> Markdown version of [/jobs/ext/2527713-sr-principal-cyber-systems-engineer-networking](https://www.wearedevelopers.com/jobs/ext/2527713-sr-principal-cyber-systems-engineer-networking). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr Principal Cyber Systems Engineer (Networking) - **Company:** Northrop Grumman - **Location:** San Antonio, TX, United States (Remote available) - **Experience:** Expert - **Salary:** $113,900.0 - $213,200.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Amazon Web Services, Antivirus Softwares, Systems Engineering, Microsoft Azure, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Computer Networks, Dynamic Host Configuration Protocol, Linux, Domain Name System (DNS), Federal Information Processing Standards (FIPS), Monitoring of Systems, Networking Hardware, Internet Protocol, Internet Protocol Security (IP SEC), Intrusion Detection Systems, Virtual Private Networks (VPN), Python (Programming Language), Key Management, Network Security, Microsoft Software, Network Architecture, Network Diagrams, Network Planning and Design, Routing, Network Time Protocols, Public Key Infrastructure, Windows PowerShell, Role-Based Access Control, Ansible, Zero Trust Network Access, Security Information and Event Management, Systems Integration, Virtual Local Area Networks, Software Vulnerability Management, Data Logging, Network Routers, Computer Networking Systems, Firewalls (Computer Science), Kubernetes, Performance Monitor, Multiaccess Edge Computing, CIS Benchmarks, Terraform, Devsecops, Docker, Vulnerability Analysis, Microservices - **Published:** August 7, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=7555282af93a3261 ## About the Role * Bachelor's degree in a Science in a STEM discipline from an accredited institution and 5 years of related experience in engineering; or a Master's degree in a STEM discipline and 3 years of related experience; or a Ph.D. in a STEM discipline and 1 year of related experience. * US Citizenship is required * Active, current DoD Top Secret security clearance and SCI eligibility * DoD 8570 IAT Level II certification (e.g., Security+ CE) or equivalent prior to start. * Hands-on experience as a cyber/security engineer or cyber systems engineer for complex networked systems (preferably DoD or similar) * Experience applying the Risk Management Framework (RMF) * Experience developing and/or implementing security controls for Microsoft and Linux systems * Working knowledge of IP networking (e.g., routing, switching, VLANs, firewalls) sufficient to read, understand, and critique network designs in collaboration with dedicated network engineers., * Bachelor's degree in a Science in a STEM discipline from an accredited institution and 8 years of related experience in engineering; or a Master's degree in a STEM discipline and 6 years of related experience; or a Ph.D. in a STEM discipline and 3 year of related experience. * US Citizenship is required * Active, current DoD Top Secret security clearance and SCI eligibility * DoD 8570 IAT Level II certification (e.g., Security+ CE) or equivalent prior to start. * Hands-on experience as a cyber/security engineer or cyber systems engineer for complex networked systems (preferably DoD or similar) * Experience applying the Risk Management Framework (RMF) * Experience developing and/or implementing security controls for Microsoft and Linux systems * Working knowledge of IP networking (e.g., routing, switching, VLANs, firewalls) sufficient to read, understand, and critique network designs in collaboration with dedicated network engineers., * Strong working knowledge of IP networking (e.g., routing, switching, VPN/IPsec, DNS, DHCP, NTP, segmentation) and secure network design principles (defense-in-depth, least privilege), with experience applying host and network hardening standards (e.g., DISA STIGs, CIS benchmarks) across servers, endpoints, and network devices. * Experience building baseline security control sets and secure configurations for core infrastructure (e.g., routers/switches, firewalls, IDS/IPS, EDR/antivirus, logging) and integrating these into a SIEM-driven NOC/SOC construct for unified monitoring and incident response. * Hands-on experience with vulnerability scanning and remediation in mission-critical or real-time environments with constrained maintenance windows, including implementing compensating controls when direct remediation is not immediately feasible. * Strong understanding of Zero Trust concepts, access-control models (RBAC/ABAC), and secure management-plane design for networked mission systems. * Experience architecting and implementing enterprise Key Management Systems (KMS) and Public Key Infrastructure (PKI), including HSM integration (FIPS 140-2/3), key hierarchies (root, KEK, DEK), certificate lifecycle management, and repeatable deployment patterns for enclave services (KMS, PKI, logging, monitoring). * Familiarity