Program Information Systems Security Manager

RTX
Tucson, AZ, United States
4 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$107,500.0 - $204,500.0
Working hours
Regular working hours

Tech stack

Cyber Security Information Systems Computer Networks Databases System Configuration Data Security File Transfer Design of User Interfaces Human-Computer Interaction Identity and Access Management Systems Analysis Information Technology Audit
+12 more
Internet Security SAP (Applications) SAP Implementation Security Information and Event Management Software Configuration Management System Testing Computer Networking Systems Computer Equipment Information Technology National Industrial Security Program Operating Manual (NISPOM) Splunk Vulnerability Analysis

Job description

Our cybersecurity team is seeking a Program Information Systems Security Manager (ISSM) to support our team 100% onsite at our facility in Tucson, Arizona.

The Program Information Systems Security Manager is responsible for compliance oversight, assessment, and operations of systems under their purview. They may be assigned to a single large-scale program or oversee multiple programs.

ISSM also has cognizance of all collateral Classified Information System (CIS) at the Site per Commercial and Government Entity (CAGE) code as stipulated by various US Government requirements including (but not limited to):

National Industrial Security Operating Manual (NISPOM) and related documentation such as:

  • Risk Management Framework (RMF),
  • Baseline Technical Security Configuration Standards,
  • Defense Counter-Intelligence Security Agency (DCSA)
  • Assessment and Authorization Process Manual (DAAPM)
  • Customer/contract specific Cybersecurity regulations.

Components of the cybersecurity (CS) program include Assessment and Authorization (A&A) activities (documentation preparation, system configuration/validation, certification testing, etc.), security sustainment activities (hardware change management, software change management, account management, media protection, user interface, file transfers, etc.), conducting self-inspections, and delivering information systems security education and awareness.

You will conduct recurring Cybersecurity reviews on information systems in accordance with DoD Manuals, NIST Special Publications, customer directives, and company policies as applicable.

You are responsible for the execution of the Raytheon Continuous Monitoring Plan as required by CA-2 Security Assessments. You’ll serve as subject matter experts (SME) on a broad range of Cybersecurity topics. You may represent the Cybersecurity organization and business unit to external Cybersecurity counterparts.

What You Will Do

  • Cybersecurity Site ISSMs are required to maintain IAM Level III certification commensurate with their role as required by DoDD 8140 (8570).
  • Complete all DCSA and Raytheon GSS required training within 6 months of appointment (annual requirements thereafter).
  • Accountability for all systems under site CAGE: metrics, eMASS, Raytheon business process (RCAST), Continuous Monitoring (ConMon) as described by Sr. ISSM
  • Maintaining a working knowledge of all CIS functions, security policies, technical security safeguards, and operational security measures.
  • Interactions with DCSA SCA/ISSP to track items including, but not limited to, upcoming authorizations (ATO), new technologies solutions (i.e., new SIEM, OS, etc.), policy interpretations (in conjunction with Sr. ISSM), and onsite A&A.
  • Developing, maintaining, and updating, in coordination with all system stakeholders (CS Manager, ISO, DT, etc.), applicable site POAM(s) to identify system weaknesses, mitigating actions, resources, and timelines for corrective actions.
  • Coordinating DCSA SVA preparation activities for assigned CAGE in conjunction with site FSO/CS Manager. AS

Important note: Within six months of hire date, you must obtain and maintain a Security professional certification commensurate with IAM Level III certification commensurate with your role as a Program ISSM as required by DoD 8140 (8570) if you do not already have this certification.

