About this role
RELOCATION ASSISTANCE: No relocation assistance available
CLEARANCE REQUIRED FOR START: No
CLEARANCE TYPE: Secret
TRAVEL: Yes, 10% of the Time
## Description
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work — and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.
At the heart of Defining Possible is our commitment to missions. In rapidly changing global security environments, Northrop Grumman brings informed insights and secure technological solutions to enable strategic objectives. We’re looking for innovators who can help us keep building on our wide portfolio of secure, affordable, integrated, and multi-domain systems and technologies that fuel those missions. By joining in our shared mission, we will support yours by expanding your personal network and developing skills, whether you are new to the field or an industry thought leader. At Northrop Grumman, you will have the resources, support, and team to do some of the best work of your career.
Northrop Grumman’s Corporate Sector's Chief Information & Digital Office (CIDO) is seeking a Sr. Principal Computer Systems Analyst – Cloud Platform / Landing Zone Engineer (Azure) to support its IT Infrastructure & Operations organization's Classified Solutions team. The selected candidate will serve as the leading technical authority for our DoD-approved Azure Isolated Secret Region (AISR) IL 6 multi-account cloud environment. This technical leader applies extensive technical expertise to design, implement, and automate secure, scalable Azure Landing Zones, subscription structures, and virtual enclaves. You will lead the transition from legacy on-premises operational habits to automated, highly resilient, cloud-native architectures.
You will ensure that major programs receive high-velocity, modern capabilities without compromising our multi-tenant Authorization to Operate (ATO). Additionally, you will serve as a key technical contact and mentor for junior systems administrators, network engineers, and tier-1 triage teams across the enterprise.
The selected candidate will be required to work on-site, full-time at our Redondo Beach, CA, or Rolling Meadows, IL, or Melbourne, FL location .
The responsibilities of this role include, but are not limited to, the following:
General Responsibilities:
- Perform as a lead Sr. Principal Computer Systems Analyst – Cloud Platform / Landing Zone Engineer (Azure) in support of classified government contracts.
- Communicate effectively with all organizational levels, internal/external customers, vendors, and senior leadership, both verbally and in writing.
- Oversee operations and administration of multi-user computer systems and multiple networks, coordinating with IT teams, project managers, and end users.
- Analyze requirements, recommend, and implement hardware/software solutions; interact with vendors to evaluate and troubleshoot products and services.
- Define, implement, and maintain enterprise-wide system enhancements, including installation, upgrades/patches, monitoring, configuration management, and problem resolution.
- Lead testing, validation, and change management for major product releases across platforms.
- Develop, publish, and continuously improve technical standards and SOPs.
- Ensure compliance with Information Systems security guidelines; prepare and maintain security documentation, audit logs, and Assessment & Authorization (A&A) submissions; serve as senior liaison to the ISSM.
- Report on strategic initiatives and project status to executive stakeholders; act as a key technical advisor impacting enterprise-wide, mission-critical systems.
- Acts as a key technical advisor to senior leadership; impacts multiple programs and mission‑critical systems across the enterprise.
- Provide senior-level technical expertise by mentoring junior and experienced team members, fostering their professional growth and enhancing team capabilities.
- Lifts and moves equipment up to 50 pounds.
- Work after hours, and weekends, as needed.
Environment Automation & IaC:
- Automate the Azure Landing Zone (ALZ): Develop declarative Infrastructure as Code (IaC) using Microsoft Bicep, ARM templates, and Terraform/OpenTofu to programmatically deploy and maintain the ALZ conceptual architecture, management groups, and resource configurations.
- Engineer Subscription Vending Patterns: Design and orchestrate automated subscription vending machines and blueprint templates to rapidly and uniformly provision pre-configured virtual enclaves for mission application teams.
- Build Air-Gapped CI/CD Pipelines: Build and maintain localized, offline CI/CD pipelines (utilizing Azure DevOps Server or GitLab CI) engineered to execute compilation, validation, and deployment in code-isolated environments lacking internet dependency.
