Full Job Description
RELOCATION ASSISTANCE: No relocation assistance available
CLEARANCE REQUIRED FOR START: No
CLEARANCE TYPE: Secret
TRAVEL: Yes, 10% of the Time
Northrop Grumman’s Corporate Sector's Chief Information & Digital Office (CIDO) is seeking a Sr. Principal Computer Systems Analyst – Cloud Platform / Landing Zone Engineer (AWS) to support its IT Infrastructure & Operations organization's Classified Solutions team. The selected candidate will serve as the leading technical authority for our proprietary, air-gapped AWS Secret Cloud for Industry (ASCI) IL6 multi-account environment. This technical leader will guide the successful design, security standards, and architectural integrity of classified multi-account workloads.
This role is responsible for the transition from legacy “on-prem” operational habits to automated, highly resilient cloud-native infrastructures, ensuring that developers receive modern, high velocity capabilities without compromising our Authorization to Operate (ATO). You will apply extensive technical expertise to solve complex, non-recurring deployment challenges and serving as a key mentor for junior platform personnel and tier-1 triage teams.
The selected candidate will be required to work on-site, full-time at our Redondo Beach, CA, or Rolling Meadows, IL, or Melbourne, FL location.
The responsibilities of this role include, but are not limited to, the following:
General Responsibilities:
- Perform as a lead Sr. Principal Computer Systems Analyst - Cloud Platform / Landing Zone Engineer (AWS) in support of classified government contracts.
- Communicate effectively with all organizational levels, internal/external customers, vendors, and senior leadership, both verbally and in writing.
- Oversee operations and administration of multi-user computer systems and multiple networks, coordinating with IT teams, project managers, and end users.
- Analyze requirements, recommend, and implement hardware/software solutions; interact with vendors to evaluate and troubleshoot products and services.
- Define, implement, and maintain enterprise-wide system enhancements, including installation, upgrades/patches, monitoring, configuration management, and problem resolution.
- Lead testing, validation, and change management for major product releases across platforms.
- Develop, publish, and continuously improve technical standards and SOPs.
- Ensure compliance with Information Systems security guidelines; prepare and maintain security documentation, audit logs, and Assessment & Authorization (A&A) submissions; serve as senior liaison to the ISSM.
- Report on strategic initiatives and project status to executive stakeholders; act as a key technical advisor impacting enterprise-wide, mission-critical systems.
- Acts as a key technical advisor to senior leadership; impacts multiple programs and mission‑critical systems across the enterprise.
- Provide senior-level technical expertise by mentoring junior and experienced team members, fostering their professional growth and enhancing team capabilities.
- Lifts and moves equipment up to 50 pounds.
- Work after hours, and weekends, as needed.
Environment Automation & IaC:
- Declarative Infrastructure: Develop and maintain declarative Infrastructure as Code (IaC) templates using declarative tools such as AWS CloudFormation, AWS SAM, Terraform, OpenTofu to standardize and automate Secret‑level cloud environments.
- Account Provisioning: Design and manage automated Account Vending Machines (AVMs) and account factories to rapidly provision standardized, compliant VPCs and AWS accounts for mission application teams, preventing multi-tenant data comingling.
- Offline Pipeline Architecture: Build and maintain offline, air-gapped CI/CD pipelines tailored to execute in code-isolated environments without public internet connectivity or external SaaS dependencies.
Governance, Security, & Guardrails:
- Access Control Enforcement: Author and enforce strict Service Control Policies (SCPs) and IAM permission boundaries to prevent unauthorized lateral movement between multi-tenant program partitions.
- Centralized Security Logging: Configure centralized audit logging by routing AWS CloudTrail events directly to a secure, immutable, centralized S3 logging bucket for seamless ingestion into our on‑premises Splunk environment, including designing compliant alternatives when native services (e.g., GuardDuty or SQS‑based pipelines) are unavailable or not accredited in the air‑gapped region.
- Manual AMI Hardening: Lead the manual STIG hardening and security configuration of Red Hat Enterprise Linux (RHEL) and Windows Amazon Machine Images (AMIs) using localized Ansible and PowerShell scripts, managing the interim pipeline while AWS Image Builder remains unapproved on the high side.
- ATO Compliance Mapping: Map all cloud infrastructure configurations directly to DISA STIGs and NIST SP 800-53 controls to achieve first time pass rates during DCSA continuous monitoring audits.
Network & Hybrid Data Flow:
- Secure Hybrid Connectivity & Patch Ingestion: Design and maintain zero‑trust network connectivity between Secret‑level AWS environments and Secret‑level on‑prem systems using AWS Transit Gateway, Direct Connect, and software‑defined firewalls. Work with security and cross‑domain solution teams to define compliant, controlled processes for importing patches and updates from lower‑classification environments into the air‑gapped Secret environment.
- On-Premise DNS Reach Back: Design and manage conditional DNS forwarding architectures using Route 53 Resolver Endpoints pointing directly back to our on-premises Active Directory and DNS servers, explicitly avoiding the deployment of active domain controllers inside the cloud boundary.
Note: Due to the classified nature of the work being performed, this position does not offer any virtual or telecommute working options. Applicants are encouraged to apply, only if they are willing to work on-site.
