Expand your horizons, advance your career, and contribute to a secure future for generations. Northrop Grumman’s Space Sector invites you to bring your pioneering spirit to our collaborative teams.
Northrop Grumman Space Systems is seeking a Cyber Systems Engineer – level 3 or 4 to join our team of qualified, diverse individuals.
This role is located in Dulles, VA.
This position is 100% onsite and cannot accommodate telecommute work. This position will work a 9/80 schedule, with every other Friday off.
Position Description:
A Cyber Systems Security Engineering position requires demonstrated technical accomplishments in securing complex systems that can be applied to Space Systems. Space Systems are comprised of multiple segments and this position has responsibilities across Ground Segments, Communications Segments, and Space Segments. This position supports National Security Space missions that require the most trustworthy personnel and a new hire start date is contingent on TS/SCI clearance transfer.
This position is responsible for the following:
Work as part of an integrated product team (IPT) to architect, implement, and satisfy Risk Management Framework (RMF) CyberSecurity, CyberResilience, and/or CyberSurvivability requirements of satellite systems, communications links, and ground command & control (C2) systems. You will engage with multiple engineering disciplines and contribute to the secure design of complex systems
System Security Engineering Requirements management in support of program protection (PP) requirements, work with systems engineers to decompose system-level security controls into technical performance requirements across the segments and down to specific components, across disciplines Anti-Tamper, TEMPEST, Cybersecurity (RMF), and cryptographic component integration/development. You will ensure that Cyber requirements are included in the formal requirements tracking process and is Cyber/SSE contributor for a segment or subsystem
Perform Attack Surface Analysis (ASA) and prepare Systems Security Plan (SSP) documentation for complex space systems, including Risk Assessment Reports (RAR), Security Control Traceability Matrices (SCTM), Security Assessment Procedures, and POA&Ms
Implement and maintain COTS security products (firewalls, anti-virus, two-factor authentication, SIEM tools, etc. within terrestrial systems
For space segments, you will support design and implementation of space vehicle hardening, for embedded processors and flight software. Experience with real-time operating systems, secure coding best practices, or other mission critical operational systems is required
Prepare and Execute assessment procedures to verify conformance with Commercial, Federal Civilian agency, Department of Defense (DoD), Intelligence Community, and/or Special Access Program, Cyber/SSE security controls, and or survivability requirements, as required based on the specified customer/system requirements
Work in an Agile engineering environment, where the Cyber/SSE may assist in triage of Static Code Analysis (SCA) tool findings (e.g. Fortify) and assist in prioritizing the findings as technical debt in the SwDLC backlog
Work in small teams to complete systems engineering, assembly, integration, and test activities for security-critical components, such as Cross Domain Solutions, cryptographic devices, and controlled interfaces
Securely deploy Mission Unique Software (MUS) in computing clouds and/or highly virtualized environments. Prepare Certification To Field (CTF) assessment procedures. Execute CTF test cases for observation by customer cybersecurity representatives
Interface with customer representatives to accomplish Cyber Test & Evaluation of systems to meet critical program milestones
Perform system vulnerability scanning, remediation, and patch management activities on Windows and Red Hat operating systems and various COTS/GOTS applications including those within virtualized and/or cloud environments
Document (or update) Standard Operating Procedures (SOPs) and when needed, perform software patch installation, other flaw remediation, antivirus updates, and continuous monitoring (ConMon) activities
Ensure systems are operated, maintained, and disposed of in accordance with security policies and procedures as outlined in the system security authorization package
To be successful you should have:
Experience designing systems/networks to use, or hands-on experience operating, DISA Host Based Security System (HBSS) or Endpoint Security Suite (ESS) solutions
Experience designing systems/networks to use, or hands-on experience with industry platform hardening practices, such as DISA Security Technical Implementation Guide (STIG) implementation, as well as documentation of deviations and mitigations
Experience designing systems/networks to use, or scanning, remediating, mitigating, and reporting cybersecurity vulnerabilities discovered through use of audit reduction tools and/or the DISA Automated Security Compliance Assessment Solution (ACAS) tool or Tenable NESSUS
Experience implementing the RMF process from system categorization through continuous monitoring
Excellent technical document preparation skills with a demonstrated ability to communicate with a variety of stakeholders ranging from technical staffers up to senior program managers
This position is contingent upon candidate program approval and clearance verification and transfer to the NG sponsored program as well as continued ability to maintain required clearance level.
Basic Qualifications (must have/required to be considered):
This requisition may be filled at either a level 3 (Principal) or a level 4 (Sr Principal), depending on the candidate’s experience as laid out in the basic qualifications detailed below as well as the interview assessment.
Requires an active Top-Secret (TS)/Sensitive Compartmented Information (SCI) clearance [TS/SCI] at time of application [US Citizenship required]
Level 3: (Principal)
Bachelor’s degree in a STEM field with 5 years of cyber systems experience (excluding internships, research projects, etc)
Master’s degree in a STEM field with 3 years of cyber systems experience (excluding internships, research projects, etc)
PhD degree in a STEM field with 1 year of cyber systems experience (excluding internships, research projects, etc)
Level 4: (Sr Principal)
Bachelor’s degree in a STEM field with 8 years of cyber systems experience (excluding internships, research projects, etc)
Master’s degree in a STEM field with 6 years of cyber systems experience (excluding internships, research projects, etc)
PhD degree in a STEM field with 4 years of cyber systems experience (excluding internships, research projects, etc)
Must hold a current CompTIA Sec+ certification OR an IAM level 2 certification*
*If does not possess, must be able to obtain a CISSP or CASP prior to start
Experience designing systems/networks to use, or hands-on experience with industry platform hardening practices, such as DISA Security Technical Implementation Guide (STIG) implementation, as well as documentation of deviations and mitigations.
Experience designing systems/networks to use, or scanning, remediating, mitigating, and reporting cybersecurity vulnerabilities discovered through use of audit reduction tools and/or the DISA Automated Security Compliance Assessment Solution (ACAS) tool or Tenable NESSUS.
Experience implementing the RMF process from system categorization through continuous monitoring.
Preferred Qualifications (not required, but nice to have):
Degree in Electrical Engineering, Software Engineering, or Aerospace Engineering
Current CISSP-ISSEP or CISSP-ISSAP certification
Experience with IA/cybersecurity experience, with are least 3 of those within the SAP community in the defense aerospace industry
Experience hardening Docker containers
About Space Sector:
Offering satellite, payload, directed energy, and electronics for security and civil markets. We're built on innovative, cost-effective aerospace/defense solutions, ensuring mission success. Join our revolution, where the impossible becomes possible.
Curious about all the exciting developments with the Northrop Grumman Space Sector? Click the link below:
https://www.northropgrumman.com/space
Working at Northrop Grumman is more than just a paycheck. We offer a comprehensive Total Rewards and benefits package designed to help you thrive at work and in life. For more information on our Total Rewards package, please visit our Total Rewards site.
Primary Level Salary Range: $125,300.00 - $187,900.00Secondary Level Salary Range: $156,400.00 - $234,600.00The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit http://www.northropgrumman.com/EEO. U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.