Confirmed on the employer's own hiring board on Sep 24, 2026. First seen by Alion on Sep 23, 2026. Northrop Grumman scores A on the Alion truth index.
Description
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.Northrop Grumman Defense Systems is seeking a Cybersecurity Analyst - 19971. This position is located in Roy, UT and supports the Sentinel program.
You will lead Risk Management Framework (RMF) activities, assess system vulnerabilities, implement DISA STIGs, and ensure strict compliance with NIST SP 800-series standards and DoD instruction set directives.
________________________________________
Key Responsibilities
- RMF Accreditation & Compliance: Execute the Risk Management Framework (NIST SP 800-37 / DoDI 8510.01) steps from categorization through Authorization to Operate (ATO) and continuous monitoring.
- Systems Security Engineering: Apply NIST SP 800-160 principles to design, implement, and maintain system security architectures for defense applications.
- Control Evaluation & Hardening: Implement and tailor security controls based on NIST SP 800-53 rev 5 and NIST SP 800-171. Apply DISA Security Technical Implementation Guides (STIGs) across Linux, Windows Server, and cloud environments.
- Vulnerability & Compliance Scanning: Utilize tools such as ACAS (Tenable Nessus), DISA Security Content Automation Protocol (SCAP), and Trellix/HBSS/ESS to execute automated vulnerability scans, document deviations, and oversee remediation.
- Artifact Authoring: Draft, review, and maintain system accreditation artifacts including System Security Plans (SSP), Security Assessment Reports (SAR), Plan of Action & Milestones (POA&M), and Security Control Traceability Matrices (SCTM).
- Cross-Functional Support: Partner with software, systems engineering, and program teams to integrate security into the Agile software development lifecycle (DevSecOps) and containerized workloads
Position Benefits:
As a full-time employee of Northrop Grumman Space Systems, you are eligible for our robust benefits package including:
- Medical, Dental & Vision coverage
- 401k
- Educational Assistance
- Life Insurance
- Employee Assistance Programs & Work/Life Solutions
- Paid Time Off
- Health & Wellness Resources
- Employee Discounts
This position’s standard work schedule is a 9/80. The 9/80 schedule allows employees who work a nine-hour day Monday through Thursday to take every other Friday off. This role may offer a competitive relocation assistance package.
Basic Qualifications:
Bachelor's degree with 2 years of experience, or Master's degree; 4 additional years of experience may be considered in lieu of a completed degree.
Must be a US Citizen and have an active U.S. Government DoD Secret security clearance at time of application, current and within scope, with an ability to obtain and maintain Special Access Program (SAP) approval within a reasonable period of time, as determined by the company to meet its business need.
DoD 8570/8140 Certification: Active IAM Level I or IAT Level II certification (e.g., Security+ CE, CySA+, CCNA Security, GICSP, or SSCP).
Demonstrated, hands-on experience applying NIST SP 800-53 and NIST SP 800-37 (RMF) frameworks in a DoD or Intelligence Community (IC) environment.
Direct experience with DISA STIG implementation, auditing, and hardening practices.
Proficiency in executing vulnerability scans with tools like ACAS, Nessus, or Rapid7
Preferred Qualifications:
- Advanced certifications such as CISSP, CASP+ CE, CISM, or AWS/Azure Security Specialty.
- Experience with Systems Security Engineering frameworks defined in NIST SP 800-160.
- Working knowledge of cross-domain solutions, cryptographic equipment, or space/ground segment defense systems.
- Experience with scripting and automation tools (e.g., Python, PowerShell, Ansible, or Terraform) to automate compliance verification.
- Familiarity with container security (e.g., Docker, Kubernetes, OpenShift) and hardening within DoD Iron Bank or similar repositories.

