About this role
RELOCATION ASSISTANCE: No relocation assistance available
CLEARANCE REQUIRED FOR START: No
CLEARANCE TYPE: Secret
TRAVEL: Yes, 10% of the Time
## Description
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work — and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.
At the heart of Defining Possible is our commitment to missions. In rapidly changing global security environments, Northrop Grumman brings informed insights and secure technological solutions to enable strategic objectives. We’re looking for innovators who can help us keep building on our wide portfolio of secure, affordable, integrated, and multi-domain systems and technologies that fuel those missions. By joining in our shared mission, we will support yours by expanding your personal network and developing skills, whether you are new to the field or an industry thought leader. At Northrop Grumman, you will have the resources, support, and team to do some of the best work of your career.
Northrop Grumman’s Corporate Sector's Chief Information & Digital Office (CIDO) is seeking a Sr. Principal Computer Systems Analyst – Cloud Platform / Landing Zone Engineer (AWS) to support its IT Infrastructure & Operations organization's Classified Solutions team. The selected candidate will serve as the leading technical authority for our proprietary, air-gapped AWS Secret Cloud for Industry (ASCI) IL6 multi-account environment. This technical leader will guide the successful design, security standards, and architectural integrity of classified multi-account workloads.
This role is responsible for the transition from legacy “on-prem” operational habits to automated, highly resilient cloud-native infrastructures, ensuring that developers receive modern, high velocity capabilities without compromising our Authorization to Operate (ATO). You will apply extensive technical expertise to solve complex, non-recurring deployment challenges and serving as a key mentor for junior platform personnel and tier-1 triage teams.
The selected candidate will be required to work on-site, full-time at our Redondo Beach, CA, or Rolling Meadows, IL, or Melbourne, FL location.
The responsibilities of this role include, but are not limited to, the following:
General Responsibilities:
- Perform as a lead Sr. Principal Computer Systems Analyst - Cloud Platform / Landing Zone Engineer (AWS) in support of classified government contracts.
- Communicate effectively with all organizational levels, internal/external customers, vendors, and senior leadership, both verbally and in writing.
- Oversee operations and administration of multi-user computer systems and multiple networks, coordinating with IT teams, project managers, and end users.
- Analyze requirements, recommend, and implement hardware/software solutions; interact with vendors to evaluate and troubleshoot products and services.
- Define, implement, and maintain enterprise-wide system enhancements, including installation, upgrades/patches, monitoring, configuration management, and problem resolution.
- Lead testing, validation, and change management for major product releases across platforms.
- Develop, publish, and continuously improve technical standards and SOPs.
- Ensure compliance with Information Systems security guidelines; prepare and maintain security documentation, audit logs, and Assessment & Authorization (A&A) submissions; serve as senior liaison to the ISSM.
- Report on strategic initiatives and project status to executive stakeholders; act as a key technical advisor impacting enterprise-wide, mission-critical systems.
- Acts as a key technical advisor to senior leadership; impacts multiple programs and mission‑critical systems across the enterprise.
- Provide senior-level technical expertise by mentoring junior and experienced team members, fostering their professional growth and enhancing team capabilities.
- Lifts and moves equipment up to 50 pounds.
- Work after hours, and weekends, as needed.
Environment Automation & IaC:
- Declarative Infrastructure: Develop and maintain declarative Infrastructure as Code (IaC) templates using declarative tools such as AWS CloudFormation, AWS SAM, Terraform, OpenTofu to standardize and automate Secret‑level cloud environments.
- Account Provisioning: Design and manage automated Account Vending Machines (AVMs) and account factories to rapidly provision standardized, compliant VPCs and AWS accounts for mission application teams, preventing multi-tenant data comingling.
- Offline Pipeline Architecture: Build and maintain offline, air-gapped CI/CD pipelines tailored to execute in code-isolated environments without public internet connectivity or external SaaS dependencies.
Governance, Security, & Guardrails:
- Access Control Enforcement: Author and enforce strict Service Control Policies (SCPs) and IAM permission boundaries to prevent unauthorized lateral movement between multi-tenant program partitions.
