hirly

Northrop Grumman

Principal Cyber Systems Engineer – Cyber A&A Engr (26-324)

United States-Colorado-Schriever AFB

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Northrop Grumman first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.6M live jobs from 190,000+ employers in 200+ countries.

Tailor my resume for this job →

Apply from your AI assistant

Connect hirly to Claude and ask it to apply to this job. hirly tailors your resume, fills the employer’s form and asks before sending. ChatGPT: manual setup today.

Some employer sites stop an application at a CAPTCHA or sign-in and hand it back with a link. Applying needs a paid plan. Works with any assistant that supports MCP.

hirly's read of this role

Seniority
Lead / management
Country
US
Work mode
On-site / unstated
First seen by hirly
25 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

RELOCATION ASSISTANCE: No relocation assistance available

CLEARANCE REQUIRED FOR START: Yes

CLEARANCE TYPE: Top Secret

TRAVEL: Yes, 10% of the Time

Description

At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work — and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.

Northrop Grumman Space Systems—Missile Defense Integration offers an excellent opportunity for a Principal Cyber Systems Engineer – Cyber A&A Engr (26-324) to join our team of skilled and diverse professionals. Based at Schriever Space Force Base, CO, this role is essential to supporting the U.S. President, the Secretary of Defense, and combatant commanders at the strategic, regional, and operational levels.

This position does not provide relocation assistance and requires on-site work with no remote options.

Position Overview:

Northrop Grumman Space Systems – Launch and Missile Defense Systems seeks a highly motivated Cyber Assessment & Authorization (A&A) Engineer to join the C2BMC (Command and Control, Battle Management, and Communications) program in Colorado Springs, CO.

C2BMC integrates the Missile Defense System and is a vital operational capability that enables senior decision-makers and combatant commanders to plan ballistic missile defense operations, maintain shared situational awareness, and dynamically manage sensors and weapon systems to achieve global and regional mission objectives. This role directly supports continuous system authorization by ensuring the cybersecurity posture of complex, distributed mission systems.

The Cyber A&A Engineer will apply deep cybersecurity engineering expertise and hands-on experience with RMF, ACAS/SCC/ConfigOS , and eMASS/Xacta to drive risk-informed decisions, maintain strong cyber hygiene, and support mission-critical accreditation activities.

Essential Functions:

Perform Assessment & Authorization (A&A) activities in support of continuous system Authorization for C2BMC and associated mission systems

Analyze ACAS, SCC, and ConfigOS scan results to identify vulnerabilities, misconfigurations, and control gaps across complex enterprise environments

Review, interpret, and validate STIGs, RMF controls (NIST SP 800‑53), and DoD cybersecurity requirements; provide clear technical guidance to engineering and operations teams

Develop and maintain Plan of Action & Milestones ( POA&Ms ), including engineering responses, remediation plans, and residual risk documentation

Conduct risk analysis for Risk Acceptance Requests ( RARs ) and provide recommendations to leadership based on mission impact and risk posture

Utilize eMASS/Xacta to create, maintain, and update system authorization packages, ensuring accuracy, completeness, and compliance with DoD RMF processes

Support the accreditation of Cross Domain Solutions ( CDS ), including documentation, control implementation evidence, and coordination with security stakeholders

Collaborate closely with C2BMC internal teams and external stakeholders (including 3rd party assessors and auditors) to plan, execute, and document cybersecurity assessments

Assist with the management and auditing of user and privileged accounts, ensuring adherence to least-privilege and separation-of-duties principles

Contribute to patch and configuration management activities by analyzing scan results, validating remediation actions, and verifying system compliance

Prepare and present clear, concise technical documentation and briefings for program management, cybersecurity leadership, and customer representatives

Basic Qualifications:

Please list your current security clearance and IAT or relevant certifications on your resume, if applicable.

  • A Bachelor’s Degree in Computer Science, Cybersecurity Engineering, Information Assurance, Engineering, Mathematics, Physics, or a related field from an accredited university, along with 5 years of experience; or a Master’s degree in a related field with 3 years of relevant work experience; or 9 years of relevant work experience may be considered as an alternative to a degree
  • Applicants must have a current, active Government-Issued 8140 certification at IAT Level II or higher (such as Security+ CE, GSEC, SSCP, CCNA-Security, CySA+, CND, etc.) at the time of application, which is required to start. The candidate is responsible for maintaining their 8140 certifications throughout the entire contract period
  • Applicants must have a current, active in-scope Government-issued Top Secret security clearance at the time of application, which is required to start

Cybersecurity & RMF

Strong cybersecurity engineering background with practical experience applying DoD Risk Management Framework ( RMF ) and NIST SP 800‑53 security controls

Working knowledge of DoDI 8500-series requirements and DoD cybersecurity directives and standards

Tools & Technologies

Hands-on experience reviewing and interpreting ACAS and SCC outputs , including vulnerability findings and compliance check results.

Demonstrated experience with STIGs , vulnerability scanning tools, and security configuration baselines

Experience using eMASS (and/or Xacta) to develop, maintain, and track RMF authorization packages

Experience supporting or participating in the accreditation of Cross Domain Solutions ( CDS )

Communication & Documentation

Excellent technical writing skills for preparing security plans, POA&Ms, risk assessments, and supporting documentation

Strong verbal communication skills with the ability to clearly articulate complex technical concepts to both technical and non-technical audiences

Preferred Qualifications:

Experience managing and responding to Cyber Tasking Orders ( CTOs ) and Information Assurance Vulnerability Management ( IAVM ) directives across enterprise environments

Demonstrated experience leading or coordinating POA&M management, including tracking remediation status and verifying closure of vulnerabilities

Experience working with third-party assessors and auditors, including coordinating evidence collection, interviews, and follow-up actions

Experience performing self-assessments against STIGs and RMF controls , and developing corrective action plans

Hands-on experience with account management and auditing for user, admin, and service accounts in complex, multi-domain environments

Knowledge of and experience with patch and configuration management processes for large, distributed, and mission-critical enterprise systems

Familiarity with missile defense, command and control (C2), or space/defense systems environments

What We Can Offer You:

Northrop Grumman provides a comprehensive benefits package and a supportive work environment that encourages your growth, benefiting both employees and the company. The benefits are flexible and customizable, enabling you to choose options that suit your individual and family needs. Your benefits will include the following:

Health Plan

Savings Plan

Paid Time Off

Education Assistance

Training and Development

Flexible Work Arrangements

https://benefits.northropgrumman.com/us/en2/BenefitsOverview/Pages/default.aspx

#NGSpace

#COSpace

#NGFeaturedJobs

#C2BMC

#Cybersecurity

#CyberEngineering

Primary Level Salary Range: $113,900.00 - $170,900.00

The above salary range repre

Original posting on Northrop Grumman's site ↗

Listed on hirly, a job board. hirly is not the employer: Northrop Grumman is hiring for this role.

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job