Cyber Information Sys Security 3
Northrop Grumman is seeking a Cyber Information Systems Security team member to join our Classified Information Systems Security (CISS) team in Orlando Florida. The CISS organization has overall responsibility for providing information systems security compliance oversight to all Northrop Grumman classified systems under their respective purview.
The CISS team performs security compliance assessments of systems and networks to ensure their systems and networks comply with all applicable policies and procedures through oversight of strict program control processes to ensure mitigation of risks and supports obtaining certification and accreditation of systems. Includes support of process, analysis, coordination, security certification test, security documentation, as well as investigations, software research, hardware introduction and release, emerging technology research inspections and periodic audits. Ensures the implementation of the Risk Management Framework (RMF), through the required government policy (i.e., NISPOM, JSIG, ICD etc…), make recommendations on process tailoring, participate in and document process activities. Perform analyses to validate established security requirements and to recommend additional security requirements and safeguards. Support the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results and preparation of required reports. Document the results of Assessment and Authorization activities and technical or coordination activity and prepare the System Security Plans and update the Plan of Actions and Milestones POA&M. Periodically conduct a complete review of each system's audits and monitor corrective actions until all actions are closed.
A strong candidate will have great customer service skills, familiarity with DoD STIG's, security compliance tools, auditing tools and performing system security audits and assessments. The position requires critical thinking/analytical skills, creativity, with a focus on ethics, integrity, quality, and good oral and written communication skills.
Responsibilities will include, but are not limited to:
- Examine systems to determine security posture and compliance readiness.
- Perform IA related support functions including troubleshooting, assistance, and/or training.
- Analyze patterns of non-compliance and take appropriate administrative or programmatic actions.
- Attain and maintain Risk Management Framework (RMF) authorizations as directed by the Defense Security Service (DSS).
- Ensure that hardware and software baselines are correct and continuously monitored form accuracy.
- Perform system audits to assess security related factors.
- Verify access control lists are compliant with policy.
- Verify that applicable patches including IAVAs, IAVBs, and TAs have been applied.
- Adhere to IS security laws and regulations to support functional operations.
- Support Security Test and Evaluations.
- Bachelor's degree with 5 years of relevant experience or master's degree with 3 years of experience
- 8570 IAM Level II Certification (CISSP, CAP, CASP CE, CISM, GSLC).
- Current Secret Clearance required.
- CISSP or an IAM Level II certification (CISSP, CISM, GSLC, CASP CE, CAP).
- Experience with security hardening, assessment and reporting tools (SCAP, ACAS, HBSS, Nessus, XACTA).
Northrop Grumman is committed to hiring and retaining a diverse workforce. We are proud to be an Equal Opportunity/Affirmative Action Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO/AA and Pay Transparency statement, please visit www.northropgrumman.com/EEO. U.S. Citizenship is required for most positions.
Meet Some of Northrop Grumman's Employees
Jacqueline operates on power electronics for Northrop Grumman’s space application projects. She meets with engineering groups, chats with customers, and works on circuit analysis.
Back to top