Establish strict program control processes to ensure mitigation of risks and support obtaining ... Experience with NIST Cybersecurity Framework, FedRAMP, PCI DSS, or similar cybersecurity frameworks
Establish strict program control processes to ensure mitigation of risks and support obtaining ... Experience with NIST Cybersecurity Framework, FedRAMP, PCI DSS, or similar cybersecurity frameworks
Software Systems Engineer
Hill Air Force Base, UT · On-site
$107K - $159K/yr
Technical and Program Risk assessment * Defect burn-down and regression testing strategy ... Familiarity complying with FedRAMP or other Government security standards *Salary Range * $107,000 ...
Software Systems Engineer
Hill Air Force Base, UT · On-site
$107K - $159K/yr
Technical and Program Risk assessment * Defect burn-down and regression testing strategy ... Familiarity complying with FedRAMP or other Government security standards *Salary Range * $107,000 ...
Software Systems Engineer
Hill Air Force Base, UT · On-site
$107K - $159K/yr
Technical and Program Risk assessment * Defect burn-down and regression testing strategy ... Familiarity complying with FedRAMP or other Government security standards *Salary Range * $107,000 ...
Quick apply
Software Systems Engineer
Hill Air Force Base, UT · On-site
$107K - $159K/yr
Technical and Program Risk assessment * Defect burn-down and regression testing strategy ... Familiarity complying with FedRAMP or other Government security standards *Salary Range * $107,000 ...
Solutions Engineer
Lehi, UT · On-site
... from program offices and IT leads to agency executives, shaping deal strategy, and winning the ... PKI basics, network security standards, and deep familiarity with FedRAMP High, RMF, DISA STIGs ...
Solutions Engineer
Lehi, UT · On-site
... from program offices and IT leads to agency executives, shaping deal strategy, and winning the ... PKI basics, network security standards, and deep familiarity with FedRAMP High, RMF, DISA STIGs ...
Solutions Engineer
Lehi, UT · Remote
... from program offices and IT leads to agency executives, shaping deal strategy, and winning the ... PKI basics, network security standards, and deep familiarity with FedRAMP High, RMF, DISA STIGs ...
Solutions Engineer
Lehi, UT · Remote
... from program offices and IT leads to agency executives, shaping deal strategy, and winning the ... PKI basics, network security standards, and deep familiarity with FedRAMP High, RMF, DISA STIGs ...
Solutions Engineer
Lehi, UT · On-site
... from program offices and IT leads to agency executives, shaping deal strategy, and winning the ... PKI basics, network security standards, and deep familiarity with FedRAMP High, RMF, DISA STIGs ...
Quick apply
Solutions Engineer
Lehi, UT · On-site
... from program offices and IT leads to agency executives, shaping deal strategy, and winning the ... PKI basics, network security standards, and deep familiarity with FedRAMP High, RMF, DISA STIGs ...
Fedramp Program Manager information
What are the key skills and qualifications needed to thrive as a FedRAMP Program Manager?
What is a FedRAMP Program Manager?
What are the main challenges a FedRAMP Program Manager faces when coordinating compliance efforts across multiple teams?
What is the difference between Fedramp Program Manager vs Cloud Security Manager?
| Aspect | Fedramp Program Manager | Cloud Security Manager |
|---|---|---|
| Certifications | FedRAMP certifications, PMP, CISSP | CISSP, CCSP, Cloud Security certifications |
| Work Environment | Federal agencies, cloud service providers, government projects | Private sector, cloud service providers, enterprise security teams |
| Industry Usage | Federal government compliance, cloud authorization | Cloud security strategy, risk management |
The Fedramp Program Manager primarily focuses on managing FedRAMP compliance and federal cloud authorization processes, often working within government or contractor environments. In contrast, the Cloud Security Manager oversees overall cloud security strategies and risk mitigation in private or enterprise settings. While both roles require cloud security knowledge and certifications like CISSP, their scope and industry focus differ significantly.