Basic Qualifications:
- Master's Degree with 6 years of IT experience; OR a Bachelor's Degree with 8 years of IT experience; OR an Associate's Degree with 10 years of IT experience; OR a High School Diploma/GED with 12 years of IT experience is required.
- Candidates must have the ability to obtain a U.S. Government Secret level security clearance as a condition of continued employment.
- Linux operating system workstation and server administration/support experience in DoD/IC classified and/or air‑gapped environments.
- Operating system cross‑platform awareness (e.g., Windows, Linux, UNIX variants), including interoperability considerations in mixed on‑prem and cloud environments
- Experience administering container orchestration platforms (e.g., Kubernetes‑based environments such as Amazon EKS or OpenShift) in classified or regulated environments.
- Proficiency with automation and configuration management tools (e.g., Ansible, Bash/Python scripting) in Linux and cloud environments.
- Solid understanding of networking concepts (TCP/IP, DNS, load balancing, firewalls) and AWS networking primitives (VPCs, subnets, security groups, network ACLs, Transit Gateway, Direct Connect, Route 53 Resolver) in classified cloud contexts.
- Demonstrated experience with system and platform security hardening and patch management using DISA STIGs and other DoD security baselines.
- Hands‑on experience architecting and operating AWS multi‑account landing zones in regulated or classified environments (e.g., AWS Organizations, SCPs, IAM guardrails, centralized logging).
- Experience designing and maintaining CI/CD pipelines and mirrored repositories for patch and artifact distribution into Secret‑level environments.
- Candidates must meet U.S. Government DoD 8140 (formerly 8570) requirements for the appropriate IAT/IAM level (typically a CompTIA Security+ or equivalent) for a Sr. Principal Computer Systems Analyst working Linux and cloud systems in a classified environment or able to obtain within six months of hire
- Active DoD Secret clearance or ability to obtain and maintain a DoD Secret clearance.
Preferred Qualifications:
- Bachelor’s degree in Information Technology or related field, and 10+ years of Linux server administration experience in DoD/IC classified and/or air‑gapped environments.
- A current U.S. Government Secret level security clearance.
- Candidates must have the ability to obtain, and maintain, a U.S. Government Top Secret level security clearance as a condition of continued employment.
- Candidates must have the ability to obtain, and maintain, SCI level access as a condition of continued employment.
- Candidates must have the ability to obtain, and maintain, a Polygraph as a condition of continued employment.
- Candidates must have the ability to obtain, and maintain, access to Special Programs as a condition of continued employment.
- Advanced cybersecurity certifications such as CASP+, CISSP, or cloud security certifications (e.g., AWS Certified Security – Specialty) in addition to meeting DoD 8140 baseline (e.g., Security+ CE).
- Operating system cross‑platform operations (e.g., Windows, Linux, UNIX variants), including integration between on‑premises and AWS workloads in classified environments.
- Experience working directly with Information System Security Managers (ISSMs) and supporting Assessment & Authorization (A&A) activities for cloud hosted systems.
- Experience administering modern Linux distributions (RHEL 8/9, Rocky Linux, etc.), including STIG‑hardened images in classified environments.
- Experience operating under and managing systems within NISPOM Chapter 8, DCID 6/3‑ICD 503, RMF, STIG, JAFAN, or JSIG information system environments.
- Experience with AWS Secret and Top Secret regions (e.g., SC2S, C2S) or other government‑only cloud offerings, including operating within air‑gapped or restricted‑connectivity constraints.
- Practical experience designing AWS landing zones using AWS Organizations, Control Tower/Account Factory, or homegrown Account Vending Machines in classified environments.
- Kubernetes orchestration (CNCF Kubernetes, Rancher, Kubernetes Dashboard, etc.), including experience with Amazon EKS or OpenShift on AWS in secure or classified deployments.
- Advanced containerization skills (Podman, Podman Compose, Docker, Docker Compose, etc.) and container security tools, with experience securing containers in air‑gapped or disconnected environments.
- Hands‑on experience with DevSecOps tooling in classified or regulated environments, including:
- Container and code security scanners (e.g., Trivy, Anchore, Clair, SonarQube).
- Secrets and key management solutions (HashiCorp Vault, AWS KMS in Secret regions, OpenShift/Kubernetes secrets).
- Experience with Terraform, OpenTofu, and AWS CloudFormation (or CDK) for hybrid on‑prem/AWS and OpenShift environments in classified settings.
- Familiarity with logging and observability stacks (e.g., EFK/ELK, Prometheus/Grafana, Splunk) deployed in air‑gapped or restricted‑connectivity environments.
- Experience building and maintaining CI/CD pipelines with integrated security checks, including offline/air‑gapped pipelines for Secret‑level AWS and on‑prem systems.
- Proficient in virtualization platforms (VMware vSphere/ESXi, Citrix XenServer, KVM/QEMU, etc.) used in classified data centers supporting hybrid on‑prem/Secret‑level AWS environments.
- Windows domain architecture experience, including hybrid integration between on‑prem Active Directory and AWS (e.g., via Route 53 Resolver and conditional forwarding) in classified environments.
- Experience with Windows AD, LDAP, VMware, and SAN storage sys