Find Jobs
Find Jobs Near You – Available Work in Your Location
Principal Cyber Protection/Sr. Principal Engineer (AHT)
Job Description
RELOCATION ASSISTANCE
Relocation assistance may be availableCLEARANCE REQUIRED FOR START
YesCLEARANCE TYPE
Top Secret TRAVEL:
Yes, 10% of the Time Description At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work — and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history. Northrop Grumman Defense Systems (NGDS) is seeking a Cyber Protection Principal Engineer to maintain and enhance capabilities in support of DAF CLOUDworks at the Air Force Research Lab (AFRL) in Rome, NY, Warner Robins, GA, or Wright Patterson Air Force Base, OH. DAF CLOUDworks is a rapidly growing secure cloud program that encompasses 10+ teams. These teams span all different areas of cloud engineering including information security, infrastructure development, and cloud migration. You will be an active part of one of these teams providing technical support of customers leveraging DAF CLOUDworks. Along with operations and sustainment, DAF CLOUDworks focuses on modifying and enhancing offerings to implement new requirements, enhance functionality, increase efficiency, or lower operating/deployment. This role is focused on cloud penetration testing, adversarial emulation, red team operations, and container security assessments within a cleared DoD environment. The ideal candidate has a strong offensive security background and deep expertise in AWS and Azure environments. This position is contingent on customer funding and approval and may be filled at a level 3 or level 4.Basic Qualifications:
Level 3: Bachelor's degree in Science with 5+ years of software development experience; Master's with 3+ years of relative experience; or an additional 4 years of experience may be considered in lieu of degree. Level 4: Bachelor's degree in Science with 8+ years of software development experience; Master's with 6+ years of relative experience; or an additional 4 years of experience may be considered in lieu of degree. This position requires an active Top Secret/SCI clearance and the ability to obtain an IAT Level II or III certification (Security+, Pentest+, SecurityX,) within 60 days of start. Deep knowledge of cloud attack paths — IAM privilege escalation, metadata service abuse, misconfigured storage, cross-account trust exploitation, and OAuth/token abuse — is required. Proficiency with cloud-native offensive tooling including Pacu (AWS exploitation framework) and AADInternals (Azure/M365 offensive toolkit), alongside enumeration platforms such as ScoutSuite, CloudFox, Prowler, and ROADtools.Preferred Qualifications:
Prior DoD or IC classified environment experience and familiarity with adversary simulation platforms such as Cobalt Strike, Sliver, or Havoc are a strong plus. Hands-on practitioner who has operated tools at depth across real engagements, documented findings under active assessment constraints, and can communicate risk clearly to both technical teams and senior leadership. Experience developing and executing cyber tabletop exercises including threat scenario design, threat actor emulation planning, and after-action reporting is highly valued. Hands-on experience with Docker and Kubernetes security assessments, including container escape techniques, privileged container abuse, K8s RBAC misconfigurations, service account taken abuse, and CI/CD pipeline security across GitLab, GitHub Actions, and Jenkins environments. Strong scripting skills in Bash, Python, and PowerShell are expected, and a working knowledge ofMITRE ATT&CK
as applied to cloud and hybrid environments Preferred certifications includeOSCP, CPTS, PNPT, GPEN, GXPN, GCPN, AWS
Security Specialty, or AZ-500. Day-to-day work Jira and Confluence for sprint and documentation workflows, and GitHub for version controlled tooling and collaborative code review. #PWRTA3Primary Level Salary Range:
$98,400.00 - $155,400.00Secondary Level Salary Range:
$122,800.00 - $193,900.00 The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business. The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates. Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit http://www.northropgrumman.com/EEO. U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on New York data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$124,932 / year median in New York
+10% projected growth