Cyber Systems Engineer (Top Secret) Space Systems (Dulles or Gilbert)
VADU01, United States
Full Time Clearance required USD 85K - 127K
Northrop Grumman
Northrop Grumman solves the toughest problems in space, aeronautics, defense and cyberspace to meet the ever evolving needs of our customers worldwide. Our 95,000 employees define possible every day using science, technology and engineering to...Description
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work — and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.This Cyber Systems Security Engineering position requires demonstrated technical accomplishments in securing complex systems and can apply this expertise to Space Systems. Space Systems are comprised of multiple segments and this position has responsibilities across Ground Segments, Communications Segments, and Space Segments. As an Engineer, you must have demonstrated technical accomplishments in the below tasks. This is a fully funded requisition for National Security Space missions that require the most trustworthy personnel; new hire start date is contingent on TS clearance transfer.
Responsibilities Include
- Working as part of an integrated product team (IPT) to architect, implement, and satisfy Risk Management Framework (RMF) CyberSecurity, CyberResilience, and/or CyberSurvivability requirements of satellite systems, communications links, and ground command & control (C2) systems. The principal engineer engages with multiple engineering disciplines and contributes to the secure design of complex systems.
- System Security Engineering Requirements management in support of program protection (PP) requirements, working with systems engineers to decompose system-level security controls into technical performance requirements across the segments and down to specific components, across disciplines Anti-Tamper, TEMPEST, Cybersecurity (RMF), and cryptographic component integration/development. The principal engineer ensures that Cyber requirements are included in the formal requirements tracking process and is Cyber/SSE contributor for a segment or subsystem.
- Performing Attack Surface Analysis (ASA) and preparing Systems Security Plan (SSP) documentation for complex space systems, including Risk Assessment Reports (RAR), Security Control Traceability Matrices (SCTM), Security Assessment Procedures, and POA&Ms.
- Implements and maintains COTS security products (firewalls, anti-virus, two-factor authentication, SIEM tools, etc., within terrestrial systems.
- For space segments, the Principal Cyber SSE supports design and implementation of space vehicle hardening, for embedded processors and flight software. Experience with real-time operating systems, secure coding best practices, or other mission critical operational systems is required.
- Preparing and Executing assessment procedures to verify conformance with Commercial, Federal Civilian agency, Department of Defense (DoD), Intelligence Community, and/or Special Access Program, Cyber/SSE security controls, and or survivability requirements, as required based on the specified customer/system requirements.
- Working in an Agile engineering environment, where the Cyber/SSE may assist in triage of Static Code Analysis (SCA) tool findings (e.g. Fortify) and assist in prioritizing the findings as technical debt in the SwDLC backlog.
- Working in small teams to complete systems engineering, assembly, integration, and test activities for security-critical components, such as Cross Domain Solutions, cryptographic devices, and controlled interfaces.
- Securely deploying Mission Unique Software (MUS) in computing clouds and/or highly virtualized environments. Preparing Certification to Field (CTF) assessment procedures. Executing CTF test cases for observation by customer cybersecurity representatives.
- Interfacing with customer representatives to accomplish Cyber Test & Evaluation of systems to meet critical program milestones.
- Performing system vulnerability scanning, remediation and patch management activities on Windows and Red Hat operating systems and various COTS/GOTS applications, including those within virtualized and/or cloud environments.
- Documenting (or updating) Standard Operating Procedures (SOPs), and when needed, performing software patch installation, other flaw remediation, antivirus updates, and continuous monitoring (ConMon) activities.
- Ensuring systems are operated, maintained, and disposed of in accordance with security policies and procedures as outlined in the system security authorization package.
Basic Qualifications
Cyber Engineer
- Minimum BS degree in engineering, with Electrical Engineering or Software Engineering preferred with 2 years of experience
(or 1 year of experience [outside of internships/graduate research/etc.] w/ a Masters, or 1 year [outside of internships/graduate research/etc.] w/ a PhD). Experience can be considered in lieu of degree
- Minimum 2 years of Cyber/SSE experience, preferably within the defense aerospace industry
- US Citizen with active Top Secret security clearance, with SCI and DCID 6/4 eligibility at time of application
- Experience designing systems/networks to use, or hands-on experience with industry platform hardening practices, such as DISA Security Technical Implementation Guide (STIG) implementation, as well as documentation of deviations and mitigations.
- Experience designing systems/networks to use, or scanning, remediating, mitigating, and reporting cybersecurity vulnerabilities discovered through use of audit reduction tools and/or the DISA Automated Security Compliance Assessment Solution (ACAS) tool or Tenable NESSUS.
- Experience implementing the RMF process from system categorization through continuous monitoring.
Preferred Qualifications
- AWS a strong plus
- MS degree in Electrical, Systems, or Aerospace Engineering.
- Current CISSP-ISSEP or CISSP-ISSAP.
- 7 years of IA/cybersecurity experience, with are least 3 of those within the SAP community in the defense aerospace industry.
- Strong preference for candidates with experience hardening Docker containers.
Tags: ACAS Agile Antivirus AWS CISSP Clearance Cloud Code analysis Compliance CTF DISA Docker DoD Firewalls Monitoring Nessus PhD Red Hat Risk assessment Risk Assessment Report Risk management RMF SAP SCTM Security assessment Security Clearance SIEM System Security Plan TEMPEST Top Secret Vulnerabilities Windows
Perks/benefits: Career development Health care Insurance Salary bonus
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.