Information System Security Manager (Onsite)

PW100: East Hartford 400 Main Street, East Hartford, CT, 06118 USA

RTX

At RTX, we're accelerating ideas to solve some of the world's biggest challenges by bringing together the brightest, most innovative minds across aviation, space and defense.

View all jobs at RTX

Apply now Apply later

Date Posted:

2024-09-12

Country:

United States of America

Location:

PW100: East Hartford 400 Main Street, East Hartford, CT, 06118 USA

Position Role Type:

Onsite

 

Pratt & Whitney is working to once again transform the future of flight—designing, building and servicing engines unlike any the world has ever seen. And because transformation begins from within, we’re seeking the people to drive it. So, calling all curious. 

Come ready to explore and you’ll find a place where your talent takes flight—beyond the borders of title, a country or your comfort zone. Bring your passion and commitment and we’ll welcome you into a tight-knit team that takes our mission personally. Channel your drive to make a difference into shaping an organization and an industry that’s evolving fast to the future.

Innovation through diversity of thought. At Pratt & Whitney, we believe diversity of thought enables creativity, innovation, and a foundation for inclusion. By fostering an inclusive culture, we accept a shared accountability and responsibility to recognize, sponsor, coach, hire and promote talent equally. We welcome our employees to be their whole - best - selves at work because trust, respect and integrity, are a part of our DNA.

At Pratt & Whitney, the difference you make is on display every day. Just look up. Are you ready to go beyond?

The Information Systems Security Manager (ISSM) you will document, monitor, and maintain the overall cybersecurity posture of one or more information systems within the Military Engines (ME) portfolio of programs in compliance with applicable U.S. Department of Defense (DoD) security laws and regulations.  The ISSM will participate in projects, guide and counsel internal customers, assist in developing and maintaining cross-security enclave processes and standards, and provide training and guidance on tools and methods to other members of the cybersecurity team that report directly to the Programs Cybersecurity Enclave Manager.

What You Will Do:

  • Under the direction of the Enclave Senior Manager, serve as an information systems security lead for information technology-related projects supporting the Military Engines portfolio of programs. Develop and maintain required plans, policies and procedures for assigned information systems in order to obtain Authority To Operate (ATO) from the government under the Risk Management Framework (RMF).
  • Lead or participate in working groups to establish, review, and update standard procedures and work instructions, drive the closure of POA&M items for technology-related control issues in Enclave information systems, and provide cybersecurity guidance for all hardware and software changes to assigned information systems
  • In collaboration with the incident response manager, coordinate and/or perform incident response containment, eradication, and recovery tasks involving classified systems and/or spills of classified data to unauthorized systems.
  • Coach, mentor, and train ISSOs on standard work, procedures, plans, and policies in line with IS-specific and Enclave-level guidelines, while developing or updating training content as directed by the Enclave Manager and performing all ISSO functions in their absence.
  • Evaluate and monitor COTS and GOTS systems, applications, and services against system architectures and RMF requirements, partner with development teams and the US Government to ensure timely task completion, assist in managing patch management across security enclaves, and collaborate with peer ISSMs and Corporate equivalents to align and share best practice.Assist in overseeing and managing the patch management process and execution across all security enclaves.  Collaborate with peer ISSMs and Corporate equivalents for alignment and sharing of best practices.
  • Audit security controls and provide technical direction and assistance with corrective or mitigation actions. Perform continuous monitoring task.

Qualifications You Must Have:

  • Bachelor’s Degree OR In lieu of a degree, a High School Diploma combined with 12 years of experience ​
  • 8 years of engineering, cybersecurity, computer science, or IT experience, or 5 years of engineering, cybersecurity, computer science, or IT experience with an advanced degree.
  • Must be a U.S. Citizen. This position may require access to systems/tools that are restricted to individuals who possess US citizenship.
  • The ability to obtain and maintain a U.S. government issued security clearance is required. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance.
  • Ability to obtain access to Special Access Programs.
  • 2 years hands-on experience in an ISSO, ISSM and/or ISSM role and 4 years’ combined hands-on experience in systems administration/engineering and/or cybersecurity support role for a combination of servers, desktop computers, operating systems, and virtual computing, preferably of information systems supporting classified programs or activities.
  • Certifications equivalent to or exceeding DoD 8570.01-M IAT Level II functional and baseline certification requirements.

Qualifications We Prefer:​

  • Ability to develop, document and interpret network and wiring diagrams; system, subsystem and device security architectures down to the board level; and data flow diagrams.
  • Programming experience with languages such as (but not limited to) bash, csh, Java/JavaScript, Perl, Powershell, Python, sh, and/or VBA.
  • Experience with using NESSUS and other scanning applications.
  • Experience using Splunk to ingest and analyze network data.
  • Experience with implementation of and/or monitoring the compliance of information systems to NIST, CIS, and/or ISO cybersecurity management framework requirements and guidelines.
  • Experience in the execution of the Assessment & Authorization processes, as defined within the Risk Managed Framework (RMF)

Learn More & Apply Now:

In addition to transforming the future of flight, we are also transforming how and where we work. We’ve introduced role types to help you understand how you will operate in our blended work environment. This role is: 

Onsite: Employees who are working in Onsite roles will work primarily onsite. This includes all production and maintenance workers, as they are essential to the development of our engines.

Candidates will learn more about role type and current site status throughout the recruiting process. For onsite and hybrid roles, commuting to and from the assigned site is the employee’s personal responsibility.

The salary range for this role is 96,000 USD - 200,000 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate’s work experience, location, education/training, and key skills.

Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.

Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company’s performance.

This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.

RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.

RTX is An Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class.

Privacy Policy and Terms:

Click on this link to read the Policy and Terms

Apply now Apply later
  • Share this job via
  • 𝕏
  • or
Job stats:  1  0  0
Category: Leadership Jobs

Tags: Bash Clearance Compliance Computer Science DoD DoDD 8570 Incident response Java JavaScript Monitoring Nessus NIST Perl POA&M PowerShell Privacy Python Risk management RMF Security Clearance Splunk

Perks/benefits: 401(k) matching Career development Flex hours Flex vacation Health care Insurance Medical leave Parental leave Team events

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.