Find Jobs
Find Jobs Near You – Available Work in Your Location
Sr / Principal Cybersecurity Analyst - 19150 - Redondo Beach California
Career Insights for Vulnerability Analyst / Penetration Tester
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on California data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.
$125,034 / year median in California
+2% projected growth
Job Description
RELOCATION ASSISTANCE
No relocation assistance availableCLEARANCE REQUIRED FOR START
YesCLEARANCE TYPE
Secret TRAVEL:
Yes, 10% of the Time ## Description At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work — and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history. At the heart of Defining Possible is our commitment to missions. In rapidly changing global security environments, Northrop Grumman brings informed insights and secure technological solutions to enable strategic objectives. We're looking for innovators who can help us keep building on our wide portfolio of secure, affordable, integrated, and multi-domain systems and technologies that fuel those missions. By joining in our shared mission, we will support yours by expanding your personal network and developing skills, whether you are new to the field or an industry thought leader. At Northrop Grumman, you will have the resources, support, and team to do some of the best work of your career. The Northrop Grumman CIDO Classified Solutions team is seeking a Sr. / Principal Classified Cybersecurity Analyst to support information systems lifecycle activities. The selected candidate will be required to work on-site, full-time at our Redondo Beach, California location. The responsibilities of this role include, but are not limited to, the following:- Manage the cybersecurity program of all assigned information systems and execute all cybersecurity-related tasks.
- Conduct and lead regular reviews of system audits and continuous monitoring activities, covering all security controls and configurations, to enhance operational efficiencies of the information system security posture.
- Perform assessments of systems and networks within the networking environment or enclave and identify where those systems and networks deviate from acceptable configurations, enclave policy, or local policy.
- Perform analyses to validate established security requirements and to recommend additional security requirements and safeguards.
- Drive the implementation of the required government policy, make recommendations on process tailoring, participate in and document process activities.
- Establish and oversee strict program control processes that mitigate risk and support system Assessment and Authorization (A&A). This includes process support, analysis, coordination, security certification testing, security documentation, investigations, software research, hardware introduction and release, emerging technology research, inspections, and periodic audits.
- Lead the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results and preparation of required reports.
- Document the results of A&A activities, and inspection activities, along with any technical or corrective actions and work collectively with the security team to submit responses to the appropriate cognizant authority.
- Prepare, review, and submit A&A documentation (System Security Plan, Risk Acceptance Report, Security Controls Traceability Matrix, Plan of Action and Milestones, etc.
Note:
Due to the classified nature of the work being performed, this position does not offer any virtual or telecommute working options. Applicants are encouraged to apply only if they are willing to work on-site. Basic Qualifications for Level 3:- Master's Degree with 3 years of experience; OR a Bachelor's Degree with 5 years of experience; OR an Associate's Degree with 7 years of experience; OR a High School Diploma (or equivalent) with 9 years of experience is required Basic Qualifications for Level 4:
- Master's Degree with 6 years of experience; OR a Bachelor's Degree with 8 years of experience; OR an Associate's Degree with 10 years of experience; OR a High School Diploma (or equivalent) with 12 years of experience is required
Additional Basic Qualifications:
- Candidates must meet the U.
Example:
Security+ CE, CySA+, GICSP, GSEC, CND, SSCP)- Candidates must have a current U.S. Government Secret security clearance (at a minimum), to include a closed investigation date completed within the last 6 years OR must be enrolled in the U.S. Government Continuous Evaluation (CE) Program to be considered
- Candidates must have the ability to obtain, and maintain, access to Special Access Programs as a condition of continued employment
Preferred Qualifications:
- Bachelor's degree in Cybersecurity or related field
- Experience in cybersecurity compliance (ex. Assessment & Authorization under RMF)
- Knowledge of security tools such as ACAS, Nessus, Splunk, Trellix, and SCAP
- Knowledge of security frameworks and documentation such as NIST, JSIG, DAAG, SSPs, POA&Ms, and SCTMs
- Proven experience designing, implementing, and supporting Cross Domain Solutions (CDS) for secure data transfer across classified networks.