Northrop Grumman · Tampa, FLremote

Salary
$79,300–$147,600from the description
Posted
Jul 1, 2026
Location
Tampa, FL
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

An on-site, shift-based cybersecurity role focused on operating and maintaining Splunk (or equivalent SIEM) infrastructure to monitor, detect, and investigate security threats. Day-to-day work spans building queries, dashboards, and correlation searches, responding to incidents, and collaborating with IT and network teams. A current DoD TS/SCI clearance and IAT Level II certification are required before starting.

Mid level · 2+ years · Remote · Bachelor's required · TS/SCI clearance · Full-time

Must have (3)
Splunk, Arcsight, Qradar or Microsoft SentinelLinuxWindows
Nice to have (5)
Splunk SPLSplunk Enterprise SecurityTrellixPython, PowerShell or Shell ScriptingSplunk Core Certified Power User

“or” means any one of them counts — you don't need all of them.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
Linux65%Splunk45%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (11)

This requisition may be filled at two levels: Cybersecurity Analyst (primary, $79,300–$118,900/yr, requiring a Bachelor's + 2 years or Master's + 0 years) or Principal Cybersecurity Analyst (secondary, $98,400–$147,600/yr, requiring Bachelor's + 5 years, Master's + 3 years, or PhD + 1 year). The salary range shown spans both levels. Seniority is assessed against the lower (Analyst) level; the Principal level would map to Senior.

The posting explicitly states the role is on-site in Tampa, FL and does not offer any virtual or telecommute options. The remote=true flag has been set per caller instruction and overrides the posting's stated requirement.

A SIEM tool is a hard requirement; Splunk is strongly preferred but an equivalent SIEM is explicitly accepted — common alternatives listed accordingly.

Trellix/HBSS appears in the essential duties narrative but is listed only under Preferred Qualifications for the Principal level, so it is marked preferred.

Splunk SPL, Splunk Enterprise Security, and Splunk dashboarding appear in the duties narrative but are not listed as hard gates in either qualifications block — marked preferred.

Scripting languages (Python, PowerShell, Bash) appear only under Preferred Qualifications for the Principal level.

DoD 8570 IAT Level II certification is a hard gate for both levels; IAT Level III is listed as preferred for the Principal level only.

The role follows a Panama 12-hour shift schedule (rotating days/nights); this is a hard scheduling requirement but cannot be represented as a skill.

Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): DoD 8570 IAT Level II.

Requires a TS/SCI clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Caller marked this a fully-remote role — scored against the national candidate pool.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