> Markdown version of [/jobs/ext/3040514-sr-principal-cyber-systems-engineer](https://www.wearedevelopers.com/jobs/ext/3040514-sr-principal-cyber-systems-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Principal Cyber Systems Engineer - **Company:** Northrop Grumman - **Location:** San Diego, CA, United States - **Experience:** Expert - **Salary:** $156,400.0 - $234,600.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Systems Engineering, Unix, Configuration Management, Cyber Security, Information Systems, Hypervisor, Identity and Access Management, Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Package Development Process, Systems Development Life Cycle, Red Hat Enterprise Linux, SAP (Applications), Software Engineering, Software Vulnerability Management, Windows Desktop, Containerization, Nessus - **Published:** September 23, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9188417/sr-principal-cyber-systems-engineer ## About the Role Northrop Grumman Aeronautics Systems has an opening for a Sr. Principal Cyber Systems Engineer to join our team of qualified, diverse individuals in Rancho Bernardo, CA. The candidate should be a self-starter with familiarity working in an Integrated Product Team construct., * Bachelor of science degree in a STEM (Science, Technology, Engineering, Math) discipline and 8 years of related engineering experience; OR a Master of science degree in a STEM discipline and 6 years of engineering experience, or a PhD in a STEM discipline and 4 years of related experience. * Must have one of the following certifications: DoD 8140 Cyber Workforce qualification, DoD 8570 IAM Level II, CompTIA SecurityX / CASP, CISSP, or CSSLP. * Experience preparing and defending accreditation packages as an ISSE or ISSM. * Experience working with DoD RMF and JSIG for SAP/SCI systems. * Experience validating security posture, reporting findings, and supporting risk-acceptance recommendations. * Experience engaging with stakeholders at multiple levels. * Must have an active US Government Top Secret clearance (with a background investigation completed within the last 6 years or currently enrolled into Continuous Evaluation). * Must have the ability to obtain and maintain Special Access Program (SAP) clearance within a reasonable amount of time as determined Preferred Qualifications: * Current SAP access. * Advanced cybersecurity certifications (e.g., CISSP-ISSEP, CISSP-ISSAP, CSSLP). * Experience with vulnerability management, cybersecurity assessment and scanning, compliance/authorization packages, and ATO documentation. * Experience with NIST publications, federal regulations, DoD RMF controls, and cybersecurity authorization requirements. * Experience with IT principles and practices, including software design, test, and integration. * Familiarity with Windows and UNIX/Linux platforms (e.g., Red Hat), hypervisor, and containerized environments. * Experience designing/reviewing hardening using DISA STIGs/SRGs. * Experience developing and evaluating information systems across the systems development lifecycle in a secure environment. * Experience working in an Integrated Product Team with engineering, cybersecurity, software, integration/test, configuration management, security, customer, and program stakeholders. ## Description * Lead and support Development and Sustainment cybersecurity execution by identifying risks and driving technical and programmatic remediation across engineering, cybersecurity, program, and customer stakeholders. * Design, develop, integrate, test, verify, and validate system security solutions. * Prepare, review, and defend accreditation packages as an Information Systems Security Engineer (ISSE) or Information Systems Security Manager (ISSM). * Apply working knowledge of DoD RMF and JSIG requirements for SAP/SCI systems. * Validate information system security posture, interpret and report findings, and support risk-acceptance recommendations related to security controls implementation. * Translate RMF controls into system- and design-level requirements, including decomposition, verification planning, and traceability. * Support vulnerability management, cybersecurity scanning and assessment, compliance package development, and requirements verification using approved tools (e.g., ACAS, Nessus). * Support host and network hardening using DISA STIGs and SRGs for Windows, UNIX/Linux, hypervisor, and containerized environments. * Coordinate with systems engineering, software, integration/test, configuration management, security, and program teams to support cybersecurity execution across the system lifecycle. * Prepare and present cybersecurity and systems engineering materials for reviews, working groups, and stakeholder discussions. * Apply systems thinking to assess cybersecurity impacts across architecture, operational constraints, program execution, and mission needs. * Drive process improvements that strengthen cybersecurity planning, traceability, risk management, and closure discipline. * Provide technical leadership, mentoring, and coordination across multiple stakeholders and disciplines. * Strong organizational and communication skills This role requires full-time onsite work at the Rancho Bernardo, CA facility. There is no remote, hybrid, or telework availability for this position. Travel up to 25% may be required in support of program needs. ## Related Videos - [WeAreDevelopers LIVE - Node and Package Security](https://www.wearedevelopers.com/videos/2138-wearedevelopers-live-node-and-package-security) - [An alternative approach to digital sovereignty: Confidential Computing](https://www.wearedevelopers.com/videos/100043-an-alternative-approach-to-digital-sovereignty-confidential-computing) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [The Time Paradox: Building Timezone-Safe Python/Django Applications](https://www.wearedevelopers.com/videos/1915-the-time-paradox-building-timezone-safe-python-django-applications) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [20 Years of Solving Unsolvable Problems](https://www.wearedevelopers.com/videos/100214-20-years-of-solving-unsolvable-problems) ## Related Articles - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [System change: restart as developer?](https://www.wearedevelopers.com/magazine/39-system-change-restart-as-developer)