Northrop Grumman Cyber Info Assurance Anlyst 3/4 in Aurora, Colorado

At Northrop Grumman we develop cutting-edge technology that preserves freedom and advances human discovery. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We continue to innovate with developments from launching the first commercial flight to space, to discovering the early beginnings of the universe. Our employees are not only part of history, they're making history.

No matter the assignment, Northrop Grumman is committed to being a leader in Cyber, Logistics and Modernization, Autonomous Systems, C4ISR, and Strike. For us, it's about more than just performing. It means realizing the values that define us: responsibility, trust, integrity and protecting freedom worldwide. These values inspire and unite our people- who make everything we do possible.

The Engineering, Sciences and Technology (ES&T) organization pushes the boundaries of innovation, redefines engineering capabilities, and drives advances in various sciences. Our team is chartered with providing the skills, innovative technologies to develop, design, produce and sustain optimized product lines across the sector while providing a decisive advantage to the warfighter. Come be a part of our mission!

The Cyber team at Northrop Grumman Mission Systems (NGMS) is looking for you to join our team as a Cyber Information Assurance Analyst based out of Aurora.

Responsibilities will include, but are not limited to:

  • Ability to perform assessments of systems and networks within the networking environment or enclave and identify where those systems and networks deviate from acceptable configurations, enclave policy, or local policy. This is achieved through passive evaluations such as compliance audits and active evaluations such as vulnerability assessments.

  • Establishes strict program control processes to ensure mitigation of risks and supports obtaining certification and accreditation of systems.

  • Includes support of process, analysis, coordination, security certification test, security documentation, as well as investigations, software research, hardware introduction, and release, emerging technology research inspections and periodic audits.

  • Assists in the implementation of the Risk Management Framework (RMF), through the required government policy (i.e. NISPOM, JSIG, ICD etc., make recommendations on process tailoring, participate in and document process activities.

  • Performs analysis to validate established security requirements and to recommend additional security requirements and safeguards.

  • Supports the formal security test and evaluation (ST&E) required by each government accrediting authority through pretest preparations, participation in the tests, analysis of the results and preparation of required reports.

  • Documents the results of Assessment and Authorization activities and technical or coordination activity and prepare the system security plans and update the Plan of Actions and Milestones POA&M.

  • Periodically conducts a complete review of each system's audits and monitor corrective actions until all actions are closed.

  • Specific duties will included, but are not limited to:

  • Advise program leadership on Software nearing End-of-Life (EOL) and present mitigation plans for EOL software

  • Communicate with stakeholders, internal, and external on EOL and obsolescence issues

  • Automated and Manual hardening of the environment following STIG guidelines

  • Maintain user roles and accesses consistent with the paradigm of least-privilege

  • Examine potential security violations to determine if the Network Environment has been breached, assess the impact, and preserve evidence.

  • Support, monitor, test, and troubleshoot hardware and software IA problems pertaining to the Network environment.

  • Perform IA related support functions including installation, configuration, troubleshooting, assistance, and /or training, in response to agency requirements for the network environment.

  • Analyze patterns of non-compliance and take appropriate administrative or programmatic actions to minimize security risks and insider threats. Manage accounts, network rights, and access to network environment systems and equipment.

  • Analyze system performance for potential security problems. Assess the performance of IA security controls within the network environment.

  • Identify IA vulnerabilities resulting from a departure from the implementation plan or that were not apparent during testing.

  • Evaluate potential IA security risks and take appropriate corrective and recovery action.

  • Ensure that hardware, software, data, and facility resources are archived, sanitized, or disposed of in a manner consistent with system security plans, and requirements.

  • Perform system audits to assess security related factors within the Network environment.

  • Adhere to IS security laws and regulations to support functional operations for the Network environment. Implement response actions in reaction to security incidents.

  • Support security test and evaluations.

Additional Northrop Grumman Information:

Northrop Grumman has approximately 85,000 employees in all 50 states and in more than 25 countries, we strive to attract and retain the best employees by providing an inclusive work environment wherein employees are receptive to diverse ideas, perspectives and talents to help solve our toughest customer challenges: to develop and maintain some of the most technically sophisticated products, programs and services in the world.

Our Values . The women and men of Northrop Grumman Corporation are guided by Our Values. They describe our company as we want it to be. We want our decisions and actions to demonstrate these Values. We believe that putting Our Values into practice creates long-term benefits for shareholders, customers, employees, suppliers, and the communities we serve.

Our Responsibility . At Northrop Grumman, we are committed to maintaining the highest of ethical standards, embracing diversity and inclusion, protecting the environment, and striving to be an ideal corporate citizen in the community and in the world.

You'll Bring These Qualifications:

This is a dual level requisition

  • Level 3: Bachelor's Degree with 5 years of relevant work experience: Master's Degree with 3 years of relevant work experience, or PhD. 4 years of relevant experience in lieu of a degree

  • Level 4 : Bachelor's Degree with 9 years of relevant work experience: Master's Degree with 7 years of relevant work experience, or PhD with 4 years of relevant experience. 4 years of relevant experience in lieu of a degree

  • Working experience maintaining classified systems audits and corrective actions (POA&Ms)

  • Proficiency in administration of both Unix/Linux based environments and Windows environments

  • Current and Active SCI Clearance

  • In-scope CI polygraph

  • Systems Administration experience

  • IAM Level-1 Certification (CAP, GSLC or SEcurity + CE) or ability to obtain within 6 months.

These Qualifications Would be Nice to Have:

  • Bachelor's or Master's degree with a technical emphasis (e.g. Information Systems, Information Technology, Computer Science).

  • CISSP

  • Amazon Web Services (AWS) certifications

  • Working experience implementing and performing Risk Management Framework (RMF) assessments on classified systems/networks.

  • Proficiency in administration of both Unix/Linux based environments and Windows environments

  • Full scope polygraph

  • Experience with security hardening, assessment and reporting tools (SCAP, ACAS, HBSS, Nessus, XACTA).

What We Can Offer You:

Northrop Grumman provides a comprehensive benefits package and a work environment that encourages your growth and supports the mutual success of our people and our company. Northrop Grumman benefits give you the flexibility and control to choose the benefits that make the most sense for you and your family. Your package will include the following:

  • Health Plan

  • Savings Plan

  • Paid Time Off

  • Additional benefits

  • Education Assistance

  • Training and Development

https://benefits.northropgrumman.com/us/en2/BenefitsOverview/Pages/default.aspx

Northrop Grumman is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO/AA and Pay Transparency statement, please visit www.northropgrumman.com/EEO . U.S. Citizenship is required for most positions.