RTX Corporation is a defense, aerospace system, and homeland security company that specializes in providing state-of-the-art electronics, mission systems integr
Information System Security Officer
Location
Massachusetts
Posted
1 day ago
Salary
$68.9K - $131.1K / year
Seniority
Senior
Job Description
Information System Security Officer
RTX Corporation
Title: Information System Security Officer Location: Woburn United States Job Description: Country: United States of America Location: US-MA-WOBURN-WB2 ~ 225 Presidential Way ~ GODDARD BLDG Position Role Type: Onsite U.S. Citizen, U.S. Person, or Immigration Status Requirements: Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance Security Clearance Type: Secret - Current Security Clearance Status: Active and existing security clearance required on day 1 At RTX, the world largest aerospace and defense company, 185,000 great minds are united by purpose and inspired to make a difference solving the world's most complex problems. With our three market leading businesses, world-class operations and investments in research and development, we offer capabilities and opportunity no one else can. Together, we push the boundaries of known science and find new ways to connect and protect our world. Raytheon brings the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. We deliver solutions that help our nation and allies defend freedoms and deter aggression, creating a safer, more secure world. Join us and help shape the future of aerospace and defense. Our cybersecurity team, is seeking an Information System Security Officer (ISSO) to support our team 100% onsite at our facility in Woburn, Massachusetts. You will interface and collaborate with the Information Systems Security Manager (ISSM) to ensure adherence to all NISPOM Chapter 8, DAAPM, JSIG policies. What You Will Do - You will be primarily responsible for system compliance, auditing, security plan development and delivering information systems security education and awareness. - You will also assist in investigating information system security violations and help prepare reports specifying corrective and preventative actions. - The position routinely collaborates with the facility security team, program personnel, and government representatives. - Security sustainment activities (hardware change management, software change management, account management, media protection, user interface, file transfers, etc.) Important note: Within six months of hire date, you must obtain and maintain a Security professional certification commensurate with IAM Level I certification (Security+ or other), if you do not already have this certification. Qualifications You Must Have - Typically requires a University Degree and minimum 2 years prior relevant experience, or an Advanced Degree in a related field. - Relevant Experience Considered in any combination: - Cybersecurity, systems security or hardening - Information Technology - Compliance-based auditing using the Risk Management Framework (RMF), DCSA Assessment and Authorization Process Manual (DAAPM), Joint SAP Implementation Guide (JSIG), National Industrial Security Program Operating Manual (NISPOM), and/or non-defense regulations such as FAA, Payment Card Industry (PCI), ISO 9001 Quality Management standards, or HIPPA - Experience working with and/or supporting computer technologies (such as: databases, operating systems, computer network hardware, software programs, hardware troubleshooting or electronics) - Physical security/security, policework/criminal justice, investigations, or Border Patrol - Project or program management, office management, senior administration, or account management Qualifications We Prefer - Experience working in DoD classified operating and/or laboratory environments - Familiarity with cybersecurity Risk Management Framework (RMF) and compliance as stipulated by NISPOM/D<span class="highlight-KW_EDCTN">AAPM, JSIG, ICD 503, STIGs and associated NIST publications - Experience with audit reviews such as physical security, network and system event logs, password administration, file access privileges, etc. - Familiarity with the execution and management of cyber incident response; preservation, containment, and eradication - Ability to work independently and as a member of a team - Self-motivated and possess exceptional written and verbal communication skills, particularly in documenting evaluation results - Customer focused, adaptable and willing to work varying assignments - Completion of National Industrial Security Program cybersecurity training courses available at https://cdse.usalearning.gov/login/index.php What We Offer Our values drive our actions, behaviors, and performance with a vision for a safer, more connected world. At RTX we value: Trust, Respect, Accountability, Collaboration, and Innovation. Relocation Non-Eligible - Relocation assistance not available Learn More & Apply Now! Please consider the following role type definition as you apply for this role: - Onsite: Employees who are working in Onsite roles will work primarily onsite. This includes all production and maintenance employees, as they are essential to the development of our products We are RTX #LI-Onsite As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote. The salary range for this role is 68,900 USD - 131,100 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills. Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement. Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance. This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply. RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window. RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act. Privacy Policy and Terms: Click on this link to read the Policy and Terms
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior AI Security Engineer
bunny.netWe're helping build a faster internet. bunny.net is the content delivery platform that truly hops.