- Maintain Custom Image Pipelines: Build and run automated pipelines via localized Ansible and PowerShell scripts to populate a private Azure Compute Gallery. This ensures manual STIG hardening and SCAP compliance validation for Windows Server, Windows 11, and Red Hat Enterprise Linux (RHEL 8/9) images, mitigating the lack of "stock" cloud images in the isolated region.
- Orchestrate Resource Optimization: Design and implement automated, event-driven resource optimization scripts (such as VM and Azure Virtual Desktop "server parking" schedules) and consumption-monitoring dashboards to manage billing and reduce sector overhead costs.
Governance, Security, & Guardrails:
- Author Enterprise Guardrails: Author, test, and enforce strict Azure Policies and policy initiatives at the management group level to prevent unauthorized resource deployment, block non-compliant configurations, and protect multi-tenant boundaries.
- Classified Identity & Access Management (IdAM): Configure and maintain Active Directory Federation Services (ADFS) and Entra ID (Azure AD) directory synchronization across on-premises and cloud boundaries to enforce zero-trust, passwordless Single Sign-On (SSO) and Role-Based Access Control (RBAC) tied to synced classified domain security groups.
- Centralize Security Auditing: Configure continuous monitoring (ConMon) and automated diagnostic log forwarding across all subscriptions to secure, immutable Log Analytics Workspaces and on-premises Splunk environments.
- Automate Drift Remediation: Implement automated remediation workflows using Azure Logic Apps and Event Grid to instantly flag, isolate, or tear down non-compliant infrastructure and configuration drift.
- Support Assessment & Authorization (A&A): Map cloud infrastructure configurations directly to NIST SP 800-53 and DISA STIG controls in EMASS/Archer. Extract automated technical evidence via Azure Resource Graph to guide the successful completion of DCSA annual audits and continuous ATO renewal cycles.
Networking & Data Egress/Ingress:
- Architect Secure Hub-and-Spoke Networks: Implement, configure, and maintain secure hybrid network paths utilizing Azure Virtual WAN hubs or Azure Route Server to handle secure, encrypted communication boundaries across classified networks.
- Enforce Zero-Trust Network Boundaries: Establish zero-trust network boundaries within the landing zone using Azure Private Links, Private Endpoints, and central inspection architectures featuring Azure Firewall Premium.
- Resolve Routing Issues: Mitigate complex BGP route propagation errors, manual routing table conflicts, and asynchronous routing issues, enforcing strict tenant domain separation over virtualized transport paths (Transport Layer Backbone - TLB) using Cisco VRF technology.
- Configure Isolated Name Resolution: Architect and configure highly restricted DNS architectures using Azure Private DNS Zones and Azure DNS Private Resolver endpoints to ensure reliable name resolution across disconnected network fabrics.
Operations in Classified Environments:
- Azure Virtual Desktop (AVD) Scaling: Architect, configure, and scale secure AVD host pools, managing session load balancing, user profiles (using FSLogix disk attachments), and user connection settings. Resolve critical 3D globe browser rendering and OpenGL/OpenCL nested RDP pass-through challenges on high-performance RTX-class GPU virtual machine instances.
- Manage Secure Container Registries: Deploy and configure secure containerized services, including Azure Kubernetes Service (AKS) and private Azure Container Registries (ACR) on the high side. Maintain these localized registries to ensure secure, scanned container ingestion.
- Air-Gapped Workload Ingestion: Manage the validation of software dependencies, base images, containerized workloads, and Helm charts, ensuring they are cryptographically verified and scanned before ingestion into IL6 networks.
- Provide Tier-3 Engineering Support: Onboard mission application teams into the landing zone framework. Resolve complex Azure RBAC permissions, policy denials, or cross-subscription routing blocks that disrupt application delivery.
