Principal Software Cyber Engineer
NEWNorthrop Grumman · United States-Colorado-Colorado Springs, United States
- Contract
- Full time
- Base
- United States-Colorado-Colorado Springs, United States
- Field
- IT & Digital
- Posted
Description
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work — and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.Northrop Grumman Space Systems is seeking a Principal Software Cyber Engineer to serve as the cyber and software security lead on a program developing and fielding a new ground-based radar performing Space Domain Awareness (SDA) missions. As the Software Cyber Engineer lead, you will be a key member of the senior technical team and will be responsible for defining, implementing, and sustaining the software and cybersecurity architecture for mission systems supporting operational execution, software development, and long-term sustainment of the radar system. The ideal candidate will have a strong foundational knowledge of secure software engineering and cybersecurity principles and be able to collaboratively apply systems engineering practices to design, implement, and document robust cyber protections for mission software and supporting services across the program.
Designs, develops, documents, tests and debugs applications software and systems that contain logical and mathematical solutions. Conducts multidisciplinary research and collaborates with equipment designers and/or hardware engineers in the planning, design, development, and utilization of electronic data processing systems for product and commercial software. Determines computer user needs; analyzes system capabilities to resolve problems on program intent, output requirements, input data acquisition, programming techniques and controls; prepares operating instructions; designs and develops compilers and assemblers, utility programs, and operating systems. Ensures software standards are met.
Basic Qualifications
- Programming languages: Java, Python, JavaScript, C, C++
- Spring Framework
- Experience debugging existing software and correcting defects
- Familiarity with Agile development methodologies and working in cross-functional scrum teams
- Ability to analyze static and dynamic scan results, distinguish actionable security findings from false positives/non-applicable items, and draft technical justifications and remediation plans (POA&M)
- Practical experience with secure coding practices and code review to identify common vulnerabilities
- Knowledge of CI/CD pipelines and how security gates integrate into build/release processes
- Comfortable reading and interpreting security requirements and translating them into developer-facing tasks and acceptance criteria
- Experience using version control systems and branching strategies in team environments
- Experience with multiple Linux distributions with a focus on Red Hat Enterprise Linux and Ubuntu
- Must have an active U.S. Government Top Secret security clearance at time of application, current and within scope.
Preferred Qualifications
- Experience overseeing software integrity and supply chain security (dependency management, SBOMs, vendor assessment)
- Familiarity with NIST SP 800-53 Risk Management Framework (RMF) and DISA Application Security and Development STIG to assess the design of information systems
- Hands-on experience with one or more SAST tools (e.g., SonarQube, Fortify)
- Hands-on experience with one or more SCA tools (e.g., Sonatype Nexus)
- Certifications such as Security+, CISSP, or CSSLP
- Familiarity with container security and orchestration hardening (Docker, Kubernetes) and image scanning tools
- Practical knowledge of vulnerability lifecycle management and patching processes across environments
- Understanding of data protection requirements and handling of sensitive data (PII, classified, export-controlled)
- Experience supporting or obtaining low-to-high (CDS) transfer approvals and familiarity with compliance workflows
