Staff Engineer Systems - Cyber (Oklahoma City)
- Northrop Grumman
- Oklahoma City, Oklahoma
- Full Time
Please note that this opportunity is contingent on program funding. Start dates are determined after funding confirmation.
Northrop Grumman Aeronautics Systems is currently seeking a Staff Engineer Systems - Cyber for a new and exciting effort located in Oklahoma City, OK .
We're looking for a highly motivated, team oriented, individual that understands cybersecurity and the importance to our mission. The candidate will be responsible for the secure operations of cloud infrastructure, platforms, and software, including the installation, maintenance, and improvement of cloud computing environments. They will also help develop new designs and security strategies across cloud-based applications and Infrastructure as Code (IaC). The candidate will have hands-on deployment, integration, and configuration experience, and will act as a Cyber Subject Matter Expert (SME) to ensure compliance with the Risk Management Framework.
Responsibilities:
- Design, plan, and implement security tooling configurations to ensure compliance with NIST Special Publication (SP) 800-53, CNSSI 1253, and DoD RMF Knowledge Service guidance.
- Assess system security controls, validate the effective implementation of controls, identify vulnerabilities, and propose corrective measures.
- Document the results of Authorization and Accreditation (A&A) activities, prepare System Security Plans (SSPs), and maintain updated Plans of Action and Milestones (POA&Ms).
- Manage the implementation, automation, configuration, and maintenance of security tools, including centralized authentication solutions, IDS/IPS systems, and compliance baselines.
- Provide expert technical analysis of cybersecurity infrastructure challenges, developing innovative technical solutions tailored to customer requirements.
- Collaborate on technical reviews of requirements, as well as design and implementation plans prior to system deployment.
- Recommend and implement enhancements to security systems aimed at improving performance, reliability, and overall security posture, encompassing installation, upgrades, monitoring, troubleshooting, and configuration.
- Serve as an Information System Security Engineer (ISSE), leveraging advanced technical expertise to inform cyber engineering practices and ensuring adherence to cybersecurity disciplines such as COMSEC, COMPUSEC, EMSEC, OPSEC, and effective use of penetration tools and techniques.
Basic Qualifications:
Bachelors Degree in a STEM (Science, Technology, Engineering or Mathematics) discipline and 12 years of related engineering experience; OR a Masters degree in a STEM discipline and 10 years of related engineering experience; OR a PhD in a STEM discipline and 8 years of related engineering experience.
- Current DoD 8570 IAT Level II Certification (e.g., Security+ CE).
- Working knowledge of NIST 800-37 RMF artifacts, including SSPs, Security Control Traceability Matrices (SCTMs), SARs, RARs, and other documentation.
- Hands-on experience deploying and configuring Linux and Windows systems per DoD STIG requirements.
- Expertise in configuring Security Incident Event Monitoring (SIEM) and IDS/IPS tools such as ACAS, HBSS, and Splunk within Linux RedHat and Windows environments.
- Familiarity with vulnerability and compliance scanning tools such as Tenable.SC and SCAP.
- Knowledge of Cross-Domain Solution (CDS) technology and compliance requirements.
- Experience designing, integrating, maintaining, and retiring systems within cloud environments.
- Proficiency in scripting security processes to establish consistent, automated baselines across multiple systems for redundancy and efficiency.
- Active Secret Clearance with a Personnel Security Investigation (PR) completed within the last 5 years .
- Ability to obtain and maintain Special Program Access (SAP) prior to onboarding.
Preferred Qualifications:
- DoD 8570 IAT Level III Certification (e.g., CASP CE, CCNP, CISA, CISSP).
- Familiarity with DoD 8500-series and 8510.01 IA policy directives, including IATT and ATO requirements, and general approaches to cybersecurity.
- Exceptional communication (written and oral), negotiation, and interpersonal skills to effectively support ISSE initiatives and collaborate with engineering teams, management, clients, partners, and government stakeholders.
- Experience with next-generation security technologies including Dell, Cisco, Palo Alto, and other advanced networking equipment.
- Knowledge of Software Development Life Cycle (SDLC) processes and tools such as DOORS.
- Experience with cloud service providers like Azure and AWS, focusing on configuration, integration, and sustainability of cloud-based systems.