Principal Cybersecurity Engineer Jobs
Principal Cybersecurity Engineer jobs are open across defense, financial services, healthcare, and enterprise technology, from senior individual contributor to staff and principal levels, with specializations in cloud security, threat architecture, and identity and access management. Find a role that fits from the openings below and apply directly.
Find JobsOverview
Showing 4 of 47+ Principal Cybersecurity Engineer jobs









Description
At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to be at the forefront of many technological advancements in our nation's history - from the first flight across the Atlantic Ocean, to stealth bombers, to landing on the moon. We look for people who have bold new ideas, courage and a pioneering spirit to join forces to invent the future, and have fun along the way. Our culture thrives on intellectual curiosity, cognitive diversity and bringing your whole self to work — and we have an insatiable drive to do what others think is impossible. Our employees are not only part of history, they're making history.At the heart of Defining Possible is our commitment to missions. In rapidly changing global security environments, Northrop Grumman brings informed insights and secure technological solutions to enable strategic objectives. We’re looking for innovators who can help us keep building on our wide portfolio of secure, affordable, integrated, and multi-domain systems and technologies that fuel those missions. By joining in our shared mission, we will support yours by expanding your personal network and developing skills, whether you are new to the field or an industry thought leader. At Northrop Grumman, you will have the resources, support, and team to do some of the best work of your career.
The Northrop Grumman Classified Solutions team is seeking a Principal Classified Cybersecurity Analyst to support information systems lifecycle activities. The selected candidate will be required to work on-site, full-time at our Roy, Utah location.
We are looking for an experienced professional to design, integrate, and maintain Cross‑Domain Solutions (CDS) that enable secure, policy‑compliant data transfer between classified and unclassified networks. The role includes conducting risk assessments, configuring hardware/software, performing rigorous testing, and providing ongoing support to ensure continuous compliance with US Government security directives.
The responsibilities of this role include, but are not limited to, the following:
Manage the cybersecurity program of all assigned information systems and execute all cybersecurity-related tasks.
Conduct and lead regular reviews of system audits and continuous monitoring activities, covering all security controls and configurations, to enhance operational efficiencies of the information system security posture.
Perform assessments of systems and networks within the networking environment or enclave and identify where those systems and networks deviate from acceptable configurations, enclave policy, or local policy.
Perform analyses to validate established security requirements and to recommend additional security requirements and safeguards.
Drive the implementation of the required government policy, make recommendations on process tailoring, participate in and document process activities.
Establish and oversee strict program control processes that mitigate risk and support system Assessment and Authorization (A&A). This includes process support, analysis, coordination, security certification testing, security documentation, investigations, software research, hardware introduction and release, emerging technology research, inspections, and periodic audits.
Lead the formal Security Test and Evaluation (ST&E) required by each government accrediting authority through pre-test preparations, participation in the tests, analysis of the results and preparation of required reports.
Document the results of A&A activities, and inspection activities, along with any technical or corrective actions and work collectively with the security team to submit responses to the appropriate cognizant authority.
Prepare, review, and submit A&A documentation (System Security Plan, Risk Acceptance Report, Security Controls Traceability Matrix, Plan of Action and Milestones, etc.) for review and approval.
Note: Due to the classified nature of the work being performed, this position does not offer any virtual or telecommute working options. Applicants are encouraged to apply only if they are willing to work on-site.
Basic Qualifications:
Master's Degree with 3 years of experience; OR a Bachelor's Degree with 5 years of experience; OR an Associate's Degree with 7 years of experience; OR a High School Diploma (or equivalent) with 9 years of experience is required
Candidates must meet the U.S. Government 8140 requirements for a Cybersecurity (722) – (Example: Security+ CE, CySA+, GICSP, GSEC, CND, SSCP)
Candidates must have a current U.S. Government Top Secret security clearance (at a minimum), to include a closed investigation date completed within the last 6 years OR must be enrolled in the U.S. Government Continuous Evaluation (CE) Program to be considered
Candidates must have the ability to obtain, and maintain, access to Special Access Programs as a condition of continued employment
Preferred Qualifications:
Bachelor’s degree in Cybersecurity or related field
Experience in cybersecurity compliance (ex. Assessment & Authorization under RMF)
Knowledge of security tools such as ACAS, Nessus, Splunk, Trellix, and SCAP
Knowledge of security frameworks and documentation such as NIST, JSIG, DAAG, SSPs, POA&Ms, and SCTMs
Proven experience designing, implementing, and supporting Cross Domain Solutions (CDS) for secure data transfer across classified networks.
