clearance transfer. Due to the nature of this work, this position will be on site only.
Responsibilities: Work as part of an integrated product team (IPT) to architect, implement, and satisfy Risk Management Framework (RMF) CyberSecurity, CyberResilience, and/or CyberSurvivability
requirements:of satellite systems, communications links, and ground command & control (C2) systems. You will engage with multiple engineering disciplines and contribute to the secure design of complex systems System Security Engineering Engineering Engineering Engineering Engineering EngineeringRequirements management in support of program protection (PP)
requirements, work with systems engineers to decompose system level security controls into technical performance
requirements across the segments and down to specific components, across disciplines Anti Tamper, TEMPEST, Cybersecurity (RMF), and cryptographic component integration/development. You will ensure that Cyber
requirements are included in the formal
requirements tracking process and is Cyber/SSE contributor for a segment or subsystem Perform Attack Surface Analysis (ASA) and prepare Systems Security Plan (SSP) documentation for complex space systems, including Risk Assessment Reports (RAR), Security Control Traceability Matrices (SCTM), Security Assessment Procedures, and POA&Ms Implement and maintain COTS security products (firewalls, anti virus, two factor authentication, SIEM tools, etc. within terrestrial systems For space segments, you will support design and implementation of space vehicle hardening, for embedded processors and flight software.
experience:with real time operating systems, secure coding best practices, or other mission critical operational systems is required Prepare and Execute assessment procedures to verify conformance with Commercial, Federal Civilian agency, Department of Defense (DoD), Intelligence Community, and/or Special Access Program, Cyber/SSE security controls, and or survivability requirements, as required based on the specified customer/system tomer/systemtomer/systemtomer/systemtomer/systemtomer/systemtomer/systemtomer/systemtomer/systemtomer/systemtomer/systemtomer/systemtomer/systemtomer/systemrequirements Work in an Agile engineering environment, where the Cyber/SSE may assist in triage of Static Code Analysis (SCA) tool findings (e.g. Fortify) and assist in prioritizing the findings as technical debt in the SwDLC backlog Work in small teams to complete systems engineering, assembly, integration, and test activities for security critical components, such as Cross Domain Solutions, cryptographic devices, and controlled interfaces Securely deploy Mission Unique Software (MUS) in computing clouds and/or highly virtualized environments. Prepare Certification To Field (CTF) assessment procedures. Execute CTF test cases for observation by customer cybersecurity representatives Interface with customer representatives to accomplish Cyber Test & Evaluation of systems to meet critical program milestones Perform system vulnerability scanning, remediation, and patch management activities on Windows and Red Hat operating systems and various COTS/GOTS applications including those within virtualized and/or cloud environments Document (or update) Standard Operating Procedures (SOPs) and when needed, perform software patch installation, other flaw remediation, antivirus updates, and continuous monitoring (ConMon) activities Ensure systems are operated, maintained, and disposed of in accordance with security policies and procedures as outlined in the system security authorization package To be successful you should have:
Experience designing systems/networks to use, or hands on
experience operating, DISA Host Based Security System (HBSS) or Endpoint Security Suite (ESS) solutions
Experience designing systems/networks to use, or hands on
experience with industry platform hardening practices, such as DISA Security Technical Implementation Guide (STIG) implementation, as well as documentation of deviations and mitigations
Experience designing systems/networks to use, or scanning, remediating, mitigating, and reporting cybersecurity vulnerabilities discovered through use of audit reduction tools and/or the DISA Automated Security Compliance Assessment Solution (ACAS) tool or Tenable NESSUS
Experience implementing the RMF process from system categorization through continuous monitoring Excellent technical document preparation
skills with a demonstrated ability to communicate with a variety of stakeholders ranging from technical staffers up to senior program managers Basic
Qualifications:Cyber Engineer Minimum BS degree in engineering, with Electrical Engineering or Software Engineering preferred with 2 years of h 2 years ofexperience (or 1 year of
experience [outside of internships/graduate research/etc.] w/ a Masters, or 1 year [outside of internships/graduate research/etc.] w/ a PhD).
Experience can be considered in lieu of degree Minimum 2 years of Cyber/SSE
experience, preferably within the defense aerospace industry US Citizen with active Top Secret security
clearance, with SCI and DCID 6/4 eligibility at time of application
Experience designing systems/networks to use, or hands on
experience with industry platform hardening practices, such as DISA Security Technical Implementation Guide (STIG) implementation, as well as documentation of deviations and mitigations.
Experience designing systems/networks to use, or scanning, remediating, mitigating, and reporting cybersecurity vulnerabilities discovered through use of audit reduction tools and/or the DISA Automated Security Compliance Assessment Solution (ACAS) tool or Tenable NESSUS.
Experience implementing the RMF process from system categorization through continuous monitoring.
Preferred
Qualifications BS in Electrical Engineering or Software Engineering MS degree in Electrical, Systems, or Aerospace Engineering Current CISSP ISSEP or CISSP ISSAP 7 years of IA/cybersecurity
experience, with are least 3 of those within the SAP community in the defense aerospace industry
Experience hardening Docker containers This position
description does not represent a current opening but may be used to identify candidates with
skills and
experience for positions within Northrop Grumman that frequently become available. Candidates who express an interest may be considered for future positions at Northrop Grumman. The Northrop Grumman Tactical Space Division is a strategic partner specializing in commercial and classified partnerships with the design, delivery, operation and sustainment of satellites and human spacecraft. We support science and space exploration through our various partnerships, including NASA’s Artemis program with the goal to return humans to the Moon in 2024 and the TESS (Transiting Exoplanet Survey Satellite) program that has discovered more than twenty confirmed plants. Recognized as an industry leader, we also develop highly specialized space and satellite components. Northrop Grumman offers a competitive and robust
benefits:program. As a full time employee of Northrop Grumman, you are eligible for our robust benefits package including: Medical Dental & Vision coverage 401k Educational Assistance Life Insurance Employee Assistance Programs & Work/Life Solutions Paid Time Off Health & Wellness Resources Employee Discounts Flexible Schedules (For example the ability to work a 9/80 work schedule, which allows an employee to work a nine hour day Monday through Thursday and take every other Friday off of work) For more details please visit our total rewards site or chat with one of our recruiters to learn more. Link: www.northropgrumman.com/ benefits Tags NGFeaturedJobs Space System NoVASpace / AZSpace DIVSE MMIC #LI BC1 NGIS SSEngineering ESCSO NGCIMSMD Cyber InformationSecurity Primary Level rimary Levelrimary Levelrimary Level salary:Range: $98,400.00 $147,600.00 The above 00 The above00 The abovesalary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope andresponsibilities of the position and the candidate's
experience,
education,
skills and current market conditions. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of
benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business. The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates. Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit http://www.northropgrumman.com/EEO. U.S.
Citizenship:is required for all positions with a governmentclearance and certain other restricted positions.