Principal Cybersecurity Analyst

Northrop Grumman Northrop Grumman · Aerospace · New York, NY +1 · Cyber

This role focuses on developing, maintaining, and automating policy solutions within cybersecurity, applying emerging automation and AI technologies for efficiency. It involves translating complex regulatory requirements into actionable solutions, performing analyses to validate security requirements, and generating options for implementing security controls. The role also involves developing strategic engagements with government partners to deliver cybersecure tools and sustain Northrop Grumman's cybersecurity posture in a changing regulatory environment.

What you'd actually do

  1. Provide timely, senior‑level security guidance, mentor junior analysts, and influence risk‑mitigation strategies across multiple functions.
  2. Lead implementation of technical control frameworks for programs to mitigate risks and continue to enable certification and accreditation of systems.
  3. Write, maintain, and own end-to-end policy lifecycle – author, maintain, and programmatically apply procedures; integrate AI for continuous improvement.
  4. Proactively monitor U.S. government cyber regulations, synthesize updates from conferences and industry events and disseminate concise briefs to internal stakeholders.
  5. Represent GCP in cross-functional committees, aligning security with NG’s strategic objectives.

Skills

Required

  • Bachelor’s degree in Computer Science, Political Science, Engineering, Cybersecurity or related field with 5 years of experience; OR a Master’s degree with 3 years of experience; OR a PhD with 1 year of experience.
  • Working knowledge of CMMC v2 (Levels 1-3), NIST 800-171/800-172 (All revisions), NIST 800-53, NIST CSF, ISO 27001, and DoD frameworks.
  • Experience presenting to Executive Leadership with ability to proactively translate technical findings into clear policy guidance.
  • CMMC Certified Professional (CCP) and/or 8140 equivalent.

Nice to have

  • Advanced degree or additional certifications (CMMC Certified Assessor (CCA) and/or 8140 equivalent).
  • Direct CMMC contract or FAR/DFARS experience.
  • Experience building AI driven risk assessment or automation solutions.
  • Experience with NIST and FAR commenting.
  • Experience with Contracting, Supply Chain, and technology challenges and solutions.
  • Experience with MS PowerPlatform.

What the JD emphasized

  • CMMC v2 (Levels 1-3)
  • NIST 800-171/800-171
  • NIST 800-53
  • NIST CSF
  • ISO 27001
  • DoD frameworks
  • Experience building AI driven risk assessment or automation solutions