• Help design the security architecture behind bunny.net's AI security products: the threat models, detection systems, access controls, and enforcement policies that protect customers from AI-era attacks • Build core security capabilities, including prompt injection detection, secret protection, agent auditing, and access enforcement • Work with Product and AI leadership to identify the threats that matter most and decide what to build next • Build security products on bunny.net's global edge network, bringing AI security to a globally distributed platform operating at massive scale • Help secure bunny.net's internal AI platform and apply those learnings to customer-facing products
Title: Information Systems Security Officer ISSO Location: United States Job Description: Information Systems Security Officer (ISSO) Boston, MA | Remote | Hybrid Philadelphia, PA Information Technology Full Time Hybrid Apply for this job ISSO Employment Type: Full-Time Experienced Department: Information Technology CGS is seeking an Information Systems Security Officer (ISSO) with DIACAP and/or RMF experience who has deep expertise in security assessment documentation to support Dept. of Commerce systems and efforts to achieve their Authorization to Operate (ATO). This position is located at the client site in the Herbert Hoover building in Washington DC. The scope of this position includes full life-cycle Assessment and Authorization (A&A) management through all 6 Steps of the RMF process in support of the Government ISSM. In this role, youll conduct security assessment and information system security oversight activities in accordance with NIST 800.53 that support systems from the perspective RMF requirements. CGS brings motivated, highly skilled, and creative people together to solve the governments most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities. Skills and attributes for success - Review systems to identify potential security weaknesses and recommend improvements to amend vulnerabilities, implement changes, and document upgrades. - Maintain responsibility for managing cybersecurity risk from an organizational perspective. - Identify organizational risks, prioritize those risks, and maintain a risk registry for escalating and presenting those risks to senior leadership. - Provide security guidance and IS validation using the National Institute of Standards and Technology (NIST) RMF, DoC, and local security policies. - Providing configuration management (CM) recommendations for information system security software, hardware, and firmware, and coordinating changes and modifications with the ISSM, Security Control Assessor (SCA), and Authorizing Official (AO). - Maintain vulnerability scanning tool compliance such as HBSS or ACAS and patch management such as IAVM to ensure IT staff pushes patches to all systems in an effort to maintain compliance with all applicable directives, manage system changes, and assess the security impact of those changes. - Support security authorization activities including transitioning from the legacy Information Assurance Certification and Accreditation Process (DIACAP) to compliance with the DoC RMF. - Provide subject matter expertise for cyber security and trusted system technology. - Apply advanced technical knowledge and analysis of specialized functional areas in task requirements to develop solutions to complex problems. - Research, write, review, disposition, feedback, and finalize recommendations regarding cyber security policy, assessment and authorization assessments (A&As), security test and evaluation reports, and security engineering practices and processes. - Conduct research and write risk assessment reports to include risk thresholds, evaluation, and scoring. - Support analysis of the findings and provide expert technical guidance for mitigation strategies, including implementation advice on the cyber security risk findings and other complex problems. Qualifications - Bachelors Degree. - A minimum of five (5) years experience as an Information Assurance (IA) Analyst, ISSE, ISSO, or similar role in ATO package development including generating security documentation for requirements, security control assessment, STIG and IAVA compliance, Standard Operating Procedures, test results, etc. - eMASS experience. - Professional security certification such as CCNA Security, CySA, GICSP, GSEC, CompTIA Security+, CE, SSCP, or higher. - Strong desktop publishing skills using Microsoft Word and Excel. - Experience with industry writing styles such as grammar, sentence form, and structure. - Ability to multi-task in a deadline-oriented environment. Ideally, you will also have - CISSP, CASP, or a similar certificate is preferred. - Masters Degree in Cybersecurity or related field. - Strong initiative, detail orientation, organizational skills, and aptitude for analytical thinking. - Demonstrated ability to work well independently and as a part of a team. - Excellent work ethic and a high commitment to quality. Our Commitment Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our clients specific needs. We are committed to solving the most challenging and dynamic problems. For the past seven years, weve been growing our government contracting portfolio, and along the way, weve created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work. Here at CGS, we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers, mending those relations for years to come. We care about our employees. Therefore, we offer a comprehensive benefits package: - Health, Dental, and Vision - Life Insurance - 401k - Flexible Spending Account - Health, Dependent Care, and Commuter - Paid Time Off and Observance of State/Federal Holidays Contact Government Services LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. Join our team and become part of government innovation. Explore additional job opportunities with CGS on our Job Board: https://cgsfederal.com/join-our-team For more information about CGS, please visit https://www.cgsfederal.com or contact Email: emailprotected CJ92213.33 - $125,146.66 a year We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans.
Platform and Security Engineer
Sport Alliance GmbHDigitalization of the fitness industry - Leading service provider for SaaS, Fintech, and lead generation.
