Job Closed

This listing is no longer active.

Northrop Grumman logo
Northrop Grumman

At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way.

Principal Cybersecurity Analyst

Security AnalystSecurity AnalystFull TimeRemoteLeadTeam 10,001+Since 1939H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

33 days ago

Salary

$103.6K - $155.4K / year

Seniority

Lead

Bachelor Degree5 yrs expEnglishCyber SecurityGoogle Cloud Platform

Job Description

Principal Cybersecurity Analyst

Northrop Grumman

• Provide timely, senior‑level security guidance, mentor junior analysts, and influence risk‑mitigation strategies across multiple functions • Lead implementation of technical control frameworks for programs to mitigate risks and continue to enable certification and accreditation of systems • Write, maintain, and own end-to-end policy lifecycle – author, maintain, and programmatically apply procedures; integrate AI for continuous improvement • Proactively monitor U.S. government cyber regulations, synthesize updates from conferences and industry events and disseminate concise briefs to internal stakeholders • Represent GCP in cross-functional committees, aligning security with NG’s strategic objectives

Job Requirements

  • Bachelor’s degree in Computer Science, Political Science, Engineering, Cybersecurity or related field with 5 years of experience; OR a Master’s degree with 3 years of experience; OR a PhD with 1 year of experience
  • Working knowledge of CMMC v2 (Levels 1-3), NIST 800-171/800-172 (All revisions), NIST 800-53, NIST CSF, ISO 27001, and DoD frameworks
  • Experience presenting to Executive Leadership with ability to proactively translate technical findings into clear policy guidance
  • CMMC Certified Professional (CCP) and/or 8140 equivalent

Benefits

  • Health insurance coverage
  • Life and disability insurance
  • Savings plan
  • Company paid holidays
  • Paid time off (PTO) for vacation and/or personal business
  • Exceptionally flexible work arrangements
  • Phenomenal learning opportunities
  • Exposure to a wide variety of projects and customers
  • Great 401k matching program

Related Job Pages

More Security Analyst Jobs

PartnerOne logo

Junior Security Analyst

PartnerOne

We are the leaders in Big Data management through hyper-automation, virtualized cloud tiering, metadata and AI

Security Analyst33 days ago
Full TimeRemoteTeam 201-500H1B No Sponsor

• Partner One is a leading investment group with a 30-year history of acquiring and growing successful software companies. • Proactive and detail-oriented Junior Security Analyst for our fast-paced security team. • First line of defense across diverse and evolving landscapes of internal environments. • Responsible for triaging alerts, maintaining security posture, and ensuring software resilience. • Ideal for someone thriving on variety and wanting deep, hands-on experience across multiple infrastructures.

Colombia
Lyra Technology Group logo

Level 2 Cyber Security Analyst

Lyra Technology Group

The trusted leader in IT services for small and medium-sized organizations.

Security Analyst33 days ago
Full TimeRemoteTeam 1,001-5,000Since 2017H1B No Sponsor