We offer flexible work arrangements, phenomenal learning opportunities, exposure to a wide variety of projects and customers, and a very friendly team environment. At Northrop Grumman, we are on the cutting edge of innovation. Our diverse portfolio of programs means there are endless paths to cultivate your career. We also offer exceptional benefits/healthcare, a 9/80 work schedule, and a great 401k matching program. Come join us!
CIDO
Principal Cybersecurity Engineer Jobs by Experience Level
See All 47 Principal Cybersecurity Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsPrincipal Cybersecurity Engineer Job Market
Who's Hiring



Top Industries Hiring
- Automotive
- Food & Beverage
- Medical Devices
- Technology & Software
What Employers Look For
The qualifications that appear most often in principal cybersecurity engineer jobs.
- Ten or more years of progressive cybersecurity experience with at least three in a senior or lead role
- Active CISSP, CISM, or equivalent enterprise security certification
- Demonstrated experience designing zero-trust or defense-in-depth security architectures at scale
- Proficiency with cloud security controls across AWS, Azure, or Google Cloud environments
- Experience leading security program strategy, roadmap development, and cross-functional stakeholder communication
- Familiarity with compliance frameworks including NIST CSF, SOC 2, ISO 27001, or FedRAMP
Tips for Your Principal Cybersecurity Engineer Job Search
Tailor your resume to architecture depth
Principal-level postings screen for evidence of system-wide security design, not just implementation. Lead each bullet with the architecture decision you owned, the threat model it addressed, and the outcome, not just the tools you used.
List certifications in priority order
CISSP, CISM, and cloud-provider security specializations carry different weight depending on the employer's stack. Put the certification that matches the posting's environment first on your credentials line so screeners see the right signal immediately.
Apply early to roles that fit
Migrate Mate lists principal cybersecurity engineer openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Target postings that name your threat domain
Search for your specific specialty, whether that's OT security, zero-trust implementation, or red-team program leadership, not just the title. Postings that name your domain get far fewer competing applicants than generic principal engineer searches.
Prepare a technical design narrative
Principal interviews almost always include a whiteboard or async architecture exercise. Walk through one past security architecture you designed end-to-end, including the constraints you faced and the tradeoffs you made, so you can adapt it to any scenario they present.
Negotiate scope before you negotiate pay
At the principal level, the reporting structure, program ownership, and whether you have hiring authority shape the role's actual value. Clarify those before you get to compensation, because a constrained scope with a high title is a lateral move in practice.
Principal Cybersecurity Engineer Jobs: Frequently Asked Questions
Which companies are hiring the most principal cybersecurity engineers?
The companies hiring the most principal cybersecurity engineers right now include Northrop Grumman, PepsiCo, and JPMorganChase, with the largest share of openings in Texas, California, and Massachusetts, based on current listings on Migrate Mate as of September 2026. Defense contractors, large financial institutions, and cloud-native technology companies consistently post the highest volume of principal-level security roles.
How many principal cybersecurity engineer jobs are remote?
About 29% of principal cybersecurity engineer openings are fully remote or hybrid as of September 2026, making it one of the more flexible senior engineering roles. Threat architecture, cloud security, and governance-focused positions tend to offer the most remote flexibility, while roles tied to classified environments or on-premises infrastructure typically require on-site presence.
How do you become a principal cybersecurity engineer?
Becoming a principal cybersecurity engineer typically requires progressing from a security analyst or engineer role through senior and lead positions while building ownership of increasingly complex architecture decisions. Earning enterprise-recognized certifications, leading cross-functional security initiatives, and demonstrating program-level impact rather than task execution are the steps that distinguish principal candidates from senior ones.
Can you get a principal cybersecurity engineer job without deep leadership experience?
It's difficult, because most principal postings treat program ownership and cross-team influence as baseline expectations rather than growth opportunities. The most realistic path without a formal leadership title is to document the security architecture decisions you drove independently, the business risk you quantified, and the teams whose roadmaps you shaped, then apply to companies where the principal role is defined as a technical track rather than a people-management step.
What does the principal cybersecurity engineer interview process look like?
The process typically runs across multiple rounds, starting with a recruiter screen focused on scope and seniority, followed by a technical panel covering threat modeling, architecture tradeoffs, and your approach to security program design. Most employers at this level also include a cross-functional interview with product, engineering, or legal stakeholders to assess how you communicate risk and drive alignment outside the security team.
Where can I find and apply to principal cybersecurity engineer jobs?
You can find and apply to principal cybersecurity engineer jobs on Migrate Mate, which lists current openings from across the United States. Find roles that match your background and apply directly to each listing from the results on this page.
See All 47 Principal Cybersecurity Engineer Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs