Sr Principal Cyber Systems Engineer (Networking)

Northrop GrummanSan Antonio, TX
$113,900 - $213,200Onsite

About The Position

Northrop Grumman Mission Systems is seeking a highly skilled and motivated Principal Cyber Systems Engineer or Senior Principal Cyber Systems Engineer to join their dynamic engineering team. This role involves serving on a team dedicated to the development of a new solution operating in a multi-level security environment. The position requires expertise in Cyber Systems Engineering along with some networking experience. This position does not offer any virtual or telecommute working options and requires applicants to be willing to work 100% on-site. The qualified applicant will become part of Northrop Grumman’s Mission Systems support team in San Antonio, TX. This position may be filled by either at the Principal Cyber Systems Engineer level OR at the Sr. Principal Cyber Systems Engineer level based on the qualifications listed.

Requirements

  • Bachelor’s degree in a Science in a STEM discipline from an accredited institution and 5 years of related experience in engineering; or a Master’s degree in a STEM discipline and 3 years of related experience; or a Ph.D. in a STEM discipline and 1 year of related experience (for Principal level).
  • Bachelor’s degree in a Science in a STEM discipline from an accredited institution and 8 years of related experience in engineering; or a Master’s degree in a STEM discipline and 6 years of related experience; or a Ph.D. in a STEM discipline and 3 year of related experience (for Senior Principal level).
  • US Citizenship is required
  • Active, current DoD Top Secret security clearance and SCI eligibility
  • DoD 8570 IAT Level II certification (e.g., Security+ CE) or equivalent prior to start.
  • Hands‑on experience as a cyber/security engineer or cyber systems engineer for complex networked systems (preferably DoD or similar)
  • Experience applying the Risk Management Framework (RMF)
  • Experience developing and/or implementing security controls for Microsoft and Linux systems
  • Working knowledge of IP networking (e.g., routing, switching, VLANs, firewalls) sufficient to read, understand, and critique network designs in collaboration with dedicated network engineers.

Nice To Haves

  • Strong working knowledge of IP networking (e.g., routing, switching, VPN/IPsec, DNS, DHCP, NTP, segmentation) and secure network design principles (defense‑in‑depth, least privilege), with experience applying host and network hardening standards (e.g., DISA STIGs, CIS benchmarks) across servers, endpoints, and network devices.
  • Experience building baseline security control sets and secure configurations for core infrastructure (e.g., routers/switches, firewalls, IDS/IPS, EDR/antivirus, logging) and integrating these into a SIEM‑driven NOC/SOC construct for unified monitoring and incident response.
  • Hands‑on experience with vulnerability scanning and remediation in mission‑critical or real‑time environments with constrained maintenance windows, including implementing compensating controls when direct remediation is not immediately feasible.
  • Strong understanding of Zero Trust concepts, access‑control models (RBAC/ABAC), and secure management‑plane design for networked mission systems.
  • Experience architecting and implementing enterprise Key Management Systems (KMS) and Public Key Infrastructure (PKI), including HSM integration (FIPS 140‑2/3), key hierarchies (root, KEK, DEK), certificate lifecycle management, and repeatable deployment patterns for enclave services (KMS, PKI, logging, monitoring).
  • Familiarity with NIST cryptographic guidance (e.g., SP 800‑57, SP 800‑38 series) and experience aligning cryptographic implementations to DoD/IC requirements.
  • Demonstrated experience executing the RMF lifecycle (Steps 0–6) for complex systems, including development of SSPs, security assessment/test plans, POA&Ms, and other authorization artifacts, and responding to AO/ISSM/ISSO comments and findings.
  • Experience using automation and infrastructure‑as‑code (e.g., Python, PowerShell, Ansible, Terraform) to manage network and security configurations, enforce standards, and generate repeatable compliance evidence.
  • Experience securing cloud or edge‑computing environments (e.g., AWS, Azure, GovCloud and/or containerized/microservices architectures such as Kubernetes and Docker), including segmentation, control‑plane protection, and integration with enterprise monitoring.
  • Experience working in Agile or DevSecOps environments, collaborating with network, systems, and software teams to integrate security into architecture/design and CI/CD pipelines; familiarity with MBSE/digital engineering tools to capture security requirements and behaviors.
  • Strong interpersonal, written, and verbal communication skills, with demonstrated ability to produce clear engineering artifacts (designs, diagrams, ICDs, risk summaries) and to brief leadership, customer representatives, and authorization officials on risk trade‑offs, mitigations, and accreditation posture.

Responsibilities

  • Join a multi‑disciplinary team designing and securing a launch execution network - a complex, multi‑enclave launch and missile test environment.
  • Own the security architecture and RMF/ATO posture for networked systems, shaping controls, documentation, and automation that keep mission systems both secure and available.
  • Work with customer ISSMs/ISSOs and other stakeholders to develop, document, and implement changes in environments operating under, or seeking, an ATO/IATT in accordance with DoD RMF.
  • Serve as a cyber systems engineer on a multi disciplinary team, collaborating closely with network, systems, software, and test engineers to design and secure complex, multi enclave launch and test networks (classified and unclassified).
  • Review and influence network architectures and detailed designs (routing, switching, VPN/IPsec, segmentation, boundary defenses) from a cybersecurity perspective, ensuring baked in protections and RMF compliant control implementations.
  • Support the design, planning, configuration, and sustainment of enterprise scale network communications and security services, producing and maintaining engineering artifacts such as security and network diagrams, configuration baselines, and implementation plans.
  • Provide cybersecurity systems engineering guidance and oversight to implementation teams, including secure configuration of Microsoft and Linux systems, network devices, and enclave services (e.g., logging/monitoring, KMS/PKI, endpoint protection).
  • Plan and support end to end testing of security and network designs, validate configurations, and monitor performance to ensure reliability, resiliency, and compliance with security policies and RMF control objectives.
  • Support vulnerability management activities (scanning, analysis, remediation planning, and compensating controls) in mission critical environments with constrained maintenance windows.
  • Leverage automation and scripting (e.g., Python, PowerShell, Ansible, Terraform) to implement and enforce secure configurations, generate compliance evidence, and streamline recurring cyber engineering tasks.
  • Perform or oversee physical layer installation tasks (e.g., fiber, patch panels, encryption devices) as needed to support secure infrastructure builds and changes.
  • Produce periodic status reports, risk/issue summaries, and engineering change documentation; clearly communicate technical options, risks, and trade offs to both technical and non technical stakeholders, including customer representatives.

Benefits

  • Relocation assistance may be available
  • health insurance coverage
  • life and disability insurance
  • savings plan
  • Company paid holidays
  • paid time off (PTO) for vacation and/or personal business
  • overtime
  • shift differential
  • discretionary bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service