Northrop Grumman · Jessup, MD

Salary
$125,300–$187,900from the description
Posted
Jun 30, 2026
Location
Jessup, MD
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A cybersecurity systems engineering role supporting a defense missile program, focused on translating weapon system requirements into secure architectures and designs. Day-to-day work involves decomposing cybersecurity requirements, analyzing attack surfaces, guiding security architecture decisions, and supporting risk management framework (RMF) authorization activities. Suits engineers with a background in systems engineering and DoD cybersecurity standards such as NIST 800-160 and RMF/NIST 800-37.

Senior level · 5+ years · Baltimore-Columbia-Towson, MD · Top Secret clearance · Full-time

Advertised as Principal, but the requirements read as Senior.

Must have (5)
NIST 800-160RMF (NIST SP 800-37)CNSSI 1253DoD 8570CISSP or Iasae Ii Certification
Nice to have (6)
MBSECameoIBM DOORSDevSecOpsAgileISSEP or Issap

“or” means any one of them counts — you don't need all of them.

Posted 6 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
RMF (NIST SP 800-37)40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $141,208 (middle half $106,798–$194,505). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (7)

The role is titled 'Principal Cyber Systems Engineer' but the actual requirements (5 years with a Bachelor's, or 9 years without a degree, with semi-independent work under senior direction) support a Senior-level band rather than Principal. 'Principal' here appears to be Northrop Grumman's internal grade label rather than an org-wide technical authority role.

The clearance situation is layered: an active Secret clearance is a hard gate at start; the posting states the candidate must be *able to obtain* a Top Secret (and SAP access), but does not require an active TS on day one. Clearance_required is set to TopSecret to reflect the stated start requirement in the posting header ('CLEARANCE REQUIRED FOR START: Yes / CLEARANCE TYPE: Top Secret'), which supersedes the body text suggesting Secret is sufficient at hire.

The CISSP/IASAE II certification is listed as a hard requirement to be obtained within six months of hire, not necessarily at time of application — flagged as must-have given the firm 'must be able to obtain' language and the explicit DoDI 8570/8140 compliance obligation.

ISSEP and ISSAP appear under Preferred Qualifications as IASAE Level III certifications.

The role has multiple places of performance (Annapolis Junction MD, Roy UT, San Antonio TX, Redondo Beach CA, Huntsville AL, San Diego CA, Colorado Springs CO); the primary location listed is Annapolis Junction, MD, which falls in the Baltimore-Columbia-Towson CBSA.

The alt SOC (15-1211 Computer Systems Analysts) reflects the strong systems engineering / requirements decomposition dimension of this role alongside its cybersecurity focus.

Requires a Top Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