Find The RightJob.
Northrop Grumman Space Systems (NGSP) is seeking a Cyber Systems Engineer - Level 3 or 4 to join our team at our facility in Aurora, Colorado.
Job responsibilities will include, but not be limited to, the following:
Support the architecture and design of baked in cybersecurity requirements and protections
Plan, implement, and perform assessment of allocated security controls, polices, and processes compliance
Translate allocated security controls into system and segment level requirements
Provide cybersecurity system engineering implementation guidance and oversight to technical teams/implementers
Review and Assess stakeholder security objectives, protection needs and concerns, security requirements, and associated verification/validation methods
Provide security considerations to inform systems engineering efforts with the objective to reduce errors, flaws, and weakness that may constitute security vulnerability leading to unacceptable asset loss and consequences
Identify, quantify, and evaluate the costs/benefits of security functions and considerations to inform analysis of alternatives, engineering trade-offs, and risk treatment decisions
Author, support and maintain cybersecurity program documentation & RMF package documentation: Cybersecurity Strategies, System Security Plans, Continuous Monitoring of all Program assets, Plans, Risk Assessment Report, Security Control Traceability Matrix, etc.
Document findings (POA&M’s) and perform scanning/assessment tasks on Program assets
This requisition may be filled at a higher job grade based on the qualifications listed below.
This requisition may be filled as either a Level 3 or a Level 4.
Basic Qualifications for a Level 3:
Bachelor's degree with 5 years of relevant experience; Master's degree with 3 years of relevant experience; PhD with 0 years of relevant experience. An additional 4 years of relevant experience may be considered in lieu of a degree.
Active Top Secret/SCI security clearance required at time of application
Direct experience developing RMF assessment and authorization documentation
Direct experience with Security Technical Implementation Guides (STIGs)
Experience with RMF (NIST 800-37) accreditation functions, including documentation, scanning, assessment, Plan of Action and Milestones (POAM) management, and all steps of the RMF process
Direct experience assessing the Program's system security posture in compliance with customer requirements and directives.
Experience with requirements development & derivation from allocated controls, system integration & test and validation and verification.
Experience developing Security CONOPs and SSPs
Experience with integrating Cyber Systems Engineering requirements with Program System Development Life Cycle (SDLC) initiatives
Experience of adjusting commercial security methodologies and technologies within sensitive and proprietary customer environments in accordance with NIST 800-53
Ability to apply analytical and evaluative methods and techniques to issues or studies concerning the efficiency and effectiveness of Cybersecurity implementation
Ability to communicate clearly and collaborate with both internal teams, internal management and external customers
Experience of Department of War (DoW)/Intelligence Community (IC) System Security Engineering activities
Possession of Security+ Certification or Certified Information Systems Security Professional (CISSP) Certification
Basic Qualifications for a Level 4:
Bachelor's degree with 8 years of relevant experience; Master's degree with 6 years of relevant experience; PhD with 4 years of relevant experience. An additional 4 years of relevant experience may be considered in lieu of a degree.
Active Top Secret/SCI security clearance required at time of application
Direct experience developing RMF assessment and authorization documentation
Direct experience with Security Technical Implementation Guides (STIGs)
Experience with RMF (NIST 800-37) accreditation functions, including documentation, scanning, assessment, Plan of Action and Milestones (POAM) management, and all steps of the RMF process
Direct experience assessing the Program's system security posture in compliance with customer requirements and directives.
Experience with requirements development & derivation from allocated controls, system integration & test and validation and verification.
Experience developing Security CONOPs and SSPs
Experience with integrating Cyber Systems Engineering requirements with Program System Development Life Cycle (SDLC) initiatives
Experience of adjusting commercial security methodologies and technologies within sensitive and proprietary customer environments in accordance with NIST 800-53
Ability to apply analytical and evaluative methods and techniques to issues or studies concerning the efficiency and effectiveness of Cybersecurity implementation
Ability to communicate clearly and collaborate with both internal teams, internal management and external customers
Experience of Department of War (DoW)/Intelligence Community (IC) System Security Engineering activities
Possession of Security+ Certification or Certified Information Systems Security Professional (CISSP) Certification
Preferred Qualifications:
Expertise with all aspects of Systems Security Engineering as defined in NIST SP 800-160
System security architecture experience
Experience working with DOORS and CAMEO
Security related tool suites in DevSecOps pipelines
Experience in configuring and implementing Rapid 7, Trellix and Splunk among other industry standard technologies.
Experience in configuring and deploying Cross Domain Solutions (CDS)
Experience in Communications Security (COMSEC)
Experience working on a multidisciplinary team and developing technical proposals
Experience working in an Agile execution framework
DoD 8500-series and 8510.01 IA policy directives, approaches to cyber security, knowledge of security procedures, IATT and ATO requirements.
Operating systems certificate (Windows/Linux)
Similar jobs
No similar jobs found
© 2026 Qureos. All rights reserved.