- Centralized Security Logging: Configure centralized audit logging by routing AWS CloudTrail events directly to a secure, immutable, centralized S3 logging bucket for seamless ingestion into our on‑premises Splunk environment, including designing compliant alternatives when native services (e.g., GuardDuty or SQS‑based pipelines) are unavailable or not accredited in the air‑gapped region.
- Manual AMI Hardening: Lead the manual STIG hardening and security configuration of Red Hat Enterprise Linux (RHEL) and Windows Amazon Machine Images (AMIs) using localized Ansible and PowerShell scripts, managing the interim pipeline while AWS Image Builder remains unapproved on the high side.
- ATO Compliance Mapping: Map all cloud infrastructure configurations directly to DISA STIGs and NIST SP 800-53 controls to achieve first time pass rates during DCSA continuous monitoring audits.
Network & Hybrid Data Flow:
- Secure Hybrid Connectivity & Patch Ingestion: Design and maintain zero‑trust network connectivity between Secret‑level AWS environments and Secret‑level on‑prem systems using AWS Transit Gateway, Direct Connect, and software‑defined firewalls. Work with security and cross‑domain solution teams to define compliant, controlled processes for importing patches and updates from lower‑classification environments into the air‑gapped Secret environment.
- On-Premise DNS Reach Back: Design and manage conditional DNS forwarding architectures using Route 53 Resolver Endpoints pointing directly back to our on-premises Active Directory and DNS servers, explicitly avoiding the deployment of active domain controllers inside the cloud boundary.
Note: Due to the classified nature of the work being performed, this position does not offer any virtual or telecommute working options. Applicants are encouraged to apply, only if they are willing to work on-site.
Basic Qualifications :
- Master's Degree with 6 years of IT experience; OR a Bachelor's Degree with 8 years of IT experience; OR an Associate's Degree with 10 years of IT experience; OR a High School Diploma/GED with 12 years of IT experience is required.
- Candidates must have the ability to obtain a U.S. Government Secret level security clearance as a condition of continued employment.
- Linux operating system workstation and server administration/support experience in DoD/IC classified and/or air‑gapped environments.
- Operating system cross‑platform awareness (e.g., Windows, Linux, UNIX variants), including interoperability considerations in mixed on‑prem and cloud environments
- Experience administering container orchestration platforms (e.g., Kubernetes‑based environments such as Amazon EKS or OpenShift) in classified or regulated environments.
- Proficiency with automation and configuration management tools (e.g., Ansible, Bash/Python scripting) in Linux and cloud environments.
- Solid understanding of networking concepts (TCP/IP, DNS, load balancing, firewalls) and AWS networking primitives (VPCs, subnets, security groups, network ACLs, Transit Gateway, Direct Connect, Route 53 Resolver) in classified cloud contexts.
- Demonstrated experience with system and platform security hardening and patch management using DISA STIGs and other DoD security baselines.
- Hands‑on experience architecting and operating AWS multi‑account landing zones in regulated or classified environments (e.g., AWS Organizations, SCPs, IAM guardrails, centralized logging).
- Experience designing and maintaining CI/CD pipelines and mirrored repositories for patch and artifact distribution into Secret‑level environments.
- Candidates must meet U.S. Government DoD 8140 (formerly 8570) requirements for the appropriate IAT/IAM level (typically a CompTIA Security+ or equivalent) for a Sr. Principal Computer Systems Analyst working Linux and cloud systems in a classified environment or able to obtain within six months of hire
- Active DoD Secret clearance or ability to obtain and maintain a DoD Secret clearance.
Preferred Qualifications :
- Bachelor’s degree in Information Technology or related field, and 10+ years of Linux server administration experience in DoD/IC classified and/or air‑gapped environments.
- A current U.S. Government Secret level security clearance.
- Candidates must have the ability to obtain, and maintain, a U.S. Government Top Secret level security clearance as a condition of continued employment.
- Candidates must have the ability to obtain, and maintain, SCI level access as a condition of continued employment.
- Candidates must have the ability to obtain, and maintain, a Polygraph as a condition of continued employment.
- Candidates must have the ability to obtain, and maintain, access to Special Programs as a condition of continued employment.
- Advanced cybersecurity certifications such as CASP+, CISSP, or cloud security certifications (e.g., AWS Certified Security – Specialty) in addition to meeting DoD 8140 baseline (e.g., Security+ CE).
