Northrop Grumman Defense Systems is seeking a Cybersecurity Analyst - 19971. This position is located in Roy, UT and supports the Sentinel program.
You will lead Risk Management Framework (RMF) activities, assess system vulnerabilities, implement DISA STIGs, and ensure strict compliance with NIST SP 800-series standards and DoD instruction set directives.
________________________________________
Key Responsibilities
• RMF Accreditation & Compliance: Execute the Risk Management Framework (NIST SP 800-37 / DoDI 8510.01) steps from categorization through Authorization to Operate (ATO) and continuous monitoring.
• Systems Security Engineering: Apply NIST SP 800-160 principles to design, implement, and maintain system security architectures for defense applications.
• Control Evaluation & Hardening: Implement and tailor security controls based on NIST SP 800-53 rev 5 and NIST SP 800-171. Apply DISA Security Technical Implementation Guides (STIGs) across Linux, Windows Server, and cloud environments.
• Vulnerability & Compliance Scanning: Utilize tools such as ACAS (Tenable Nessus), DISA Security Content Automation Protocol (SCAP), and Trellix/HBSS/ESS to execute automated vulnerability scans, document deviations, and oversee remediation.
• Artifact Authoring: Draft, review, and maintain system accreditation artifacts including System Security Plans (SSP), Security Assessment Reports (SAR), Plan of Action & Milestones (POA&M), and Security Control Traceability Matrices (SCTM).
• Cross-Functional Support: Partner with software, systems engineering, and program teams to integrate security into the Agile software development lifecycle (DevSecOps) and containerized workloads
Position Benefits:
As a full-time employee of Northrop Grumman Space Systems, you are eligible for our robust benefits package including:
• Medical, Dental & Vision coverage
• 401k
• Educational Assistance
• Life Insurance
• Employee Assistance Programs & Work/Life Solutions
• Paid Time Off
• Health & Wellness Resources
• Employee Discounts
This position’s standard work schedule is a 9/80. The 9/80 schedule allows employees who work a nine-hour day Monday through Thursday to take every other Friday off. This role may offer a competitive relocation assistance package.
Basic Qualifications:
Bachelor's degree with 2 years of experience, or Master's degree; 4 additional years of experience may be considered in lieu of a completed degree.
Must be a US Citizen and have an active U.S. Government DoD Secret security clearance at time of application, current and within scope, with an ability to obtain and maintain Special Access Program (SAP) approval within a reasonable period of time, as determined by the company to meet its business need.
DoD 8570/8140 Certification: Active IAM Level I or IAT Level II certification (e.g., Security+ CE, CySA+, CCNA Security, GICSP, or SSCP).
Demonstrated, hands-on experience applying NIST SP 800-53 and NIST SP 800-37 (RMF) frameworks in a DoD or Intelligence Community (IC) environment.
Direct experience with DISA STIG implementation, auditing, and hardening practices.
Proficiency in executing vulnerability scans with tools like ACAS, Nessus, or Rapid7
Preferred Qualifications:
• Advanced certifications such as CISSP, CASP+ CE, CISM, or AWS/Azure Security Specialty.
• Experience with Systems Security Engineering frameworks defined in NIST SP 800-160.
• Working knowledge of cross-domain solutions, cryptographic equipment, or space/ground segment defense systems.
• Experience with scripting and automation tools (e.g., Python, PowerShell, Ansible, or Terraform) to automate compliance verification.
• Familiarity with container security (e.g., Docker, Kubernetes, OpenShift) and hardening within DoD Iron Bank or similar repositories.
Primary Level Salary Range: $79,300.00 - $118,900.00Job details are sourced from the employer's original posting.
Open job postingAbout the company
Northrop Grumman Corporation is an American multinational aerospace and defense technology company.