Principal Senior Penetration Tester

Northrop Grumman

Confirmed live 2 days ago Low trust

Quick summary

Work type
On-site
Location
San Antonio, TX
Salary
$103,600–$155,400 / yr
Posted
52 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $182k
This role $130k
$88k most similar roles pay here $251k

This role pays less than 90% of similar roles. Most pay $154,025–$209,212 — the shaded band above. At the midpoint, this role pays about $130k versus about $182k for comparable roles.

Based on 240 similar postings.

Employer

About Northrop Grumman

Northrop Grumman is a leading global aerospace and defense technology company providing systems in autonomous systems, cyber, C4ISR, space, strike, and logistics. Industry: Aerospace & Defense

Northrop Grumman currently has 367 open roles on FindRole.

Listed pay typically runs $114,900–$176,300 across 353 roles with salary data.

Most-posted roles

View all roles at Northrop Grumman

At a glance

TL;DR · Principal Senior Penetration Tester

The Principal/Sr Principal Penetration Tester joins the Northrop Grumman Mission Systems team as a Cyber Protection Engineer to conduct penetration testing and cybersecurity assessments. This role involves evaluating system security architecture, identifying vulnerabilities, and mapping attack paths across cloud-native and hybrid environments. The engineer will perform offensive security operations targeting CI/CD pipelines, containerized workloads, and enterprise services within AWS and Azure platforms. Key responsibilities include developing attack methodologies, validating security controls, and providing remediation guidance. Required technical skills include proficiency in Python, Bash, or PowerShell scripting; experience with Docker, Kubernetes, and VMware; and knowledge of Windows and Linux systems. The role addresses the critical challenge of securing cloud infrastructure and enterprise services while ensuring compliance with cybersecurity frameworks like RMF and STIGs to protect complex system security layouts from evolving threat vectors.

What you'll do

  • Conduct cloud-focused penetration testing and security assessments across hybrid environments.
  • Perform offensive security operations targeting CI/CD pipelines, containerized workloads, and enterprise services.
  • Identify vulnerabilities, attack paths, and potential threat vectors within AWS and Azure platforms.
  • Develop attack methodologies, testing procedures, and technical analysis for security evaluations.
  • Evaluate cloud security posture and validate existing security controls.
  • Provide technical reporting, operational recommendations, and remediation guidance to stakeholders.
  • Use scripting and automation languages like Python or Bash to support testing workflows.

What we're looking for

  • US Citizenship is required.
  • Active US Government Top Secret Security Clearance is required with the ability to obtain an SCI.
  • Must possess a DoD 8570 Certification for IAT Level II or higher (Sec+, CCNA, CySA+, or CND).
  • For Principal level: Bachelor's degree and 5 years of experience, Master's and 3 years, or 9 years of experience without a degree.
  • For Sr. Principal level: Bachelor's degree and 8 years of experience, Master's and 6 years, or 12 years of experience without a degree.
  • Experience conducting penetration testing, vulnerability analysis, or security assessments against cloud, enterprise, or hybrid environments.
  • Proficiency with cloud platforms (AWS/Azure), CI/CD pipelines, containerization (Docker/Kubernetes), and scripting languages like Python, Bash, or PowerShell.
  • Knowledge of Windows/Linux systems, networking fundamentals, offensive security methodologies, and cybersecurity compliance frameworks.

More like this

Similar roles

Principal Senior Principal Cyber Protection Engineer

Northrop Grumman

Rome, NY 3 days ago $103,600$155,400
AWS Azure Docker Kubernetes Terraform Python Bash PowerShell CI/CD VMware Splunk Sentinel ELK CrowdStrike Infrastructure‑as‑Code Penetration Testing Vulnerability Management RMF STIGs SCAP
8+ yrs exp

Cyber Protection Engineer

Northrop Grumman

Rome, NY 8 days ago $83,400$125,200
AWS Azure Docker Kubernetes Terraform Ansible Python Bash PowerShell CI/CD GitHub Actions GitLab CI/CD Jenkins Azure DevOps VMware Splunk Sentinel ELK CrowdStrike RMF
2+ yrs exp

Senior Penetration Tester

CoStar Group

Arlington, VA 74 days ago $115,000$203,000
Penetration Testing Python PowerShell C# Java JavaScript Go AWS Kubernetes CI/CD Active Directory Burp Suite OWASP ZAP Nmap Bloodhound Metasploit Cobalt Strike Sliver Mythic MITRE ATT&CK Secure Code Review
6+ yrs exp

Penetration Tester

Leidos

Huntsville, AL 10 days ago $87,100$157,450
Penetration Testing Python Bash PowerShell Burp Suite Metasploit Cobalt Strike Nmap OWASP Top 10 AWS Azure GCP REST SOAP GraphQL TCP/IP Vulnerability Assessment ScoutSuite Prowler
4+ yrs exp

Expert Penetration Tester

IBM

26 days ago
Penetration Testing NMap Nessus Metasploit BurpSuite Nikto Tcpdump LLMs Unix Windows TCP/IP VLANs Firewalls Intrusion Detection Intrusion Prevention SQL Databases Containers C C++ Java C#

Principal System Integration and Test Engineer

Motorola Solutions

Irvine, CA 164 days ago $180,000$220,000
Embedded Firmware C++ Python Embedded Linux Scripting TCP/IP Signal Generators Spectrum Analyzers Logic Analyzers Digital Communication System Integration Hardware Testing Field Testing Debugging Troubleshooting
10+ yrs exp