with NIST cryptographic guidance (e.g., SP 800-57, SP 800-38 series) and experience aligning cryptographic implementations to DoD/IC requirements. * Demonstrated experience executing the RMF lifecycle (Steps 0-6) for complex systems, including development of SSPs, security assessment/test plans, POA&Ms, and other authorization artifacts, and responding to AO/ISSM/ISSO comments and findings. * Experience using automation and infrastructure-as-code (e.g., Python, PowerShell, Ansible, Terraform) to manage network and security configurations, enforce standards, and generate repeatable compliance evidence. * Experience securing cloud or edge-computing environments (e.g., AWS, Azure, GovCloud and/or containerized/microservices architectures such as Kubernetes and Docker), including segmentation, control-plane protection, and integration with enterprise monitoring. * Experience working in Agile or DevSecOps environments, collaborating with network, systems, and software teams to integrate security into architecture/design and CI/CD pipelines; familiarity with MBSE/digital engineering tools to capture security requirements and behaviors. * Strong interpersonal, written, and verbal communication skills, with demonstrated ability to produce clear engineering artifacts (designs, diagrams, ICDs, risk summaries) and to brief leadership, customer representatives, and authorization officials on risk trade-offs, mitigations, and accreditation posture. We understand that candidates may not possess every preferred skill. If you meet all of the basic qualifications, have a solid background in many of the preferred qualifications, and are enthusiastic about our mission, we encourage you to apply. ## Description Join a multi-disciplinary team designing and securing a launch execution network - a complex, multi-enclave launch and missile test environment. As a cyber-strong systems engineer with solid networking skills, you will own the security architecture and RMF/ATO posture for networked systems, shaping controls, documentation, and automation that keep mission systems both secure and available. This role is on-site full-time in San Antonio, TX and requires an active TS and SCI eligibility. * Work with customer ISSMs/ISSOs and other stakeholders to develop, document, and implement changes in environments operating under, or seeking, an ATO/IATT in accordance with DoD RMF. * Serve as a cyber systems engineer on a multi disciplinary team, collaborating closely with network, systems, software, and test engineers to design and secure complex, multi enclave launch and test networks (classified and unclassified). * Review and influence network architectures and detailed designs (routing, switching, VPN/IPsec, segmentation, boundary defenses) from a cybersecurity perspective, ensuring baked in protections and RMF compliant control implementations. * Support the design, planning, configuration, and sustainment of enterprise scale network communications and security services, producing and maintaining engineering artifacts such as security and network diagrams, configuration baselines, and implementation plans. * Provide cybersecurity systems engineering guidance and oversight to implementation teams, including secure configuration of Microsoft and Linux systems, network devices, and enclave services (e.g., logging/monitoring, KMS/PKI, endpoint protection). * Plan and support end to end testing of security and network designs, validate configurations, and monitor performance to ensure reliability, resiliency, and compliance with security policies and RMF control objectives. * Support vulnerability management activities (scanning, analysis, remediation planning, and compensating controls) in mission critical environments with constrained maintenance windows. * Leverage automation and scripting (e.g., Python, PowerShell, Ansible, Terraform) to implement and enforce secure configurations, generate compliance evidence, and streamline recurring cyber engineering tasks. * Perform or oversee physical layer installation tasks (e.g., fiber, patch panels, encryption devices) as needed to support secure infrastructure builds and changes. * Produce periodic status reports, risk/issue summaries, and engineering change documentation; clearly communicate technical options, risks, and trade offs to both technical and non technical stakeholders, including customer representatives. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Top Characteristics of a Software Engineer](https://www.wearedevelopers.com/magazine/166-top-characteristics-of-a-software-engineer) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The Ultimate Software Engineer Career Path Guide for 2023](https://www.wearedevelopers.com/magazine/146-the-ultimate-software-engineer-career-path-guide-for-2023) - [Is Software Engineering Hard?](https://www.wearedevelopers.com/magazine/448-is-software-engineering-hard)