Northrop Grumman · Dulles, VAremote

Salary
$114,000–$171,000from the description
Posted
Jul 14, 2026
Location
Dulles, VA
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A full-time, on-site cybersecurity analyst role focused on the assessment and authorization of classified information systems. Day-to-day work involves continuous monitoring, security audits, vulnerability analysis, Risk Management Framework documentation, and supporting formal security testing against government accreditation requirements. Suited to experienced cybersecurity professionals holding an active TS/SCI clearance with a recent polygraph and relevant IAM-level certifications.

Senior level · 5+ years · Remote · TS/SCI clearance · Full-time

Advertised as Principal, but the requirements read as Senior.

Must have (3)
Risk Management FrameworkAssessment and AuthorizationCISSP, Cism, Cciso, Casp+, Gslc, Cap or Cgrc
Nice to have (7)
ACASNessusSplunkSCAPeMASSDISA STIGsCNSSI 1253

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
Risk Management Framework40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (12)

The job posting explicitly states this role is on-site full-time at Dulles, VA and 'does not offer any virtual or telecommute working options.' Remote=true has been set at the caller's instruction, overriding the posting's stated requirement.

The metro (Washington-Arlington-Alexandria, DC-VA-MD-WV) is retained for reference since the posting names Dulles, VA as the work location, but the caller has directed that the candidate pool be treated as national.

The clearance requirement is TS/SCI with a current/recent polygraph adjudicated within the last 5 years — both are hard gates per the posting.

Degree requirement is set to None because the JD accepts a range of degree levels (Master's, Bachelor's, Associate's, or High School/GED) each paired with increasing years of experience, making no single degree a hard gate.

Total years minimum is set to 5, reflecting the lowest experience threshold that pairs with a Bachelor's degree (the most common baseline); the posting's tiered structure means the true floor could be as low as 3 years (with a Master's).

The IAM Level II or higher certification (CISSP, CISM, CCISO, CASP+, GSLC, CAP, CGRC, etc.) is a hard gate per DoD 8140/8570 compliance requirements stated in Basic Qualifications. CISSP is listed as the primary with common equivalents in alternatives.

ACAS, Nessus, Splunk, SCAP, eMASS, NIST SP 800-53, DISA STIGs, and CNSSI 1253 all appear under Preferred Qualifications only.

Current Special Program Access (SAP/SAR) is listed as 'ideal' under Preferred Qualifications — not a hard gate.

Seniority is assessed as Senior despite the 'Principal' title: the experience requirements (3–9 years depending on degree) and scope of work are consistent with a Senior-level individual contributor role. The 'Principal' label appears to be an internal Northrop Grumman job family designation rather than an indication of org-wide technical authority.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Security Test and Evaluation, NIST SP 800-53.

Requires a TS/SCI clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