Principal Cyber Intelligence Analyst

Northrop GrummanJessup, MD
$103,600 - $155,400Hybrid

About The Position

Northrop Grumman's Corporate Sector's Chief Information & Digital Office (CIDO) is seeking a Principal Cyber Intelligence Analyst to support its CISO & Global Cybersecurity organization’s Cybersecurity Operations Center. The team is looking to add a versatile, experienced, highly motivated analyst and tool builder to our world-class team of cyber defensive operators. Adaptability, creativity, commitment to mission, self-direction, and strong written/verbal communications skills are essential. The desired candidate should be a high-performing SOC analyst wishing for greater influence in automating away alert fatigue and/or a cyber systems engineer with intense curiosity about the front-line of cyber defense and incident response.

Requirements

  • 8 years of relevant experience with an Associates in Computer Science, Computer Engineering, Cybersecurity, Computer Network Defense, Information Systems, Digital Forensics, or related field; 5 Years with Bachelors; 3 Years with Masters; 1 Year with PhD.
  • Candidates must have a current U.S. Government Top Secret level security clearance, to include SCI access and a recent Polygraph [adjudicated within the last 5 years], in order to be considered.
  • Fluency in offensive cyber Tactics, Techniques, & Procedures (TTPs).
  • A strong foundation in defensive cyber operations in a team atmosphere.
  • Blue Team analytic mindset and experience: incident triage, threat hunting, alert handling.
  • Proven Dev/Sec/Ops competency – able to write code, optimize SIEM queries, engineer integrations, and upskill in new technologies as needed.
  • Creative problem-solving experience using a wide variety of cyber and IT systems including Windows, Linux, Networking, AWS, Azure.
  • Ability to work in flexible environments: working at an office, a SCIF as required and home when necessary.
  • One or more active DOD 8570 IAT Level 2 certification (Sec+, CySA+, GSEC, SSCP, CCNA Security, GICSP, CND).

Nice To Haves

  • Experience with classified operations and cross‑domain solutions.
  • Security Orchestration Automation & Response (SOAR) systems engineering and playbook development.
  • Threat Detection Engineering experience, such as: SIEM queries, EDR detections, network IDS/IPS rules, Yara rules.
  • One or more active DOD 8570 IAT Level 3 certification (CASP+, CCNP Security, CISA, CISSP, CCSP, GCED, GCIH).
  • High-level industry and vendor certs, academic or passion projects, broader cyber community engagements.

Responsibilities

  • Monitor, investigate, and respond to cyber threat alerts on unclassified and classified networks.
  • Create and tune cyber threat detection rules in a variety of platforms.
  • Conceptualize, build and integrate tools that improve efficacy of defensive cyber operations.
  • Collaborate with cyber, technical, and non-technical teams to navigate the complexities of incident response and DevSecOps in organic networks, restricted environments, and an evolving mission landscape.

Benefits

  • flexible work arrangements
  • phenomenal learning opportunities
  • exposure to a wide variety of projects and customers
  • very friendly team environment
  • health insurance coverage
  • life and disability insurance
  • savings plan
  • Company paid holidays
  • paid time off (PTO) for vacation and/or personal business
  • 401k matching program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service