Classified Cybersecurity Analyst

Northrop Grumman Northrop Grumman · Aerospace · Baltimore, MD +1 · Cyber

Northrop Grumman is seeking a Classified Cybersecurity Analyst to perform assessments of systems and networks, identify deviations from acceptable configurations, and establish program control processes to mitigate risks. The role involves assisting in the implementation of government policy (RMF, DAAPM, NIST), performing security test and evaluation, and completing Assessment and Authorization activities including RMF Body Of Evidence documentation. A Secret security clearance and Security+CE certification are required.

What you'd actually do

  1. Perform assessments of systems and networks within the networking environment or enclave and identify where those systems and networks deviate from acceptable configurations, enclave policy, or local policy; this is achieved through passive evaluations such as compliance audits and active evaluations such as vulnerability assessments.
  2. Establish strict program control processes to ensure mitigation of risks and support obtaining certification and accreditation of systems; this will include support of process, analysis, coordination, security certification test, security documentation, as well as investigations, software research, hardware introduction and release, emerging technology research inspections, and periodic audits.
  3. Assist in the implementation of the required government policy (i.e. RMF, DAAPM, NIST), make recommendations on process tailoring, and participate in and document process activities.
  4. Perform analyses to validate established security requirements and to recommend additional security requirements and safeguards.
  5. Support the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results, and preparation of required reports.

Skills

Required

  • Associate's degree with 4 years of relevant experience, or a Bachelor's degree with 2 years of relevant experience, or a Master's degree with 0 years of experience; a High School diploma or equivalent with 6 years of relevant experience may be considered in lieu of a completed degree.
  • current DoD Secret level security clearance (at a minimum), to include a closed investigation date completed within the last 6 years, or must be enrolled in the DoD Continuous Evaluation Program (CEP)
  • obtain and maintain access to Special Programs
  • Current Security+CE certification
  • apply knowledge, insights, and understanding of business and cybersecurity concepts, tools, and processes
  • manage communications with stakeholders
  • identify and address cybersecurity program impacts

Nice to have

  • Bachelor's degree in Cyber Security, Information Security, or a similar STEM related discipline.
  • Diverse classified information systems security/information assurance background.
  • Knowledge of ACAS, NESSUS, SPLUNK, SCAP, POA&Ms, NIST, JSIG, system audits, vulnerability scanning, and/or RMF package development.
  • Prior experience communicating with customers and program leadership.
  • Current DoD Top Secret/SCI security clearance.

What the JD emphasized

  • Secret
  • Secret
  • Secret
  • RMF
  • RMF
  • RMF