Principal / Sr Principal Cyber Systems Engineer
Northrop Grumman · Colorado Springs, CO
$113,900–$213,200from the description
Jul 17, 2026
Colorado Springs, CO
Jul 21, 2026
What this job asks for AI summary
A cybersecurity engineering role focused on assessing and hardening defense systems through compliance audits, vulnerability scanning, and Risk Management Framework (RMF) activities. Day-to-day work involves maintaining authorization documentation, conducting security control assessments, and coordinating remediation of identified gaps. Suited to candidates with hands-on RMF, STIG, and DoD policy experience who hold an active Secret clearance.
Senior level · 5+ years · Colorado Springs, CO · Bachelor's required · Secret clearance · Full-time
Advertised as Principal, but the requirements read as Senior.
“or” means any one of them counts — you don't need all of them.
Posted 2 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $133,758 (middle half $108,740–$165,225). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
This posting covers two levels simultaneously: Principal (5+ years with a Bachelor's) and Sr. Principal (8+ years with a Bachelor's). The salary ranges are stacked: $113,900–$170,900 for Principal and $142,200–$213,200 for Sr. Principal. The overall years minimum is set to 5 (the lower gate for the Principal level).
The clearance gate at application is an active Secret; however, candidates must also be able to obtain TS/SCI. An active Top Secret is listed only under Preferred Qualifications.
The advertised title includes both 'Principal' and 'Sr. Principal' — the level advertised in the title is set to Principal (the lower of the two named levels). The actual scope and experience requirements (5–8+ years, RMF/compliance engineering) are consistent with a Senior individual-contributor role on a standard career ladder.
Penetration-testing certifications (OSCP, OSCE, GPEN, GWAPT, GXPN) and IAT III (CISSP) appear under Preferred Qualifications only.
Networking concepts (subnetting, firewalls, NAT, ACLs, VLANs) are listed under Preferred Qualifications as an 'understanding of' — no specific tool named, so omitted from the skills list per extraction rules.
Cross-Domain Solution (CDS) experience is listed under Preferred Qualifications and is a niche, program-specific capability; omitted as it names no standard commercial tool.
Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53, NIST SP 800-115.
Requires a Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.