> Markdown version of [/jobs/ext/1800203-program-information-system-security-manager-special-access-programs-woburn-ma](https://www.wearedevelopers.com/jobs/ext/1800203-program-information-system-security-manager-special-access-programs-woburn-ma). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Program Information System Security Manager - Special Access Programs - Woburn, MA - **Company:** RTX - **Location:** Woburn, MA, United States - **Experience:** Expert - **Salary:** $107,500.0 - $204,500.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Computer Networks, Databases, Identity and Access Management, Information Security Management, SAP Implementation, Security Information and Event Management, Information Technology, National Industrial Security Program Operating Manual (NISPOM), Splunk, Vulnerability Analysis - **Published:** July 31, 2026 - **Apply:** https://globalhr.wd5.myworkdayjobs.com/REC_RTX_Ext_Gateway/job/US-MA-WOBURN-WB1--235-Presidential-Way--SPENCER-BLDG/Program-Information-System-Security-Manager---Special-Access-Programs---Woburn--MA_01863562 ## About the Role Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance, * Typically a Bachelors Degree or equivalent experience and minimum 8 years prior relevant experience, or an Advanced Degree in a related field and minimum 5 years experience * Experience supporting cybersecurity compliance as stipulated by the Joint SAP Implementation Guide (JSIG), DCSA Assessment and Authorization Guide (DAAG), and/or National Industrial Security Program Operating Manual (NISPOM) regulations * Direct leadership or project/program management experience * IAM Level I certification (Security+ or other) * Relevant Experience Considered: + Cybersecurity, systems security or hardening + Information Technology + Compliance-based auditing using the Risk Management Framework (RMF) and/or non-defense regulations such as FAA, Payment Card Industry (PCI), ISO 9001 Quality Management standards, or HIPPA + Experience working with and/or supporting computer technologies (such as: databases, operating systems, computer network hardware, software programs, hardware troubleshooting or electronics) + Physical security/security, policework/criminal justice, investigations, or Border Patrol + Project or program management, office management, senior administration, or account management, * Experience supporting Special Access Programs as either an ISSM or ISSO. * Master's Degree in Computer Science, Information Systems, Information Technology, Cyber Security, Criminal Justice, Business or other relevant degree * Experience with various information system security tools that address vulnerability analysis and mitigation. These may include Splunk, Forcepoint, Ivanti, Tenable, ACAS, HBSS, etc. * Experience in the oversight and execution of the Assessment & Authorization processes (Certification & Accreditation), as defined in the JSIG/RMF * Experience in the execution and management of Information System's (IS) incident response and administrative inquiries/investigations in collaboration with the Investigations department * Experience in and execution of a continuous monitoring/improvement program (to include but not limited to self-inspections, security control assessments, training, log management systems, automated inventory utilities, etc.) * Experience providing technical security expertise and oversight for complex, cross-domain, heterogeneous classified networked environments in collaboration with internal/external Customers, Information Technology (IT) and other Raytheon Business Units * Experience working with the customer, both internal and external in the development of Basis of Estimates (BOE's) and contract negations * Experience with any of the following: NISPOM, JAFAN 6/3, DCID 6/3, JSIG/RMF, and ICD-503 or equivalent requirements to include technical computer/network system auditing * Experience in professional engagements with internal and external customers (i.e., AOs, DAOs, SCAs, Program Managers, etc.), to include negotiating controls/requirements with government Contracting Activities ## Description Our Cybersecurity team is seeking a Program Information System Security Manager (ISSM) - Special Access Programs to support our Special Access Program classified computing environments 100% onsite at our facility in Woburn, Massachusetts. The Cybersecurity Program Information Systems Security Manager is responsible for compliance oversight, assessment, and operations of systems under their purview. They may be assigned to a single large-scale program or oversee multiple programs. The Program ISSM has cognizance over classified programs at the Woburn site per Commercial and Government Entity (CAGE) code as stipulated by various US Government requirements including (but not limited to): National Industrial Security Operating Manual (NISPOM) and related documentation such as: Risk Management Framework (RMF),Joint SAP Implementation Guide (JSIG)Intelligence Community Directive 503 (ICD 503)Baseline Technical Security Configuration Standards, DCSA Assessment and Authorization Guide (DAAG)Customer/contract specific Cybersecurity regulations. What You Will Do * Complete Raytheon GSS required training within 6 months of appointment (annual requirements thereafter). * Accountability for classified systems under site CAGE and SBU: metrics, Raytheon business process (RCAST), Continuous Monitoring (ConMon) as described by Sr. ISSM * Maintaining a working knowledge of all classified functions, security policies, technical security safeguards, and operational security measures. * Interactions with SCA to track items including, but not limited to, upcoming authorizations (ATO), new technologies solutions (i.e., new SIEM, OS, etc.), policy interpretations (in conjunction with Sr. ISSM), and onsite inspections. * Developing, maintaining, and updating, in coordination with all system stakeholders (CS Manager, ISO, DT, etc.), applicable site POAM(s) to identify system weaknesses, mitigating actions, resources, and timelines for corrective actions. * Coordinating customer inspection preparation activities for assigned sites in conjunction with Program/Industrial Security. Important note: Within six months of hire date, you must obtain and maintain a Security professional certification commensurate with IAM Level III certification commensurate with your role as a Site ISSM as required by DoDD 8140 (8570) if you do not already have this certification. ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers)