Classified Cybersecurity Analyst

Northrop Grumman Northrop Grumman · Aerospace · Baltimore, MD +1 · Cyber

This role involves performing cybersecurity assessments, identifying deviations from acceptable configurations, establishing risk mitigation processes, and supporting certification and accreditation of systems. It requires implementing government policies, performing security test and evaluation, and completing Assessment and Authorization activities like RMF documentation. The position requires a Secret security clearance and a Security+CE certification.

What you'd actually do

  1. Perform assessments of systems and networks within the networking environment or enclave and identify where those systems and networks deviate from acceptable configurations, enclave policy, or local policy; this is achieved through passive evaluations such as compliance audits and active evaluations such as vulnerability assessments.
  2. Establish strict program control processes to ensure mitigation of risks and support obtaining certification and accreditation of systems; this will include support of process, analysis, coordination, security certification test, security documentation, as well as investigations, software research, hardware introduction and release, emerging technology research inspections, and periodic audits.
  3. Assist in the implementation of the required government policy (i.e. RMF, DAAPM, NIST), make recommendations on process tailoring, and participate in and document process activities.
  4. Perform analyses to validate established security requirements and to recommend additional security requirements and safeguards.
  5. Support the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results, and preparation of required reports.

Skills

Required

  • Associate's degree with 4 years of relevant experience, or a Bachelor's degree with 2 years of relevant experience, or a Master's degree with 0 years of experience; a High School diploma or equivalent with 6 years of relevant experience may be considered in lieu of a completed degree.
  • current U.S. Government Secret level security clearance (at a minimum), to include a closed investigation date completed within the last 6 years, or must be enrolled in the DoD Continuous Evaluation Program (CEP), in order to be considered; the required security clearance must be maintained as a condition of continued employment.
  • The ability to apply knowledge, insights, and understanding of business and cybersecurity concepts, tools, and processes to the benefit of program decisions, actions, and performance.
  • The ability to manage communications with stakeholders through organized processes to ensure that program information is defined, collected, shared, understood, stored, and retrieved in a manner that effectively meets program and stakeholder needs that are within Cybersecurity risk tolerance.
  • The ability to identify and address cybersecurity program impacts through a systematic proactive approach that identifies, communicates, monitors, and promptly resolves conflicts across all levels of the program.

Nice to have

  • Bachelor's degree in Cyber Security, Information Security, or a similar STEM related discipline.
  • Diverse classified information systems security/information assurance background.
  • Knowledge of ACAS, NESSUS, SPLUNK, SCAP, POA&Ms, NIST, JSIG, system audits, vulnerability scanning, and/or RMF package development.
  • Prior experience communicating with customers and program leadership.
  • Current U.S. Government Top Secret/SCI security clearance.

What the JD emphasized

  • current U.S. Government Secret level security clearance
  • must be enrolled in the DoD Continuous Evaluation Program (CEP)
  • obtain and maintain access to Special Programs
  • current Security+CE certification