Staff Cyber Security Analyst
UTRO01, United States
Full Time Senior-level / Expert Clearance required USD 147K - 221K
Northrop Grumman
Northrop Grumman solves the toughest problems in space, aeronautics, defense and cyberspace to meet the ever evolving needs of our customers worldwide. Our 95,000 employees define possible every day using science, technology and engineering to...Description
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work — and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.Northrop Grumman is seeking a Staff Cyber Security Analyst for its Roy, Utah location.
Roles and Responsibilities Include:
- Establish strict program control processes to ensure mitigation of risks and support obtaining certification and accreditation of systems; this includes support of process, analysis, coordination, security certification test, security documentation, as well as investigations, software research, hardware introduction and release, emerging technology research inspections, and periodic audits.
- Implement required government policy (i.e., JSIG, DAAPM), review and make recommendations on process tailoring, and approve documented processes.
- Perform analyses to validate established security requirements and implement additional security requirements and safeguards.
- Support the formal Security Test and Evaluation (ST&E) required by each government authority through pre-test preparations, participation in the tests, analysis of the results, and preparation of required reports.
- Document the results of Assessment and Authorization activities and technical or coordination activity and prepare the system Security Plans and update the Plan of Actions and Milestones POA&M.
- Periodically conduct a complete review of each system's audits and monitor corrective actions until all actions are closed.
- The ability to obtain a Special Access Programs (SAP/SAR) clearance within a reasonable period of time as determined by the company, and also by customer and/or program requirements; maintaining a SAP clearance will be a condition of continued employment.
- Current DoD 8570 IAM Level II security certification (i.e CAP, CISSP, etc.)
- Demonstrated expert knowledge of cybersecurity practices, network technologies, and system development life-cycles, in addition to an understanding of information technology infrastructure management/monitoring and applications.
- Experience developing guidelines, monitoring policies, and enforcing standards for cybersecurity frameworks and industry best practices supporting National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, CNSSI 1253, and DoD Risk Management Framework (RMF).
Basic Qualifications:
- Bachelor's Degree with at least 12 years of experience, or Master's degree and 9 years of experience.
- Current DoD Secret level security clearance with an original adjudication, or a periodic reinvestigation date, completed within the last 6 years; maintaining the required security clearance will be a condition of continued employment.
- The ability to obtain a Special Access Programs (SAP/SAR) clearance within a reasonable period of time as determined by the company, and also by customer and/or program requirements; maintaining a SAP clearance will be a condition of continued employment.
- Current DoD 8570 IAM Level II security certification (i.e CAP, CISSP, etc.)
- Demonstrated expert knowledge of cybersecurity practices, network technologies, and system development life-cycles, in addition to an understanding of information technology infrastructure management/monitoring and applications.
- Experience developing guidelines, monitoring policies, and enforcing standards for cybersecurity frameworks and industry best practices supporting National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, CNSSI 1253, and DoD Risk Management Framework (RMF).
Preferred Qualifications:
- Working knowledge of Microsoft and Linux Red Hat operating system.
- Working knowledge and understanding of auditing, vulnerability scanning/remediation, SIEMs, DISA STIGs, configuration/change control, and implementation of Risk Management Framework.
- Strong verbal and written communication skills to produce coherent and concise documentation required for certification evaluation.
Tags: Audits CISSP Clearance DAAPM DISA DoD DoDD 8570 IAM Linux Monitoring NIST NIST 800-53 POA&M Red Hat Risk management RMF SAP Security Assessment Report Security Clearance SIEM STIGs System Security Plan
Perks/benefits: Career development Health care Insurance Relocation support Salary bonus
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.