Northrop Grumman · Colorado Springs, CO

Salary
$113,900–$213,200from the description
Posted
Jul 17, 2026
Location
Colorado Springs, CO
Last confirmed open
Jul 21, 2026

What this job asks for AI summary

A cybersecurity engineering role focused on assessing and hardening defense systems through compliance audits, vulnerability scanning, and Risk Management Framework (RMF) activities. Day-to-day work involves maintaining authorization documentation, conducting security control assessments, and coordinating remediation of identified gaps. Suited to candidates with hands-on RMF, STIG, and DoD policy experience who hold an active Secret clearance.

Senior level · 5+ years · Colorado Springs, CO · Bachelor's required · Secret clearance · Full-time

Advertised as Principal, but the requirements read as Senior.

Must have (7)
DoD 8570.01M IAT II certification, Security+ Ce, Ccna Security, Gsec or SscpRisk Management FrameworkACAS, Nessus or Tenable.scSTIG hardeningSTIG Viewer, Scap, Evaluate Stig or Stig ManagerMicrosoft OfficeLinux
Nice to have (10)
eMASSSIEMRHELAnsible or PythonJira or ConfluenceVMwareElastic StackOSCP, Osce, Gpen, Gwapt or GxpnCISSPAgile, Scrum, Kanban or Safe

“or” means any one of them counts — you don't need all of them.

Posted 2 times — it's one opening, so apply once.

We read this from the posting text with AI. Skim the description below before ruling yourself out.

How this req sits in the market our data

What won't set you apart
Linux65%Risk Management Framework40%

Most people in this occupation already list these. Still required — just not what gets you shortlisted.

What the occupation pays Median $133,758 (middle half $108,740–$165,225). This posting is about at that midpoint.

Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.

Why we read it this way (8)

This posting covers two levels simultaneously: Principal (5+ years with a Bachelor's) and Sr. Principal (8+ years with a Bachelor's). The salary ranges are stacked: $113,900–$170,900 for Principal and $142,200–$213,200 for Sr. Principal. The overall years minimum is set to 5 (the lower gate for the Principal level).

The clearance gate at application is an active Secret; however, candidates must also be able to obtain TS/SCI. An active Top Secret is listed only under Preferred Qualifications.

The advertised title includes both 'Principal' and 'Sr. Principal' — the level advertised in the title is set to Principal (the lower of the two named levels). The actual scope and experience requirements (5–8+ years, RMF/compliance engineering) are consistent with a Senior individual-contributor role on a standard career ladder.

Penetration-testing certifications (OSCP, OSCE, GPEN, GWAPT, GXPN) and IAT III (CISSP) appear under Preferred Qualifications only.

Networking concepts (subnetting, firewalls, NAT, ACLs, VLANs) are listed under Preferred Qualifications as an 'understanding of' — no specific tool named, so omitted from the skills list per extraction rules.

Cross-Domain Solution (CDS) experience is listed under Preferred Qualifications and is a niche, program-specific capability; omitted as it names no standard commercial tool.

Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53, NIST SP 800-115.

Requires a Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.

Read the full posting

The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.

Apply

Apply on employer site ↗