Requirements

  • Typically a University Degree or equivalent experience and minimum 8 years prior relevant experience, or An Advanced Degree in a related field and minimum 5 years experience.
  • Experience supporting cybersecurity compliance as stipulated by DCSA Assessment and Authorization Process Manual (DAAPM), Joint SAP Implementation Guide (JSIG), and/or National Industrial Security Program Operating Manual (NISPOM) regulations
  • Direct leadership or project/program management experience
  • IAM Level I certification (Security+ or other)
  • Relevant Experience Considered:
  • Cybersecurity, systems security or hardening
  • Information Technology
  • Compliance-based auditing using the Risk Management Framework (RMF) and/or non-defense regulations such as FAA, Payment Card Industry (PCI), ISO 9001 Quality Management standards, or HIPPA
  • Experience working with and/or supporting computer technologies (such as: databases, operating systems, computer network hardware, software programs, hardware troubleshooting or electronics)
  • Physical security/security, policework/criminal justice, investigations, or Border Patrol
  • Project or program management, office management, senior administration, or account management, * Master’s Degree in Computer Science, Information Systems, Information Technology, Cyber Security, Criminal Justice, Business or other relevant degree
  • Experience with various information system security tools that address vulnerability analysis and mitigation. These may include Splunk, Forcepoint, Ivanti, Tenable, ACAS, HBSS, etc.
  • Experience in the oversight and execution of the Assessment & Authorization processes (Certification & Accreditation), as defined in JSIG/RMF
  • Experience in the execution and management of Information System’s (IS) incident response and administrative inquiries/investigations in collaboration with the Investigations department
  • Experience in and execution of a continuous monitoring/improvement program (to include but not limited to self-inspections, security control assessments, training, log management systems, automated inventory utilities, etc.)
  • Experience providing technical security expertise and oversight for complex, cross-domain, heterogeneous classified networked environments in collaboration with internal/external Customers, Information Technology (IT) and other Raytheon Business Units
  • Experience working with the customer, both internal and external in the development of Basis of Estimates (BOE’s) and contract negations
  • Experience with any of the following: NISPOM, JAFAN 6/3, DCID 6/3, JSIG/RMF, and ICD-503 or equivalent requirements to include technical computer/network system auditing
  • Experience in professional engagements with internal and external customers (i.e., AOs, DAOs, SCAs, Program Managers, etc.), to include negotiating controls/requirements with government Contracting Activities, Administrative Management, Aerospace and Defense, Affirmative Action, Auditing, Business Processes, Certification & Accreditation Process (C&A), Change Management, Computer Hardware, Computer Networks, Computer Science, Computer Security, Contract Requirements, Corporate Policies, Corrective Action, Criminal Justice, DCID - Director of Central Intelligence Directive, Data Access Objects (DAO), Defense Intelligence, DoD Directive 8140, DoD Directive 8570, Documentation, Electronics, Federal Aviation Administration (FAA), Government Contracts, Government Requirements, HIPAA (Health Insurance Portability and Accountability Act), IAM - Information Assurance Management, ISO (International Organization for Standardization), ISO 9001, Identify Issues, Incident Response, Information Technology & Information Systems, Information Technology/Systems Audit, Intelligence Agencies, International Classification of Diseases (ICD), Internet Security, Leadership, Life Insurance, Maintain Compliance, Management of Information Systems/Technology (MIS), Metrics, Negotiation Skills, Network Software, Network System Hardware, Network Systems, Office Management, Operating Systems, Operational Measurement, Operations Security (OPSEC), PCI, Physical Security, Product Development, Program Evaluation, Project/Program Management, Publications, Quality Management, Quality Metrics, RTX, Regulations, Rehabilitation Act, Research & Development (R&D), Risk Management Framework (RMF), SAP, Sales Management, Security Analysis, Security Clearance, Security Information and Event Management (SIEM), Security Monitoring, Splunk, System Operations, System Validation, Systems Administration/Management, Systems Analysis, Team Building, Team Player, Technical Support, U.S. National Institute of Standards and Technology (NIST), United States Citizen, United States Department of Defense (DoD), User Interface/Experience (UI/UX), Validation Testing, Vision Plan

Benefits & conditions

The salary range for this role is 107,500 USD - 204,500 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate’s work experience, location, education/training, and key skills.

Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.

Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company’s performance.

This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.

RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.

RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans’ Readjustment Assistance Act.

Privacy Policy and Terms

About the company

At RTX, the world largest aerospace and defense company, 185,000 great minds are united by purpose and inspired to make a difference solving the world’s most complex problems. With our three market leading businesses, world-class operations and investments in research and development, we offer capabilities and opportunity no one else can. Together, we push the boundaries of known science and find new ways to connect and protect our world.

Raytheon brings the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today’s mission and stay ahead of tomorrow’s threat. We deliver solutions that help our nation and allies defend freedoms and deter aggression, creating a safer, more secure world. Join us and help shape the future of aerospace and defense., Our values drive our actions, behaviors, and performance with a vision for a safer, more connected world. At RTX we value: Trust, Respect, Accountability, Collaboration, and Innovation.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

Videos

See all

Related articles

See all