Principal-sr. Principal Independent Assessment Engineer-aht

Northrop Grumman Northrop Grumman · Aerospace · Rome, NY +1 · Cyber

This role is for an Independent Security Assessor at Northrop Grumman, focusing on assessing implemented security controls within information systems for the DAF CLOUDworks program. The position requires a strong understanding of IT security concepts, cloud technologies, Risk Management Framework (RMF), and security assessment processes. The role involves independent assessment of management, operational, and technical security controls.

What you'd actually do

  1. Conduct independent, comprehensive assessments of the management, operational, and technical security controls implemented within information systems.
  2. Assist the program developing methods to monitor and measure risk, compliance, and assurance efforts.
  3. Validate the implementation of DISA STIGs and Security Requirements Guides (SRGs).
  4. Manage cybersecurity risk and compliance using software platforms like XACTA or eMASS.

Skills

Required

  • Technical knowledge of infrastructure components (network, storage, Linux/Windows)
  • Knowledge of IT security concepts
  • Working knowledge of Cloud-based technologies (AWS, Azure, Google Cloud)
  • Knowledge of current industry methods for IT security assessment, monitoring, detection, and remediation
  • Knowledge of the Security Assessment and Authorization process
  • Knowledge of network security architecture concepts
  • Knowledge of Risk Management Framework (RMF) requirements
  • Familiarity with ACAS (Tenable Nessus) and SCAP Compliance Checker
  • Familiarity with software platforms for cybersecurity risk and compliance (XACTA, eMASS)
  • Experience with Infrastructure as Code (IaC), containerization (Docker, Kubernetes), or DevSecOps

Nice to have

  • Relocation assistance may be available
  • Travel 10% of the Time

What the JD emphasized

  • Active Top Secret clearance with Sensitive Compartmented Information (SCI) eligibility
  • Able to obtain IAT Level II certification per DoD 8570.01 such as CompTIA Security+ (formerly CASP+) or CompTIA Security+ within 60 days of start date.