Role Description Lyra Technology Group is looking for L2 Cyber Security Analyst for one of their operating companies, VirtualArmour. The primary role of our L2 Cyber Security Analyst is to work with customers for our Managed Security Services (MSS) department. The Cyber Security Analyst’s role will help protect our customer networks against cybersecurity threats such as hackers, cyber-terrorists and malware that can steal or corrupt sensitive customer data. This role will be monitoring and analyzing customer networks, servers, databases, and end-point equipment for key indicators of compromise. Once a possible threat is detected, the analyst must investigate, respond to, and report to our customers with any recommended remediation. Cyber Analysts should have the experience and knowledge desired below and will also be enrolled in the VirtualArmour Academy, where students will be trained in other aspects of the role. Your work as the Level 2 - Cyber Security Analyst includes several components: - Monitor and triage security alerts from EDR/XDR, SIEM, and related security tooling; prioritize incidents based on risk and business impact. - Investigate endpoint threats (malware, ransomware, credential theft, persistence, lateral movement) using Microsoft Defender for Endpoint (MDE), CrowdStrike EDR, SentinelOne EDR, and Stellar Cyber XDR. - Perform incident response activities: evidence collection, scoping, containment, eradication, recovery, and post-incident reporting. - Conduct endpoint and host-based analysis (process trees, command-line execution, registry changes, scheduled tasks, persistence mechanisms, network connections). - Correlate telemetry across endpoint, identity, network, and cloud sources to confirm malicious activity and reduce false positives. - Execute response actions (e.g., isolate host, kill/quarantine process, block indicators, remove persistence, enforce policy changes) in accordance with playbooks and approvals. - Develop and maintain detection and response playbooks/runbooks for common attack scenarios (phishing, suspicious PowerShell, credential dumping, suspicious service creation, etc.). - Create and tune alerting rules, exclusions, and detections to improve signal quality and reduce noise while maintaining security coverage. - Document investigations thoroughly: timelines, IOCs, impacted assets/users, actions taken, and recommendations for prevention. - Support threat hunting activities using EDR/XDR telemetry and threat intelligence to identify suspicious patterns and proactively reduce risk. - Participate in on-call rotation and shift-based SOC coverage as required. - Research security enhancements and make recommendations for management. - Stay up to date on information technology trends and security standards. - Train, mentor, and guide teammates through direct comms and by hosting knowledge transfer calls. Qualifications - 2–4 years of experience in a SOC, incident response, cyber analyst or security operations role. - 2–4 years of hands-on experience working with at least one (1) of the following: - Microsoft Defender for Endpoint (MDE) - CrowdStrike EDR - SentinelOne EDR - Stellar Cyber XDR - Strong knowledge of attacker tactics and techniques aligned to MITRE ATT&CK, NIST, Lockhead Martin (e.g., persistence, privilege escalation, lateral movement, exfiltration). - Solid understanding of Windows security fundamentals (event logs, authentication, common persistence locations) and basic Linux/macOS concepts. - Familiarity with common security log sources and workflows (SIEM concepts, ticketing/case management, escalation processes). - Ability to write clear incident documentation and communicate findings to both technical and non-technical stakeholders. - Experience handling sensitive information and following documented procedures and change controls. - Strong knowledge of the Windows and Linux operating systems. - Ability to establish and maintain a strong level of customer trust and confidence. Preferred Qualifications - Experience with Microsoft security ecosystem (e.g., Defender for Identity, Defender for Cloud, Entra ID/Azure AD sign-in logs). - Basic scripting/automation skills (PowerShell, Python, or Bash) for investigation and enrichment tasks. - Familiarity with network security concepts, protocols (TCP/UDP, DNS, HTTP/S, TLS, proxies, VPNs), and packet/log analysis. - Threat hunting experience and building detections based on behavioral analytics. - Experience with vulnerability management and remediation tracking. - MSSP experience. - A bachelor’s/master's degree in cyber security or related field, or equivalent level of experience within IT. - Security certifications (nice-to-have): Security+, CySA+, GCIH, GCIA, SC-200, or equivalent. Benefits - The target salary for this role is $100,000 per year. - This position will operate in a fully remote model.

Canada
$100K / year
Job Closed
Placer.ai logo

Security Analyst

Placer.ai

The most advanced foot traffic analytics platform for anyone with a stake in the physical world.

Security Analyst33 days ago
Full TimeRemoteTeam 501-1,000Since 2016H1B No Sponsor

Role Description We are seeking a detail-oriented, self-driven Security Analyst, based in Israel, to join the Risk and Compliance team and operate Placer’s ISO-aligned Event Management Process end-to-end. This role is the front door for security events at Placer — the person who makes sure that every reported security event (from employees, vendors, and automated monitoring) is triaged, classified, escalated where required, and closed with documented evidence. The Security Analyst is both an operator and a process owner. This is an excellent entry-point role for a Computer Science graduate or similar background person looking to build a foundation in security operations and compliance. You will run the daily flow of events, partner with Corporate IT, R&D/DevOps, and the CISO to drive down events, implement improvements and take corrective and preventive actions. You will report directly to the Chief Information Security Officer and work closely with the broader employee base engaging them directly. This role covers five primary pillars: - Security Event Intake and Triage - Classification, Escalation and Coordination - Process Operations and Continuous Improvement - AI Automation This is a temporary position with an hourly pay. Responsibilities - Own the front door for all reported security events — internal security hotline, IT services alerts, employee reports, and automated monitoring. - Triage security events within defined SLAs; gather context from logs, endpoints, identity systems, and SaaS admin telemetry. - Maintain the Security Event Register as the single source of truth for every reported event — timeline, evidence, classification, owner, status, root cause, and corrective actions. - Review mail service admin holds that require review and investigation, user engagement, and follow-up. - Classify security events against the defined severity matrix; distinguish security events from incidents and apply the agreed escalation criteria consistently. - Notify the CISO when escalation criteria are met, evidence collection, and timeline capture during incidents. - Own and operate Placer’s ISO-aligned Event Management Process end-to-end. - Maintain the Security Event Management Process documentation (playbook). - Coordinate with the CISO on security event detail enrichment, false positive reduction, detection rule tuning, and playbook updates. - Continuously raise the bar on the process — automate intake, reduce mean time to triage and closure, and remove repeat security events. - Design and implement automation/AI enhancements to reporting and security event handling. - Assist the broader Risk and Compliance team with audits, control reviews, and reporting on standardization of systems security, applications. - Respond to security event escalations in a timely manner. - Prioritize responsibilities as they evolve on a day-to-day basis, and escalate appropriately. Qualifications - Computer science graduate or equivalent. - Hands-on experience in a fast-paced SaaS, cloud, or AI-first technology company is beneficial. - Demonstrated ability to apply theoretical CS concepts and logical process-driven thinking to real-world security and operations challenges. - Strong computer and SaaS services experience – business productivity tools. - AI basics or more would be of benefit. - Similar experience would be of significant value. Requirements - Working knowledge of Mac and Windows endpoints, and related security events end-to-end. - Familiarity with ticketing/case management tools (e.g., Jira) and comfort with structured data management. - Highly committed, ownership-driven, and self-motivated. - Excellent written English communication. - Strong cross-functional partner — comfortable working across Corporate IT, R&D/DevOps, Legal, and HR. - Customer-oriented mindset toward internal reporters. - Comfortable operating across U.S. and Israel time zones in a globally distributed company. Benefits - Join a rocketship! We are pioneers of a new market that we are creating. - Take a central and critical role at Placer.ai. - Work with, and learn from, top-notch talent. - Competitive salary. - Excellent benefits.