• Developer-Driven SecOps: Leverage your programming background to transition manual security and infrastructure processes into automated, self-service APIs and internal tooling, speaking the same language as our product engineers. • Platform Operations: Design, implement, and operate cloud infrastructure (primarily AWS) as a secure, reliable platform, enabling self-service for engineering teams to deploy and run applications. • Infrastructure Hardening: Apply defense-in-depth and zero-trust principles, implementing layered security controls across network, compute, identity, and data tiers. • Security Standards & Governance: Develop, document, and enforce security standards, guidelines, and hardening baselines for software development (SDLC) and platform operations, driving adoption across the organization. • Incident Response: Detect, triage, manage, and respond to cyber security incidents, owning the process from initial signal through resolution and post-mortem. • Hands-on Security Engineering: Actively address vulnerabilities, implement security features (WAF rules, SIEM monitors, access policies), and improve overall platform resilience. • Continuous Threat Review: Conduct ongoing reviews of security tooling (such as our CNAPP Wiz), processes, and controls in response to new threats, architecture changes, and internal risk assessments. • Harness Engineering: Extend and improve our tooling that supports the Agent-Harnesses to safeguard AI-assisted development workflows across the SDLC. • Stakeholder Collaboration: Coordinate, communicate, and align seamlessly with key stakeholders including the CTO, CISO, Engineering Managers, Tech Leads, and cross-functional product teams.
Information Security Risk Manager
Deutsche Telekom IT SolutionsAs Hungary’s most attractive employer in 2025 (according to Randstad’s representative survey), Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group. The company provides a wide portfolio of IT and telecommunications services with more than 5300 employees. We have hundreds of large customers, corporations in Germany and in other European countries. DT-ITS received the Best in Educational Cooperation award from HIPA in 2019, acknowledged as the Most Ethical Multinational Company in 2019. The company continuously develops its four sites in Budapest, Debrecen, Pécs and Szeged and is looking for skilled IT professionals to join its team.
Role Description As an Information Security Risk Manager, you will be part of a centralized information security governance team providing security risk management services across multiple Deutsche Telekom legal entities. The role focuses on operating and continuously improving the information security risk management framework, while supporting and enabling local risk managers through consultation, training, and professional use of GRC tools. You will contribute to transparent risk reporting, effective risk mitigation, and harmonized governance practices in a complex, multinational environment. - Operate and continuously improve the information security risk management process, methodologies, and related policies - Ensure alignment with group-level security standards and governance requirements - Support the integration of risk management into business and IT processes - Act as a trusted advisor for supported legal entities on information security risk topics - Train and upskill local risk managers on risk processes, methods, and policies - Provide hands-on guidance during risk identification, assessment, and treatment - Support professional usage of the GRC platform by local risk managers - Assist in risk creation, maintenance, and lifecycle management within the tool - Collect user feedback and represent business needs toward process and tool improvements - Identify, create, and manage information security risks in cooperation with stakeholders - Monitor and support risk mitigation actions, including follow-up on progress and effectiveness - Ensure risks are properly documented and audit-ready - Prepare and maintain Top 10 risk reports, quarterly risk summaries, and ad-hoc reports - Define, monitor, and analyze risk KPIs and metrics - Provide management with insights on risk trends and improvement areas Qualifications - Bachelor’s or Master’s degree in Information Security, Computer Science, Engineering, Business Informatics, or a related field - High-level English language knowledge (spoken and written) - At least mid-level German language proficiency - 3–7+ years of experience in Information Security / Cybersecurity / Risk Management / GRC roles - Experience in large enterprise or multinational environments - Strong understanding of information security risk management frameworks (e.g. ISO 27005, NIST RMF) - Knowledge of information security standards (e.g. ISO 27001, NIST, CIS) - Ability to apply security governance principles in practical, business-aligned ways - Strong communication and stakeholder management skills - Ability to explain security and risk topics in business-friendly language - Structured, proactive, and solution-oriented mindset Requirements - Experience in training, coaching, or enablement activities - Experience working in a shared service or internal consulting model is an advantage - CRISC, CISM, CISSP, COBIT, ITIL or similar governance-related certifications - Hands-on experience with GRC tools (e.g. ServiceNow, Archer, OneTrust, or similar) Benefits - *Please be informed that our remote working possibility is only available within Hungary due to European taxation regulation. Company Description As Hungary’s most attractive employer in 2025 (according to Randstad’s representative survey), Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group. The company provides a wide portfolio of IT and telecommunications services with more than 5300 employees. We have hundreds of large customers, corporations in Germany and in other European countries. DT-ITS received the Best in Educational Cooperation award from HIPA in 2019, acknowledged as the Most Ethical Multinational Company in 2019. The company continuously develops its four sites in Budapest, Debrecen, Pécs and Szeged and is looking for skilled IT professionals to join its team.