- Technical Leadership & Mentoring: Represent the organization as the prime technical contact on contracts and projects. Interact with senior external personnel (such as Microsoft Customer Support Advocates/CSAs and DCSA auditors) and actively mentor junior/experienced team members by leading upskilling efforts within the Classified Admins Community of Practice.
Basic Qualifications:
- Master's Degree with 6 years of IT experience; OR a Bachelor's Degree with 8 years of IT experience; OR an Associate's Degree with 10 years of IT experience; OR a High School Diploma/GED with 12 years of IT experience is required.
- Candidates must have the ability to obtain a U.S. Government Secret level security clearance as a condition of continued employment.
- Candidates must meet U.S. Government DoD 8140 (formerly 8570) requirements for an appropriate IAT Level II certification (e.g., CompTIA Security+ CE, CCNA Security, or equivalent) or able to obtain within six months of hire.
- Extensive experience with Azure Cloud Administration, Entra ID (Azure AD) directory synchronization, role-based access control (RBAC), and virtual desktop pooling (AVD/VDI) in secure, air-gapped, or regulated environments.
- Strong proficiency in Azure-native automation and declarative tools (Bicep, PowerShell, Azure CLI, ARM templates, YAML).
- Solid understanding of enterprise networking concepts (subnets, routing, VLANs, BGP) and Azure networking primitives (VNETs, Virtual WAN hubs, ExpressRoute, Azure DNS Private Resolvers, Network Security Groups).
Preferred Qualifications:
- A current U.S. Government Secret level security clearance.
- Candidates must have the ability to obtain, and maintain, a U.S. Government Top Secret level security clearance as a condition of continued employment.
- Candidates must have the ability to obtain, and maintain, SCI level access as a condition of continued employment.
- Candidates must have the ability to obtain, and maintain, a Polygraph as a condition of continued employment.
- Candidates must have the ability to obtain, and maintain, access to Special Programs as a condition of continued employment.
- Microsoft Certified: Azure Solutions Architect Expert, DevOps Engineer Expert, or Azure Security Engineer Associate.
- Advanced cybersecurity certifications, such as CASP+ or CISSP (meeting IAM Level III baseline) active at the time of hire.
- Experience working directly with Information System Security Managers (ISSMs) and supporting Assessment & Authorization (A&A) activities for cloud-hosted systems under the Risk Management Framework (RMF).
- Hands-on experience administering container orchestration platforms (e.g., Azure Kubernetes Service - AKS or OpenShift on Azure) in classified, air-gapped, or regulated environments.
- Experience configuring and administering Red Hat Enterprise Linux (RHEL 8/9) servers and Satellite Server repositories in secure environments.
- Experience with automated container and code security scanners (e.g., Trivy, Anchore) in offline, air-gapped DevSecOps pipelines.
- Familiarity with Cross-Domain Solutions (CDS) and controlled Data Transfer Architectures (DTA) for importing patches and updates into air-gapped Secret networks.
- Experience operating under and managing systems within NISPOM Chapter 8, DCID 6/3, ICD-503, JSIG, or JAFAN information system security environments.
- Familiarity with logging, audit trails, and observability stacks (such as Prometheus, Grafana, SolarWinds, or Splunk) deployed in air-gapped environments.
- Familiarity with Azure's high-side government-only secret regions (Microsoft Isolated Secret Region - MSISR) and their specific architectural constraints (e.g., alias label routing, lack of public internet egress).
- Demonstrated technical leadership, including active participation in a technical community of practice, and mentoring junior systems and network administrators.
We offer flexible work arrangements, phenomenal learning opportunities, exposure to a wide variety of projects and customers, and a very friendly team environment. At Northrop Grumman, we are on the cutting edge of innovation. Our diverse portfolio of programs means there are endless paths to cultivate your career. We also offer exceptional benefits/healthcare, a 9/80 work schedule, and a great 401k matching program. Come join us!
Primary Level Salary Range: $111,700.00 - $193,900.00
The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.
Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.
The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.
Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit http://www.northropgrumman.com/EEO. U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.