Israel
Job Closed
ICF logo

Associate Cyber Security Analyst

ICF

Founded in 1969, ICF is a global advisory and technology services company headquartered in Reston, Virginia. It delivers data-driven solutions across energy, en

Security Analyst34 days ago

Role Description This is an entry-level position expected to begin Summer 2026, and is fully-remote from any U.S. location. Travel 1-2 times per year may be required. This is a non-exempt position. The Associate Cyber Security Analyst supports the day‑to‑day operation of ICF’s information security program under the guidance of senior security staff and the Cyber Security Manager. This role assists with monitoring, maintaining, and documenting security controls and technologies, including: - Endpoint protection - Access controls - Vulnerability management - Security event monitoring Working closely with experienced analysts and internal stakeholders, the Associate Cyber Security Analyst helps: - Identify, document, and escalate security issues - Support routine security operations - Contribute to security assessments and reporting The role provides hands‑on exposure to and guidance with: - Incident response - Compliance activities - Security tooling Performance Objectives: - Detail‑oriented with a strong analytical mindset and a willingness to learn - Ability to clearly document work and communicate effectively in writing and verbally - Collaborate with technical and business stakeholders to support vulnerability remediation and security event response - Learn, follow, and document common security processes under guidance from senior team members - Assist with security request and incident ticket intake, triage, and escalation - Support the collection and creation of artifacts for audit and compliance activities - Analyze security log data to identify emerging or unusual patterns - Review and help validate vulnerability findings using established processes - Assist with the operation of infrastructure and application vulnerability scanning tools - Research and test emerging threats, vulnerabilities, and security techniques - Working knowledge of Windows, macOS, and/or Linux operating systems - Foundational understanding of networking concepts, including the OSI model, TCP/IP, routing, and switching - Familiarity with scripting or query languages such as PowerShell, Python, Java, or SQL - Assist in modifying or proposing security alerts for events of interest - Participate in on‑call rotations as part of a team, with guidance and escalation support - Assist with disaster recovery and incident response testing and exercises Qualifications - Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field or equivalent practical experience Requirements - 1–2 years of general technology experience (including internships, academic projects, or relevant hands‑on work) - Foundational knowledge of information security principles, common security practices, and log monitoring/analysis concepts - Familiarity with cloud platforms (Azure and/or AWS) and common security tools through coursework, labs, or hands‑on experience (e.g., vulnerability scanners, network analysis tools, penetration testing frameworks) - Exposure to security monitoring and incident response fundamentals, including network traffic analysis - Basic scripting or automation experience (e.g., simple scripts or academic projects) - Awareness of emerging technologies, including the use of generative or agentic AI in security contexts - Strong interest in learning and developing cybersecurity skills - Ability to manage multiple tasks, adapt to changing priorities, and operate effectively in time‑sensitive situations - Demonstrated professionalism and discretion in handling sensitive information - Flexibility to support extended hours or incident response activities, as needed - Entry‑level cybersecurity certifications (e.g., CompTIA Security+ or equivalent) a plus Benefits - Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process. - Pay Range: $61,232.00 - $104,094.00 based on full-time employment.

United States
$61.2K - $104.1K / year