Principal Cyber Systems Engineer
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.Northrop Grumman Enterprise Services is seeking a Principal level Cyber Security Engineer to join the Information Security team supporting its mission of defending and protecting the company's networks, systems, data, intellectual property, and personal information wherever it resides. Experience with security engineering is key for this role.As a member of the Defense Systems (DS) Cybersecurity Team, this role will directly support in the securing of our entire DS enterprise by providing consultation regarding the secure building of networks, close collaboration with sector business units, staff the teams, and the development of processes that will keep us defining what's possible.We want to empower you to bring your best, with resources, support, and talented team members that will launch your career.Responsibilities include, but are not limited to:
- Develop solutions that balance business requirements with information and cyber security requirements
- Develop solutions that shape the organization's security policies and standards for use in cloud environments
- Align standards, frameworks and security with overall business and technology strategy
- Identify security design gaps in existing and proposed architectures and recommend changes or enhancements
- Identify and communicate current and emerging security threats
- Identify risks and provide guidance regarding remediation of gaps to facilitate a hardened and sustainable solutions
- Take ownership of solutions, assignments, actions items and issues, and remain accountable for their completion
- Work effectively with other team members, customers and key stakeholders and foster team success
- Communicate and collaborate with leadership and technical teams to include systems and network administrators, security engineers, and IT Support teams
- Security and risk assessments for services, applications, hardware and systems
- Interface with Enterprise Information Security Officer on a regular basis to provide security recommendations for approval
- Master's Degree with 3 years of IT experience; OR a Bachelor's Degree with 5 years of IT experience; OR an Associates degree with 7 years of IT experience; OR a High School Diploma with 9 years of IT experience is required
- Must have a minimum of 3 years of experience with Cyber Security Engineering
- Must have experience with the following Security Frameworks: NIST 800-53 and NIST 800-171
- Candidates must have the ability to obtain a DOD Secret level security clearance as a condition of continued employment
- STEM degree and/or Business degree preferred
- Professional/technical certifications: CISSP, CISM, CCSP, Security Plus, AWS, Azure Certified
- DoD 8570 IAT/IAM Level II or III certification
- Senior-level cyber security engineering and architecture experience
- Experience with interpreting and implementing security compliance standards and guidance including Governance, Risk & Compliance (GRC) policies and procedures, NIST 800-53 security control framework
- Experience in areas such as system security, network, and application security
- Knowledge of current and emerging cyber security threats, vulnerabilities, and controls
- Contributor for architectural/industry changes in the area of cyber security
- Experience with Linux and Windows operating systems
- Experience with operating in an Agile/DevOps environment
- Experience with Scripting
- Advanced knowledge in cyber security principles, networking, architecture, servers, systems design, virtual hosts, configuration management, Identity and Access Management, encryption, intrusion detection systems (IDS) and intrusion prevention systems (IPS)
- Directory Services and Centralized Authentication, such as Active Directory or Red Hat
- Identity Manager Vulnerability scanning and management of databases, operating systems, and/or web applications
- IDS/IPS and anti-malware tools/technologies
- Experience with Agile, Scrum and Application Lifecycle Management (ALM)
- Experience operating in an Agile/DevOps environment
- Exceptional verbal and written communications.
- Quickly learn and adapt to new and changing business/technical concepts, requirements, skills, tools
- Goal-oriented team player committed to quality and detail
- Proven track record of driving decisions collaboratively, resolving conflicts and ensuring follow-through
- Innovative and strategic thinker who is positive, proactive and readily embraces change
- Demonstrated ability to explain technical details to a non-technical audience