> Markdown version of [/jobs/ext/2552104-sr-principal-classified-cybersecurity-analyst-secret](https://www.wearedevelopers.com/jobs/ext/2552104-sr-principal-classified-cybersecurity-analyst-secret). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr Principal Classified Cybersecurity Analyst - Secret - **Company:** Northrop Grumman - **Location:** Corinne, UT, United States (Remote available) - **Experience:** Expert - **Salary:** $111,700.0 - $167,500.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Identity and Access Management, Security Content Automation Protocol, Information Security Management System, Nessus, Splunk, Plan of Action and Milestones - **Published:** August 5, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f5ee0ac1d555daa4 ## About the Role * Master's degree with 6 years of relevant technical experience; OR a Bachelor's degree with 8 years of relevant technical experience; OR an Associate's degree with 10 years of relevant technical experience; OR a High School Diploma/GED with 12 years of relevant technical experience is required * Candidates must meet the U.S. Government 8140 requirements (8570 equivalent) for a Sr Principal Classified Cybersecurity Analyst - IAM level III certification at a minimum (examples: CISM, CISSP, GSLC, CCISO) * Candidates must have a current U.S. Government Secret level security clearance (at a minimum), to include a closed investigation date completed within the last 6 years OR must be enrolled in the U.S. Government Continuous Evaluation (CE) Program to be considered * Candidates must have the ability to obtain, and maintain, a Top Secret level clearance * Candidates must have the ability to obtain, and maintain, access to Special Access Programs as a condition of continued employment, * Bachelor's degree in Cybersecurity or related field * CISSP * Experience in cybersecurity compliance (ex. Assessment & Authorization under RMF) * Top Secret preferred * Knowledge of security tools such as ACAS, Nessus, Splunk, Trellix, and SCAP * Knowledge of security frameworks and documentation such as NIST, JSIG, DAAG, SSPs, POA&Ms, and SCTMs ## Description * Manage the cybersecurity program of all assigned information systems and execute all cybersecurity-related tasks. * Conduct and lead regular reviews of system audits and continuous monitoring activities, covering all security controls and configurations, to enhance operational efficiencies of the information system security posture. * Perform assessments of systems and networks within the networking environment or enclave and identify where those systems and networks deviate from acceptable configurations, enclave policy, or local policy. * Perform analyses to validate established security requirements and to recommend additional security requirements and safeguards. * Drive the implementation of the required government policy, make recommendations on process tailoring, participate in and document process activities. * Establish and oversee strict program control processes that mitigate risk and support system Assessment and Authorization (A&A). This includes process support, analysis, coordination, security certification testing, security documentation, investigations, software research, hardware introduction and release, emerging technology research, inspections, and periodic audits. * Lead the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results and preparation of required reports. * Document the results of A&A activities, and inspection activities, along with any technical or corrective actions and work collectively with the security team to submit responses to the appropriate cognizant authority. * Prepare, review, and submit A&A documentation (System Security Plan, Risk Acceptance Report, Security Controls Traceability Matrix, Plan of Action and Milestones, etc.) for review and approval. Note: Due to the classified nature of the work being performed, this position does not offer any virtual or telecommute working options. Applicants are encouraged to apply only if they are willing to work on-site. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)