Principal Cyber Systems Engineer (ISSE) (26-207 & 26-344) at Northrop Grumman
Colorado Springs, CO
$113,900–$170,900from the description
Aug 18, 2026
Colorado Springs, CO
Sep 25, 2026
What this job asks for AI summary
A cybersecurity engineering role on the C2BMC missile defense program at Schriever Space Force Base, supporting the tuning, integration, and optimization of security tools such as ESS/HBSS, Elastic, ConfigOS, and Tanium. The position involves building custom security dashboards, managing tool upgrades and deployments, and performing software assurance analysis. Candidates must hold an active Top Secret clearance and a DoD 8140 IAT Level II or higher certification at time of application. On-site only; no remote work.
Senior level · 5+ years · Colorado Springs, CO · Top Secret clearance · Full-time
Advertised as Principal, but the requirements read as Senior.
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $133,758 (middle half $108,740–$165,225). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Aug 20, 2026. It is a model, not a headcount.
Why we read it this way (10)
The title 'Principal' maps to Northrop Grumman's internal job code (26-207 & 26-344) and does not reflect org-wide technical authority in the BLS sense; the actual scope and experience floor (5 years with a bachelor's, or 9 years without a degree) is consistent with a Senior-level role.
Degree requirement is marked None because the posting explicitly accepts 9 years of relevant experience as an alternative to any degree.
The minimum experience floor is 5 years (with a bachelor's degree); 3 years is accepted with a master's, and 9 years with no degree — 5 years is used as the overall years minimum per the most common path.
Splunk is listed alongside Elastic in the qualifications section ('Splunk/Elastic'); Elastic is used as the primary skill name with Splunk as an alternative, since both are named as interchangeable in context.
'Audit tool scripting' is retained as a required skill because the posting explicitly calls out 'configuring, running, and scripting audit tools' under Basic Qualifications, though no specific scripting language is named.
Software Assurance (SwA) static and dynamic code analysis is required; Fortify is the only named tool and is captured as the concrete skill.
The DoD 8140 IAT Level II certification (e.g., Security+ CE, CCNA-Security, CySA+, CND) is an explicit hard gate — candidates must hold it at time of application.
SOC classification is 15-1212 (Information Security Analysts) because the primary day-to-day work is security tool tuning, threat detection, dashboard creation, and software assurance analysis. 15-1244 is noted as a runner-up given the significant Windows/RHEL system administration component.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): Windows administration.
Requires a Top Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.