Colorado Springs, CO

Salary
$91,800–$170,900from the description
Posted
Aug 11, 2026
Location
Colorado Springs, CO
Last confirmed open
Sep 24, 2026

What this job asks for AI summary

A Cyber Systems Engineer role (Level 2 or 3) at Northrop Grumman's Space Sector in Colorado Springs, focused on RMF-based security assessment and authorization activities for government programs. Day-to-day work involves conducting compliance audits, maintaining eMASS records, preparing A&A documentation, and performing vulnerability assessments against DoD cybersecurity standards. Suited to candidates with an active Secret clearance and a DoD 8570 IAT II certification.

Mid level · 2+ years · Colorado Springs, CO · Bachelor's required · Secret clearance · Full-time

Must have (4)
STIG Viewer, Scap, Evaluate Stig or Stig ManagerRMFeMASSSecurity+, Ccna Security, Gsec or Sscp
Nice to have (12)
ACAS, Nessus or Tenable.scLinuxSTIG hardeningSIEMRHELAnsible or PythonJiraVMwareElastic StackCISSPOSCP, Osce, Gpen, Gwapt or GxpnXylok

“or” means any one of them counts — you don't need all of them.

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
Security+45%RMF40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $133,758 (middle half $108,740–$165,225). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 12, 2026. It is a model, not a headcount.

Why we read it this way (9)

This posting covers two levels simultaneously: Level 2 (2+ years experience, salary $91,800–$137,600) and Level 3 (5+ years experience, salary $113,900–$170,900). The minimum experience and salary figures reflect Level 2; the maximum salary reflects Level 3. Seniority is assessed at Mid (Level 2 baseline), though a Level 3 hire would be Senior.

The DoD 8570 IAT II certification requirement names Security+, CCNA Security, GSEC, and SSCP as acceptable options; these are captured as alternatives on the Security+ skill entry.

STIG Viewer, SCAP, Evaluate-STIG, and STIG Manager are listed together as examples of compliance audit tools in the required duties section; they are captured as alternatives on a single skill entry.

ACAS/Nessus/tenable.sc appear under Preferred Qualifications and are marked accordingly.

Ansible and Python appear together under Preferred as automation tools for STIG/SCAP scanning; captured as alternatives on a single preferred skill.

The role is contingent on program award and the candidate obtaining final clearances and program access within a reasonable timeframe.

The posting notes 10% travel in the header but lists 25% CONUS/OCONUS travel as a preferred qualification — these figures conflict; the header figure (10%) is the stated requirement.

Ignored 3 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): DoD 8570 IAT II, NIST SP 800-53, NIST SP 800-115.

Requires a Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