Cyber Protection Principal/Sr. Principal Engineer-AHT

Northrop Grumman

USonsite$98k-$194k/yrPosted May 13, 2026
Posting intelligenceListed a while

Skills

confluencekubernetesjenkinsdockergithubgitlabpythonazurejiracicdaws

About the role

RELOCATION ASSISTANCE: Relocation assistance may be available

CLEARANCE REQUIRED FOR START: Yes

CLEARANCE TYPE: Top Secret

TRAVEL: Yes, 10% of the Time

Description

At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work - and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.

Northrop Grumman Defense Systems (NGDS) is seeking a Cyber Protection Principal Engineer to maintain and enhance capabilities in support of DAF CLOUDworks at the Air Force Research Lab (AFRL) in Rome, NY, Warner Robins, GA, or Wright Patterson Air Force Base, OH. DAF CLOUDworks is a rapidly growing secure cloud program that encompasses 10+ teams. These teams span all different areas of

cloud engineering including information security, infrastructure development, and cloud migration. You will be an active part of one of these teams providing technical support of customers leveraging DAF CLOUDworks. Along with operations and sustainment, DAF CLOUDworks focuses on modifying and enhancing offerings to implement new requirements, enhance functionality, increase efficiency, or lower operating/deployment.

This role is focused on cloud penetration testing, adversarial emulation, red team operations, and container security assessments within a cleared DoD environment. The ideal candidate has a strong offensive security background and deep expertise in AWS and Azure environments.

This position is contingent on customer funding and approval and may be filled at a level 3 or level 4.

**this position is contingent upon funding/award

Basic Qualifications:

Level 3: Bachelor’s degree in Science with 5+ years of software development experience; Master's with 3+ years of relative experience; or an additional 4 years of experience may be considered in lieu of degree.

Level 4: Bachelor’s degree in Science with 8+ years of software development experience; Master's with 6+ years of relative experience; or an additional 4 years of experience may be considered in lieu of degree.

This position requires an active Top Secret/SCI clearance and the ability to obtain an IAT Level II or III certification (Security+, Pentest+, SecurityX,) within 60 days of start.

Deep knowledge of cloud attack paths - IAM privilege escalation, metadata service abuse, misconfigured storage, cross-account trust exploitation, and OAuth/token abuse - is required.

Proficiency with cloud-native offensive tooling including Pacu (AWS exploitation framework) and AADInternals (Azure/M365 offensive toolkit), alongside enumeration platforms such as ScoutSuite, CloudFox, Prowler, and ROADtools.

Preferred Qualifications:

Prior DoD or IC classified environment experience and familiarity with adversary simulation platforms such as Cobalt Strike, Sliver, or Havoc are a strong plus.

Hands-on practitioner who has operated tools at depth across real engagements, documented findings under active assessment constraints, and can communicate risk clearly to both technical teams and senior leadership.

Experience developing and executing cyber tabletop exercises including threat scenario design, threat actor emulation planning, and after-action reporting is highly valued.

Hands-on experience with Docker and Kubernetes security assessments, including container escape techniques, privileged container abuse, K8s RBAC misconfigurations, service account taken abuse, and CI/CD pipeline security across GitLab, GitHub Actions, and Jenkins environments.

Strong scripting skills in Bash, Python, and PowerShell are expected, and a working knowledge of MITRE ATT&CK as applied to cloud and hybrid environments

Preferred certifications include OSCP, CPTS, PNPT, GPEN, GXPN, GCPN, AWS Security Specialty, or AZ-500.

Day-to-day work Jira and Confluence for sprint and documentation workflows, and GitHub for version controlled tooling and collaborative code review.

Primary Level Salary Range: $98,400.00 - $155,400.00

Secondary Level Salary Range: $122,800.00 - $193,900.00

The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.

Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.

The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.

Compensation

This Teacher role pays $98k-$194k/yr. Within typical range for teacher roles in United States.

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on Northrop Grumman's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation for Teacher roles in United States varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Teacher hub for United States medians across recent openings.

You never touch the form - the application is filled and submitted for you on Northrop Grumman's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.