Cyber Systems Engineer 3– Cyber Tools Engr (ESS) (26-309)

Posted 3 Days Ago
Be an Early Applicant
Colorado Springs, CO, USA
In-Office
114K-171K Annually
Senior level
Aerospace • Logistics • Security • Software • Cybersecurity
The Role
Design, deploy, configure, and maintain Trellix (ePO/ENS) endpoint security across Windows and Linux; perform large-scale deployments, patching, and optimization; troubleshoot and tune policies; implement STIG/compliance controls; create SOPs and documentation; research Trellix updates and automate remediation workflows.
Summary Generated by Built In
RELOCATION ASSISTANCE: No relocation assistance available

CLEARANCE REQUIRED FOR START: Yes

CLEARANCE TYPE: Secret

TRAVEL: NoDescription

At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work — and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.

Northrop Grumman Space Systems—Missile Defense Integration offers an excellent opportunity for a Principal Cyber Systems Engineer – Cyber Tools Engineer (ESS) (26-309) to join our team of skilled and diverse professionals. Based in Colorado Springs, CO, this role is essential to supporting the U.S. President, the Secretary of Defense, and combatant commanders at the strategic, regional, and operational levels.

This position does not provide relocation assistance and requires on-site work with no remote options.

Position Overview:

The Command and Control, Battle Management, and Communications (C2BMC) program is a key component of the Missile Defense System. It is a vital operational system that enables the U.S. president, the secretary of defense, and combatant commanders at strategic, regional, and operational levels to systematically plan ballistic missile defense operations, collectively monitor the battle, and dynamically control networked sensors and weapon systems to achieve global and regional mission goals. C2BMC supports layered missile defense capabilities that enable an optimized response to threats across all ranges and flight phases. It serves as a force multiplier by networking, integrating, and synchronizing autonomous sensor and weapon systems and operations, both globally and regionally, to improve performance. C2BMC is essential for all ground and flight tests that verify and demonstrate the current and future capabilities of missile defense systems.

Essential Functions:

  • Design, develop, configure, and maintain security policies, tasks, and deployments for the Trellix Endpoint Security Suite, including ePolicy Orchestrator (ePO), Endpoint Security (ENS), the C2BMC Testbed (CTB), and Ops in the NT labs

  • Perform large-scale deployments, upgrades, patching, and optimization of Trellix agents and servers across Windows and Linux environments while minimizing disruption to operations

  • Develop and maintain comprehensive technical documentation, including standard operating procedures (SOPs), policy guides, STIG compliance reports, and configuration baselines

  • Troubleshoot complex endpoint security issues, conduct root-cause analysis, tune policies to reduce false positives, and implement automated remediation workflows

  • Assist with implementing STIG, conducting security audits, and meeting continuous monitoring needs

  • Research and assess new Trellix features, updates, and best practices; suggest improvements to enhance the endpoint security program

Basic Qualifications:

 

Please list your current security clearance and IAT or relevant certifications on your resume, if applicable.

 

  • A Bachelor’s Degree in Computer Science, Software Engineering, Computer Engineering, Mathematics, Physics, or a related field from an accredited university, along with 5 years of experience; or a Master’s degree in a related field with 3 years of relevant work experience; or 9 years of relevant work experience may be considered as an alternative to a degree

  • Applicants must have a current, active DoD 8140 certification at IAT Level II or higher (such as Security+ CE, CCNA-Security, CySA+, CND, etc.) at the time of application, which is required to start. The candidate is responsible for maintaining their DoD 8140 certification throughout the entire contract period

  • Applicants must have a current, active in-scope DoD-issued Secret security clearance at the time of application, which is required to start

  • 5–8 years of progressively responsible experience in IT security or systems administration, including at least 3 years of hands-on experience administering and engineering Trellix (or legacy McAfee/HBSS) Endpoint Security solutions

  • Proven experience deploying, configuring, and maintaining Trellix ePO, Endpoint Security (ENS), and related components (e.g., Application Control, DLP, and Threat Intelligence) in medium- to large-scale enterprise environments

