RELOCATION ASSISTANCE: No relocation assistance available
CLEARANCE REQUIRED FOR START: Yes
CLEARANCE TYPE: Secret
TRAVEL: Yes, 10% of the Time
DescriptionThe Northrop Grumman CIDO Classified Solutions team is seeking a
Classified Cybersecurity Analyst to support information systems lifecycle activities. The selected candidate will be required to work on-site, full-time at our Linthicum, MD location.
This position may be filled as a Level 3 or Level 4.
Level 3 responsibilities of this role will include but not be limited to the following:
- Conduct system audits and continuous monitoring activities, covering all security controls, configurations, and operational processes to evaluate the security posture of the information systems.
- Perform assessments of systems and networks within the networking environment or enclave and identify where those systems and networks deviate from acceptable configurations, enclave policy, or local policy.
- Perform analyses to validate established security requirements and to recommend additional security requirements and safeguards.
- Assist in the implementation of the required government policy, make recommendations on process tailoring, and participate in and document process activities.
- Establish strict program control processes to ensure mitigation of risks and support the Assessment and Authorization (A&A) of systems. This includes process support, analysis, coordination, security certification testing, security documentation, investigations, software research, hardware introduction and release, emerging technology research, inspections, and periodic audits.
- Support the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results, and preparation of required reports.
- Document the results of A&A activities, and technical or coordination activities, and prepare the Risk Management Framework body of evidence.
Level 4 responsibilities of this role will include but not be limited to the following:
- Manage the cybersecurity program of all assigned information systems and execute all cybersecurity-related tasks.
- Conduct and lead regular reviews of system audits and continuous monitoring activities, covering all security controls and configurations, to enhance operational efficiencies of the information system security posture.
- Perform assessments of systems and networks within the networking environment or enclave and identify where those systems and networks deviate from acceptable configurations, enclave policy, or local policy.
- Perform analyses to validate established security requirements and to recommend additional security requirements and safeguards.
- Drive the implementation of the required government policy, make recommendations on process tailoring, and participate in and document process activities.
- Establish and oversee strict program control processes that mitigate risk and support system Assessment and Authorization (A&A). This includes process support, analysis, coordination, security certification testing, security documentation, investigations, software research, hardware introduction and release, emerging technology research, inspections, and periodic audits.
- Lead the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results, and preparation of required reports.
- Document the results of A&A activities, and inspection activities, along with any technical or corrective actions and work collectively with the security team to submit responses to the appropriate cognizant authority.
- Prepare, review, and submit A&A documentation (System Security Plan, Risk Acceptance Report, Security Controls Traceability Matrix, Plan of Action and Milestones, etc.) for review and approval.
Note: Due to the classified nature of the work being performed, this position does not offer any virtual or telecommute working options. Applicants are encouraged to apply only if they are willing to work on-site, full-time at our Linthicum, MD campus.
Basic Qualifications for Level 3:- Master's degree with 3 years of experience, or a Bachelor's degree with 5 years of experience, or an Associates degree with 7 years of experience; a High School Diploma/GED with 9 years of experience may be considered in lieu of a completed degree.
- Candidates must meet the U.S. Government 8140 requirements for a Principal Classified Cybersecurity Analyst - IAM II - or be able to obtain the required certification within 6 months of hire date; the required certification must be maintained as a condition of continued employment.
Basic Qualifications for Level 4:- Master's degree with 6 years of experience, or a Bachelor's degree with 8 years of experience, or an Associates degree with 10 years of experience; a High School Diploma/GED with 12 years of experience may be considered in lieu of a completed degree.
- Candidates must meet the U.S. Government 8140 requirements for a Principal Classified Cybersecurity Analyst - IAM III; the required certification must be maintained as a condition of continued employment.
Basic Qualifications for Levels 3 and 4:- Candidates must have a current U.S. Government Secretsecurity clearance (at a minimum), to include a closed investigation date completed within the last 6 years, OR must be enrolled in the U.S. Government Continuous Evaluation (CE) Program to be considered.
Preferred Qualifications:- Bachelor's degree in Cybersecurity or related field.
- Experience in cybersecurity compliance (ex. Assessment & Authorization under RMF).
- Knowledge of security tools such as ACAS, Nessus, Splunk, Trellix, and SCAP.
- Knowledge of security frameworks and documentation such as NIST, JSIG, DAAG, SSPs, POA&Ms, and SCTMs.
We offer flexible work arrangements, phenomenal learning opportunities, exposure to a wide variety of projects and customers, and a very friendly team environment. At Northrop Grumman, we are on the cutting edge of innovation. Our diverse portfolio of programs means there are endless paths to cultivate your career. We also offer exceptional benefits/healthcare, a 9/80 work schedule, and a great 401k matching program. Come join us!
Primary Level Salary Range: $108,800.00 - $163,200.00
Secondary Level Salary Range: $135,800.00 - $203,600.00
The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.
Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.
The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.