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they’re making history.

Northrop Grumman Mission Systems is a trusted provider of mission-enabling solutions for global security. Our Engineering and Sciences (E&S) organization pushes the boundaries of innovation, redefines engineering capabilities, and drives advances in various sciences. Our team is chartered by providing the skills and innovative technologies to develop, design, produce and sustain optimized product lines across the sector while providing a decisive advantage to the warfighter. Come be a part of our mission!

Northrop Grumman Mission Systems has an opening for a systems engineer in the cyber specialty discipline. We are seeking a highly skilled and motivated Principal Cyber Systems Engineer or Senior Principal Cyber Systems Engineer to join our dynamic engineering team. This role involves serving on a team dedicated to the development of a new solution operating in a multi-level security environment. The position requires expertise in Cyber Systems Engineering along with some networking experience.

The qualified applicant will become part of Northrop Grumman’s Mission Systems support team in San Antonio, TX.

This position may be filled by either at the Principal Cyber Systems Engineer level OR at the Sr. Principal Cyber Systems Engineer level based on the qualifications listed.

Please Note: Due to the classified nature of the work being performed, this position does not offer any virtual or telecommute working options. Applicants are encouraged to apply, only if they are willing to work 100% on-site.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:07 min

Inspecting default bridge architectures and custom Docker networks

Oliver Seitz Oliver Seitz · World Congress 2025

1:42 min

Automating Skupper deployments using Ansible

Alex Soto Alex Soto · World Congress 2024

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all