> Markdown version of [/jobs/ext/254472-information-technology-security-analyst-hybrid](https://www.wearedevelopers.com/jobs/ext/254472-information-technology-security-analyst-hybrid). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Technology Security Analyst- Hybrid - **Company:** Northrop Grumman - **Location:** Gardena, CA, United States - **Experience:** Expert - **Salary:** $88,992.0 - $125,000.0 - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Cyber Security, Phishing, Security Information and Event Management, Software Vulnerability Management, IT General Controls (ITGC), Web Filtering, Information Technology, CIS Benchmarks - **Published:** May 31, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=2751aa130e565fa4 ## About the Role Do you have experience in Vuls?, Do you have a Bachelor's degree?, Are you passionate about cybersecurity, risk management, and building stronger security programs in highly regulated environments? We're looking for an experienced Information Technology Security Analyst to help strengthen and evolve our Information Security Governance Program while protecting critical systems, sensitive data, and organizational operations. In this role, you'll work at the center of cybersecurity governance, compliance, risk management, and security operations-partnering with IT teams, leadership, auditors, and external security partners to continuously improve our security posture and cyber maturity. If you thrive in a collaborative environment, enjoy solving complex security challenges, and want to make a meaningful impact, we'd love to hear from you., * Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, or related field (or equivalent experience) * 5+ years of experience in cybersecurity, information security, GRC, or technology risk * Experience working in financial services or other regulated environments preferred Technical Knowledge & Skills * Strong understanding of: + NIST CSF + NIST 800-53 + CIS Controls + ISO 27001 * Experience implementing and auditing CIS Critical Controls and security benchmarks * Familiarity with NCUA, FFIEC, and GLBA requirements * Experience with: + Vulnerability management + Penetration testing remediation + Third-party/vendor risk assessments + SOC report reviews + SIEM and security monitoring tools + Endpoint protection and DLP technologies Professional Skills * Excellent analytical and problem-solving abilities * Strong written and verbal communication skills * Ability to translate technical concepts for non-technical audiences * Experience presenting security metrics and risk updates to senior leadership and boards * Strong organizational skills with the ability to manage multiple priorities effectively * Commitment to continuous improvement and operational excellence ## Description Security Governance & Compliance * Support and enhance the organization's Information Security Governance Program * Develop, maintain, and review security policies, standards, and procedures * Ensure alignment with industry frameworks including NIST CSF, NIST 800-53, CIS Controls, and ISO 27001 * Assist with regulatory compliance efforts related to NCUA, FFIEC, GLBA, and related standards * Prepare and present cybersecurity reports, metrics, and risk updates to leadership and board committees Risk Management & Assessments * Conduct security risk assessments across infrastructure, applications, cloud platforms, and third-party vendors * Review SOC reports, penetration test results, certifications, and vendor security documentation * Lead Business Impact Assessments and support Business Continuity and Disaster Recovery initiatives * Support enterprise risk management and vendor risk management activities Vulnerability & Security Operations * Manage the full vulnerability lifecycle: identification, prioritization, remediation, and reporting * Monitor daily security alerts and incidents across SIEM, endpoint protection, DLP, email security, and web filtering platforms * Investigate incidents, perform root cause analysis, and coordinate remediation efforts * Monitor for phishing sites, malicious domains, and emerging cyber threats Audits, Controls & Continuous Improvement * Support internal and external audits, penetration tests, and ITGC reviews * Audit system configurations against CIS benchmarks and security standards * Track remediation activities and perform control testing * Contribute to cyber maturity assessments and continuous improvement initiatives such as ACET and CAT Collaboration & Awareness * Partner with internal teams, MSSPs, auditors, and business units to strengthen security practices * Deliver cybersecurity awareness guidance on phishing, social engineering, and data protection * Stay current on emerging threats, technologies, and regulatory developments, * Influence and strengthen enterprise cybersecurity strategy * Work with leadership on meaningful security initiatives * Contribute to regulatory readiness and organizational resilience * Grow your expertise in governance, risk, compliance, and security operations * Be part of a collaborative team focused on continuous improvement and innovation ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Lies, Damned Lies and Large Language Models](https://www.wearedevelopers.com/videos/1231-lies-damned-lies-and-large-language-models) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)