Cybersecurity Analyst / Principal Cybersecurity Analyst - 19072
Clearfield, UT • On-site
Full-time
Medical, Life, PTO
Re-posted 11 days ago
Northrop Grumman rating
8.2
Based on 362 frontline employees who took The Breakroom Quiz
88th of 538 rated manufacturers
Job description
Cybersecurity Analyst / Principal Cybersecurity Analyst -
The Northrop Grumman Ground Subsystem Support Contract (GSSC) has an exciting opportunity on the cyber team located in Clearfield, UT. This is a dual level position. The selected candidate will perform the following key duties and responsibilities:
- Perform assessments of weapon system components and networks to identify where those systems and networks deviate from acceptable configurations, enclave policy, or local policy; this is achieved through passive evaluations such as compliance audits and active evaluations such as vulnerability assessments.
- Establish strict program control processes to ensure mitigation of risks and support obtaining certification and accreditation of systems; this includes support of process, analysis, coordination, security certification test, security documentation, as well as investigations, software research, hardware introduction and release, emerging technology research inspections, and periodic audits.
- Document the results of Assessment and Authorization activities and technical or coordination activity and prepare the system Security Plans and update the Plan of Actions and Milestones POA&M.
- Periodically conduct a complete review of each system's audits and monitor corrective actions until all actions are closed.
- Provide analysis, design, development, implementation, and security assessments to ensure compliance with National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53, CNSSI 1253, and DoD RMF Knowledge Service guidance.
- Apply analytical and evaluative methods and techniques to issues or studies concerning the efficiency and effectiveness of Cyber Security implementation.
- Develop system and policy documentation required for certification evaluation.
- Perform other ISSM/ISSO duties as necessary.
- Apply scientific, engineering, and information assurance principles to deliver trustworthy systems that satisfy stakeholder requirements within their established risk tolerance.
Basic Qualifications Cybersecurity Analyst:
- Bachelor's degree with 2 years of experience, or Master's degree; 4 additional years of experience may be considered in lieu of a completed degree.
- Must be a US Citizen and have the ability to obtain and maintain a U.S. Government DoD security clearance (Secret, Top Secret).
- Current DoDD 8140 ISSM 722-Intermediate Certification (Examples: CGRC, CASP, CCISO, Security+), or ability to obtain one within 6 months, and maintaining the required certification will be a condition of continued employment.
- Must be able to prioritize and execute tasks in a collaborative team environment within schedules and timelines.
Basic Qualifications Principal Cybersecurity Analyst:
- Bachelor's degree with 5 years of experience, or Master's degree with 3 years of experience, or PhD degree with 1 year of experience; 4 additional years of experience may be considered in lieu of a completed degree.
- Must be a US Citizen and have the ability to obtain and maintain a U.S. Government DoD security clearance (Secret, Top Secret).
- Current DoDD 8140 ISSM 722-Intermediate Certification (Examples: CGRC, CASP, CCISO, Security+), or ability to obtain one within 6 months, and maintaining the required certification will be a condition of continued employment.
- Experience with NIST Cybersecurity Framework, FedRAMP, PCI DSS, or similar cybersecurity frameworks
- Must be able to prioritize and execute tasks in a collaborative team environment within schedules and timelines.
Preferred Qualifications:
- 2 years of Information Systems Security Officer/Manager experience.
- Current DODD 8140 ISSM 722-Advanced Certification (Examples: CISM, CISSP, GCIA, GSLC).
- Working knowledge and understanding of auditing, vulnerability scanning/remediation, DISA STIGs, configuration/change control, and implementation of Risk Management Framework.
- Excellent verbal and written communication skills to produce coherent and concise documentation required for certification evaluation.
- ICBM Experience.
- Current DoD Top Secret security clearance.
What Northrop Grumman employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Northrop Grumman
Sourced by ZipRecruiter
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible.
Industry
Space research administration
Company size
10,000+ Employees
Headquarters location
Falls Church, VA, US
Year founded
1939