  • Demonstrated ability to develop and fine-tune security policies, automate tasks through scripting, and create technical documentation for operational use and compliance

  • Extensive experience with Windows Server and client administration, with a working knowledge of Linux endpoint management

  • Deep expertise in Trellix ePO administration, policy creation, extensions, and reporting

  • In-depth understanding of Trellix Endpoint Security (ENS), including firewall, exploit prevention, and adaptive threat protection features

  • Strong understanding of endpoint security concepts, threat-hunting basics, malware analysis, and zero-trust principles

  • Strong technical writing and documentation skills, capable of creating clear SOPs and compliance artifacts

  • Possesses strong analytical and troubleshooting skills to resolve complex endpoint issues

  • Ability to work both independently and as part of a team while handling multiple priorities

  • Strong communication skills to clearly explain technical concepts to both technical and non-technical stakeholders

Preferred Qualifications:

  • Experience in supporting endpoint security within DoD, federal agencies, or similarly regulated sectors is highly preferred. This includes managing STIG compliance and security baseline controls

What We Can Offer You:

Northrop Grumman provides a comprehensive benefits package and a supportive work environment that encourages your growth, benefiting both employees and the company. The benefits are flexible and customizable, enabling you to choose options that suit your individual and family needs. Your benefits will include the following:

  • Health Plan
  • Savings Plan
  • Paid Time Off
  • Education Assistance
  • Training and Development
  • Flexible Work Arrangements

https://benefits.northropgrumman.com/us/en2/BenefitsOverview/Pages/default.aspx

#NGSpace

#COSpace

#NGFeaturedJobs

#C2BMC

Primary Level Salary Range: $113,900.00 - $170,900.00

The above salary range represents a general guideline; however, Northrop Grumman considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills and current market conditions.

Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. Annual bonuses are designed to reward individual contributions as well as allow employees to share in company results. Employees in Vice President or Director positions may be eligible for Long Term Incentives. In addition, Northrop Grumman provides a variety of benefits including health insurance coverage, life and disability insurance, savings plan, Company paid holidays and paid time off (PTO) for vacation and/or personal business.

The application period for the job is estimated to be 20 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.

Northrop Grumman is an Equal Opportunity Employer, making decisions without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class. For our complete EEO and pay transparency statement, please visit http://www.northropgrumman.com/EEO. U.S. Citizenship is required for all positions with a government clearance and certain other restricted positions.

Skills Required

  • Bachelor's degree in Computer Science, Software Engineering, Computer Engineering, Mathematics, Physics, or related field with 5 years experience; OR Master's with 3 years; OR 9 years relevant experience as alternative
  • Current, active DoD 8140 certification at IAT Level II or higher (e.g., Security+ CE, CCNA-Security, CySA+, CND)
  • Current, active DoD-issued Secret security clearance at time of application
  • 5-8 years of IT security or systems administration experience, including at least 3 years hands-on administering and engineering Trellix (or McAfee/HBSS) Endpoint Security solutions
  • Proven experience deploying, configuring, and maintaining Trellix ePO, ENS, Application Control, DLP, and Threat Intelligence components in medium- to large-scale enterprise environments
  • Ability to develop and fine-tune security policies, automate tasks through scripting, and create technical documentation and SOPs
  • Extensive experience with Windows Server and client administration and working knowledge of Linux endpoint management
  • Deep expertise in Trellix ePO administration, policy creation, extensions, and reporting
  • In-depth understanding of Trellix ENS features including firewall, exploit prevention, and adaptive threat protection
  • Strong understanding of endpoint security concepts, threat-hunting basics, malware analysis, and zero-trust principles
  • Strong technical writing and documentation skills for compliance artifacts and SOPs
  • Analytical and troubleshooting skills to resolve complex endpoint security issues
  • Ability to work independently and as part of a team while handling multiple priorities
  • Strong communication skills to explain technical concepts to technical and non-technical stakeholders
  • Experience supporting endpoint security within DoD, federal agencies, or similarly regulated sectors and managing STIG compliance
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
85,636 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account