> Markdown version of [/jobs/ext/3075379-principal-cyber-systems-engineer-cyber-a-a-engr](https://www.wearedevelopers.com/jobs/ext/3075379-principal-cyber-systems-engineer-cyber-a-a-engr). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Cyber Systems Engineer - Cyber A&A Engr - **Company:** Northrop Grumman - **Location:** Colorado Springs, CO, United States - **Experience:** Expert - **Salary:** $31,200.0 - $49,920.0 - **Contract:** Permanent contract - **Skills:** Xacta, Configuration Management, Cyber Security, Knowledge Management, Machine Learning, Software Vulnerability Management, Information Technology, Wearables, Servicenow, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 25, 2026 - **Apply:** https://www.builtincolorado.com/job/principal-cyber-systems-engineer-cyber-engr-26-324/11365653?handler=ApplyRedirect ## About the Role Please list your current security clearance and IAT or relevant certifications on your resume, if applicable. * A Bachelor's Degree in Computer Science, Cybersecurity Engineering, Information Assurance, Engineering, Mathematics, Physics, or a related field from an accredited university, along with 5 years of experience; or a Master's degree in a related field with 3 years of relevant work experience; or 9 years of relevant work experience may be considered as an alternative to a degree * Applicants must have a current, active Government-Issued 8140 certification at IAT Level II or higher (such as Security+ CE, GSEC, SSCP, CCNA-Security, CySA+, CND, etc.) at the time of application, which is required to start. The candidate is responsible for maintaining their 8140 certifications throughout the entire contract period * Applicants must have a current, active in-scope Government-issued Top Secret security clearance at the time of application, which is required to start Cybersecurity & RMF * Strong cybersecurity engineering background with practical experience applying DoD Risk Management Framework (RMF) and NIST SP 800-53 security controls * Working knowledge of DoDI 8500-series requirements and DoD cybersecurity directives and standards Tools & Technologies * Hands-on experience reviewing and interpreting ACAS and SCC outputs, including vulnerability findings and compliance check results. * Demonstrated experience with STIGs, vulnerability scanning tools, and security configuration baselines * Experience using eMASS (and/or Xacta) to develop, maintain, and track RMF authorization packages * Experience supporting or participating in the accreditation of Cross Domain Solutions (CDS) Communication & Documentation * Excellent technical writing skills for preparing security plans, POA&Ms, risk assessments, and supporting documentation * Strong verbal communication skills with the ability to clearly articulate complex technical concepts to both technical and non-technical audiences Preferred Qualifications: * Experience managing and responding to Cyber Tasking Orders (CTOs) and Information Assurance Vulnerability Management (IAVM) directives across enterprise environments * Demonstrated experience leading or coordinating POA&M management, including tracking remediation status and verifying closure of vulnerabilities * Experience working with third-party assessors and auditors, including coordinating evidence collection, interviews, and follow-up actions * Experience performing self-assessments against STIGs and RMF controls, and developing corrective action plans * Hands-on experience with account management and auditing for user, admin, and service accounts in complex, multi-domain environments * Knowledge of and experience with patch and configuration management processes for large, distributed, and mission-critical enterprise systems * Familiarity with missile defense, command and control (C2), or space/defense systems environments ## Description Northrop Grumman Space Systems - Launch and Missile Defense Systems seeks a highly motivated Cyber Assessment & Authorization (A&A) Engineer to join the C2BMC (Command and Control, Battle Management, and Communications) program in Colorado Springs, CO. C2BMC integrates the Missile Defense System and is a vital operational capability that enables senior decision-makers and combatant commanders to plan ballistic missile defense operations, maintain shared situational awareness, and dynamically manage sensors and weapon systems to achieve global and regional mission objectives. This role directly supports continuous system authorization by ensuring the cybersecurity posture of complex, distributed mission systems. The Cyber A&A Engineer will apply deep cybersecurity engineering expertise and hands-on experience with RMF, ACAS/SCC/ConfigOS, and eMASS/Xacta to drive risk-informed decisions, maintain strong cyber hygiene, and support mission-critical accreditation activities. Essential Functions: * Perform Assessment & Authorization (A&A) activities in support of continuous system Authorization for C2BMC and associated mission systems * Analyze ACAS, SCC, and ConfigOS scan results to identify vulnerabilities, misconfigurations, and control gaps across complex enterprise environments * Review, interpret, and validate STIGs, RMF controls (NIST SP 800-53), and DoD cybersecurity requirements; provide clear technical guidance to engineering and operations teams * Develop and maintain Plan of Action & Milestones (POA&Ms), including engineering responses, remediation plans, and residual risk documentation * Conduct risk analysis for Risk Acceptance Requests (RARs) and provide recommendations to leadership based on mission impact and risk posture * Utilize eMASS/Xacta to create, maintain, and update system authorization packages, ensuring accuracy, completeness, and compliance with DoD RMF processes * Support the accreditation of Cross Domain Solutions (CDS), including documentation, control implementation evidence, and coordination with security stakeholders * Collaborate closely with C2BMC internal teams and external stakeholders (including 3rd party assessors and auditors) to plan, execute, and document cybersecurity assessments * Assist with the management and auditing of user and privileged accounts, ensuring adherence to least-privilege and separation-of-duties principles * Contribute to patch and configuration management activities by analyzing scan results, validating remediation actions, and verifying system compliance * Prepare and present clear, concise technical documentation and briefings for program management, cybersecurity leadership, and customer representatives, Leads and grows the US data science capability while remaining hands-on with coding, machine learning model development, deployment, and MLOps. Mentors data scientists and machine learning engineers, establishes workflows and standards, translates business problems into scalable solutions, and partners with product, data, and UK-based teams. The role emphasizes rapid delivery, production-grade systems, stakeholder communication, and Google Cloud-based model automation, monitoring, and deployment. Top Skills: Ci/CdDockerGoogle BigqueryGoogle Cloud PlatformKafkaKubernetesMlopsNumpyPandasPythonScikit-LearnSQLVertex AiVertex Ai EndpointsVertex Ai PipelinesVertex Ai WorkbenchXgboost Tapestry - Coach and Kate Spade Sales Associate III An Hour Ago Hybrid Park Meadows, Lone Tree, CO, USA 15-24 Hourly Junior 15-24 Hourly Junior eCommerce * Fashion * Retail * Sales * Wearables * Design Represents Coach on the sales floor by delivering personalized luxury-retail service, building client relationships, meeting sales goals, and using omnichannel selling tools. Responsibilities include styling customers, cross-selling, clienteling, processing transactions, handling inventory, replenishing merchandise, supporting visual merchandising, maintaining stockroom organization, and collaborating with teammates. The role requires flexible scheduling, physical retail work, strong communication, and the ability to use POS and mobile technology. Top Skills: Clienteling ToolsIpadLaptopMobile PosPosShort-Form VideoSocial Selling Platforms PNC Bank ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Android beyond mobile: Cars, TVs, and Wearables](https://www.wearedevelopers.com/videos/553-android-beyond-mobile-cars-tvs-and-wearables) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Reality and Beyond: Coding a Drone Using {Unity 3D .NET} and ChatGPT AI!](https://www.wearedevelopers.com/videos/702-reality-and-beyond-coding-a-drone-using-unity-3d-net-and-chatgpt-ai) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)