Principal Cybersecurity Analyst

Northrop Grumman

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Roy, UT
Salary
$108,800–$163,200 / yr
Employment
Full-time
Posted
5 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $158k
This role $136k
$99k most similar roles pay here $204k

This role pays less than 72% of similar roles. Most pay $131,475–$184,325 — the shaded band above. At the midpoint, this role pays about $136k versus about $158k for comparable roles.

Based on 240 similar postings.

Employer

About Northrop Grumman

Northrop Grumman is a leading global aerospace and defense technology company providing systems in autonomous systems, cyber, C4ISR, space, strike, and logistics. Industry: Aerospace & Defense

Northrop Grumman currently has 347 open roles on FindRole.

Listed pay typically runs $114,000–$171,000 across 333 roles with salary data.

Most-posted roles

View all roles at Northrop Grumman

At a glance

TL;DR · Principal Cybersecurity Analyst

As a Principal Cybersecurity Analyst-19970 within the Cyber Security & Infrastructure Engineering group, you will serve as a technical compliance lead supporting the Sentinel program. You will be responsible for implementing, hardening, and monitoring complex cybersecurity baselines across enterprise, mission, and classified environments. Your daily work involves analyzing NIST SP 800-53 security controls and CNSSI 1253 overlays to translate agency requirements into automated audits and Risk Management Framework artifacts. You will manage the RMF lifecycle, perform system hardening on Windows and Red Hat Enterprise Linux platforms using DISA STIGs, and execute vulnerability scanning via Tenable ACAS, Trellix, and Splunk. To ensure continuous compliance, you will develop automation scripts using PowerShell, Python, and Ansible to mitigate configuration drift while managing technical vulnerabilities and preparing plans of action for government inspections.

What you'll do

  • Implement and tailor NIST SP 800-53 security controls and CNSSI 1253 overlays across classified and unclassified networks.
  • Define and validate Organization-Defined Parameters (ODPs) to meet requirements for Authorizing Officials and Security Control Assessors.
  • Execute the Risk Management Framework (RMF) lifecycle by preparing Security Assessment Plans, Traceability Matrices, and System Security Plans.
  • Perform system hardening across Windows, Linux, and storage architectures using DISA STIGs and SCAP compliance tools.
  • Conduct vulnerability scanning and remediation tracking using enterprise tools like Tenable ACAS, Trellix, and Splunk.
  • Develop automated scripts in PowerShell, Python, or Ansible to monitor configurations and prevent configuration drift.
  • Author detailed Plans of Action and Milestones (POA&M) to mitigate identified technical vulnerabilities.
  • Support government inspections and Security Test & Evaluation events to maintain program Authorizations to Operate (ATO).

What we're looking for

  • Must be a U.S. citizen.
  • Must possess an active U.S. Government DoD Secret security clearance at time of application.
  • Bachelor's degree with 5 years of experience, or 3 years with Master's, or 1 with PhD; 4 additional years of experience may be considered in lieu of a degree.
  • Must hold an active DoD 8140/8570 compliant IAM Level II or IASAE Level I/II baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP).
  • Demonstrated hands-on experience executing RMF processes and applying NIST SP 800-53 security controls and Organization-Defined Parameters within DoD or IC programs.
  • Proven experience building and maintaining RMF Body of Evidence artifacts including SSP, SCTM, and POA&M.
  • Experience configuring DISA STIGs, analyzing ACAS/Nessus vulnerability reports, and using SIEM tools like Splunk.
  • Advanced certifications (CISSP, CASP+ CE, CISM, or AWS/Azure Security Specialty) and experience with scripting/automation tools are preferred.

More like this

Similar roles

Cybersecurity Analyst

Northrop Grumman

Roy, UT 5 days ago $79,300–$118,900
RMF NIST SP 800-53 DISA STIGs ACAS Tenable Nessus SCAP Trellix HBSS DevSecOps Docker Kubernetes Python PowerShell Ansible Terraform Linux Windows Server OpenShift
2+ yrs exp

Staff Cybersecurity Analyst

Northrop Grumman

Roy, UT 7 days ago $152,900–$229,300
RMF NIST SP 800-53 CNSSI 1253 Security Architecture System Hardening DevSecOps Splunk Tenable ACAS Rapid7 Trellix Python PowerShell Ansible Windows Server Red Hat Enterprise Linux SIEM Vulnerability Assessment DISA STIGs
10+ yrs exp

Principal Cybersecurity Analyst

Northrop Grumman

Sunnyvale, CA 10 days ago $114,000–$171,000
Risk Management Framework Assessment and Authorization NIST ACAS NESSUS SPLUNK SCAP System Audits Vulnerability Scanning Security Test and Evaluation CISSP CISM CAP/CGRC CASP+ HCISPP
5+ yrs exp

Principal Cybersecurity Analyst

Northrop Grumman

Roy, UT 13 days ago $98,400–$147,600
Cross‑Domain Solutions (CDS RMF NIST ACAS Nessus Splunk Trellix SCAP JSIG DAAG Security+ CySA+ GICSP GSEC CND SSCP
5+ yrs exp

Senior Principal Classified Cybersecurity Analyst

Northrop Grumman

Colorado Springs, CO 14 days ago $129,300–$193,900
RMF NIST Linux (RHEL) eMass SIEM ACAS NESSUS SPLUNK SCAP Trellix Elk Vulnerability Scanning System Audit Risk Management Framework SCTM
8+ yrs exp

Principal Classified Cybersecurity Analyst

Northrop Grumman

Edwards, CA 49 days ago $114,000–$171,000
Risk Management Framework NIST ACAS Nessus Splunk Trellix SCAP JSIG DAAG Cybersecurity Information Systems Continuous Monitoring SCTMs SSPs
5+ yrs exp