- Operating system cross‑platform operations (e.g., Windows, Linux, UNIX variants), including integration between on‑premises and AWS workloads in classified environments.
- Experience working directly with Information System Security Managers (ISSMs) and supporting Assessment & Authorization (A&A) activities for cloud hosted systems.
- Experience administering modern Linux distributions (RHEL 8/9, Rocky Linux, etc.), including STIG‑hardened images in classified environments.
- Experience operating under and managing systems within NISPOM Chapter 8, DCID 6/3‑ICD 503, RMF, STIG, JAFAN, or JSIG information system environments.
- Experience with AWS Secret and Top Secret regions (e.g., SC2S, C2S) or other government‑only cloud offerings, including operating within air‑gapped or restricted‑connectivity constraints.
- Practical experience designing AWS landing zones using AWS Organizations, Control Tower/Account Factory, or homegrown Account Vending Machines in classified environments.
- Kubernetes orchestration (CNCF Kubernetes, Rancher, Kubernetes Dashboard, etc.), including experience with Amazon EKS or OpenShift on AWS in secure or classified deployments.
- Advanced containerization skills (Podman, Podman Compose, Docker, Docker Compose, etc.) and container security tools, with experience securing containers in air‑gapped or disconnected environments.
- Hands‑on experience with DevSecOps tooling in classified or regulated environments, including:
- Container and code security scanners (e.g., Trivy, Anchore, Clair, SonarQube).
- Secrets and key management solutions (HashiCorp Vault, AWS KMS in Secret regions, OpenShift/Kubernetes secrets).
- Experience with Terraform, OpenTofu, and AWS CloudFormation (or CDK) for hybrid on‑prem/AWS and OpenShift environments in classified settings.
- Familiarity with logging and observability stacks (e.g., EFK/ELK, Prometheus/Grafana, Splunk) deployed in air‑gapped or restricted‑connectivity environments.
- Experience building and maintaining CI/CD pipelines with integrated security checks, including offline/air‑gapped pipelines for Secret‑level AWS and on‑prem systems.
- Proficient in virtualization platforms (VMware vSphere/ESXi, Citrix XenServer, KVM/QEMU, etc.) used in classified data centers supporting hybrid on‑prem/Secret‑level AWS environments.
- Windows domain architecture experience, including hybrid integration between on‑prem Active Directory and AWS (e.g., via Route 53 Resolver and conditional forwarding) in classified environments.
- Experience with Windows AD, LDAP, VMware, and SAN storage systems in support of hybrid on‑prem/Secret‑level AWS environments.
- Experience deploying, tuning, and operating host‑based and network monitoring tools (e.g., HBSS, SolarWinds, Splunk) in DoD/IC classified networks.
- Strong networking background (subnets, routing, VLANs, VPNs, segmentation), including AWS cloud networking (VPCs, Transit Gateway, Direct Connect, VPC endpoints) in classified environments.
- Scripting and automation (Bash, Python, Ansible) for infrastructure provisioning, configuration, and security baselining in AWS and on‑prem classified environments.
- Experience with the creation and deployment of system images in an enterprise environment, including STIG‑compliant AMIs and virtual machine templates for classified AWS and on‑prem systems.
- Cloud platform integration experience in secure or regulated environments, with primary focus on AWS (including AWS Secret/Top Secret regions), and familiarity with related platforms such as Azure and VMware Cloud Foundation as a plus.
- Experience with the Assessment & Authorization (A&A) process for classified systems, including mapping controls to DISA STIGs and NIST SP 800‑53 and supporting DCSA audits for cloud‑hosted workloads.
- Familiarity with cross‑domain solutions (CDS) and controlled data transfer processes for importing patches and updates from lower‑classification environments into air‑gapped Secret networks.
We offer flexible work arrangements, phenomenal learning opportunities, exposure to a wide variety of projects and customers, and a very friendly team environment. At Northrop Grumman, we are on the cutting edge of innovation. Our diverse portfolio of programs means there are endless paths to cultivate your career. We also offer exceptional benefits/healthcare, a 9/80 work schedule, and a great 401k matching program. Come join us!
Primary Level Salary Range: $111,700.00 - $193,900.00
The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.
Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.
The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.
Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit http://www.northropgrumman.com/EEO. U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.