Vacancy expired!
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.
Northrop Grumman Enterprise Services is seeking a Principal Cyber Information Systems Security Analyst to function as an Information System Security Manager (ISSM) for the Bacchus facility located in Magna, UT. This ISSM will support the SAP and Collateral Programs.Responsibilities will include, but not be limited to, the following:- Collaborate with multiple suppliers in a matrixed environment in support of various ATO activities .
- Perform assessments of systems and networks within a Cloud environment or enclave and identify where those systems and networks deviate from acceptable configurations, enclave policy, or local policy; this is achieved through passive evaluations such as compliance audits and active evaluations such as vulnerability assessments.
- Establish strict program control processes to ensure mitigation of risks and support obtaining certification and accreditation of systems; this includes support of process, analysis, coordination, security certification test, security documentation, as well as investigations, software research, hardware introduction and release, emerging technology research inspections, and periodic audits.
- Assist in the implementation of the required government policy (i.e., JSIG, DAAPM) and make recommendations on process tailoring, and participate in and document process activities.
- Perform analyses to validate established security requirements and to recommend additional security requirements and safeguards.
- Support the formal Security Test and Evaluation (ST&E) required by each government authority through pre-test preparations, participation in the tests, analysis of the results, and preparation of required reports.
- Document the results of Assessment and Authorization activities and technical or coordination activity and prepare the system Security Plans and update the Plan of Actions and Milestones POA&M.
- Periodically conduct a complete review of each system's audits and monitor corrective actions until all actions are closed
- Master's degree with 3 years of experience; OR a Bachelor's degree with 5 years of experience; OR an Associates degree with 7 years of experience; OR a High School Diploma/GED with 9 years of experience is required
- Must have a DoD 8570 IAM level II, or level III, security certification (examples: CAP, CASP CE, CISM, GSLC, CISSP-Associate, or CISSP); OR must have the ability to obtain the certification within 6 months of start
- Candidates must have a current DOD Top Secret security clearance to include a closed investigation date completed within the last 6 years OR be enrolled in the DOD Continuous Evaluation Program (CEP), in order to be considered
- Must have the ability to obtain, and maintain, access to Special Programs as condition of continued employment
- The ideal candidate will have a Bachelor's degree in Cyber Security, a CASP CE, and 6 years of experience with Certification and Accreditation of classified systems and Risk Management Framework
- Knowledge of ACAS, NESSUS, SPLUNK, SCAP, POA&Ms, NIST, system audits, vulnerability scanning, and RMF package development preferred
- Demonstrated expert knowledge of cybersecurity practices, network technologies, and system development life-cycles, in addition to an understanding of information technology infrastructure management/monitoring and applications
- Experience developing guidelines, monitoring policies, and enforcing standards for cybersecurity frameworks and industry best practices supporting National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, CNSSI 1253, and DoD Risk Management Framework (RMF).
- Diverse classified information systems security/information assurance background
- Amazon Web Services Certification and experience
- Strong verbal and written communication skills
- Active DoD Top Secret security clearance with SAP access preferred
Vacancy expired!