A complete application in a minute — tailored resume and cover letter, ready to send.
RTX in Largo, FL is seeking a Senior Information Assurance and Cybersecurity professional to lead RMF activities and manage authorization for sensitive systems onsite. Active TS/SCI clearance required; relocation not offered.
You will craft SSPs, SCTMs, SARs, RARs, POA&Ms, and monitoring plans, guiding ISSMs and ISSOs through complex compliance requirements. You'll interpret NIST 800-series, ICD 503, NISPOM, JSIG, DCID, and related standards while mentoring junior staff and coordinating with
Location:US-FL-LARGO-382SS ~ 7887 Bryan Dairy Rd. ~ BLDG 100
Position Role Type:Onsite
U.S. Citizen, U.S. Person, or Immigration Status Requirements: Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
Security Clearance Type: TS/SCI - Current
Security Clearance Status: Active and existing security clearance required on day 1
Raytheon Company, Managed by Collins AerospaceAt RTX, the world's largest aerospace and defense company, 185,000 great minds are united by purpose and inspired to make a difference solving the world’s most complex problems. With our three market leading businesses, world-class operations and investments in research and development, we offer capabilities and opportunity no one else can. Together, we push the boundaries of known science and find new ways to connect and protect our world.
Collins Aerospace is a leader in technologically advanced, intelligent solutions that help redefine the aerospace and defense industry. With a comprehensive portfolio and deep technical expertise, we help customers meet the demands of the global market. Join us and help shape the future of aerospace and defense.
We're hiring for a Senior Information Assurance and Cybersecurity professional with extensive experience independently leading RMF, ICD 503, NISPOM, and security authorization activities for sensitive systems. Provides senior-level technical leadership across risk assessments, security control implementation and assessment, vulnerability management, continuous monitoring, compliance audits, and development of critical RMF artifacts including SSPs, SCTMs, SARs, RARs, and POA&Ms. This role will be worked onsite in Largo, FL and requires an active and transferrable TS/SCI clearance. Relocation assistance is not available.
Independently lead and executeInformation Assurance (IA) and Risk Management Framework (RMF)activities for information systems processing National Security Information, from system categorization and control selection through assessment, authorization, and continuous monitoring
Provide senior-level technical expertise and recommendations under the general direction of the Information Assurance Domain Lead and/or Information Technology leadership, exercising independent judgment in resolving complex cybersecurity, compliance, and risk-management issues
Ensure applicableNational Industrial Security Program Operating Manual (NISPOM)requirements are effectively implemented, operationally functional, periodically assessed, and accurately documented within the RMF process
Lead the development, review, maintenance, and presentation ofRMF and ICD 503 artifacts, including System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Plans of Action and Milestones (POA&Ms), Continuous Monitoring Plans, security control assessment evidence, and other authorization documentation
Analyze system architectures, security controls, vulnerabilities, and operational environments to identify cybersecurity risks and developrisk-based recommendations and mitigation strategies
Develop and maintain comprehensiveSystem Security Plans (SSPs)and supporting certification and authorization documentation, ensuring technical implementations and supporting evidence accurately reflect the operational environment
Interpret and implement applicable requirements from theNIST 800 Series, ICD 503, JSIG, DCID, NISPOM, ICD 705, and other government security policies, directives, and standards
Conduct or supporttechnical computer and network system audits, security control assessments, vulnerability assessments, configuration reviews, and compliance evaluations to identify security gaps and validate implementation effectiveness
Work directly withInformation System Security Managers (ISSMs), Security Control Assessors (SCAs), Information System Security Officers (ISSOs), system administrators, engineers, and customer personnelto review, update, defend, and explain accreditation and authorization documentation
Serve as a technical point of contact duringRMF assessments, audits, inspections, customer reviews, and authorization activities, coordinating responses to findings and ensuring timely closure of identified deficiencies
Evaluate and interpretSTIGs, ACAS results, vulnerability scan data, configuration baselines, and other security-hardening requirementsto identify security deficiencies and develop appropriate remediation plans
Lead continuous monitoring activities and establish processes for tracking security controls, vulnerabilities, POA&Ms, configuration changes, system modifications, and other events that may affect an authorization boundary or risk posture
Provide technical leadership in the assessment and implementation of security controls across enterprise, network, host, application, and enclave environments
Identify opportunities to improve RMF processes, documentation quality, security posture, and operational efficiency; develop and implement process improvements where appropriate
Mentor and provide technical guidance to junior IA/RMF personnel, including review of security documentation, assessment evidence, control implementations, and remediation activities
Collaborate across engineering, information technology, program management, security, and functional organizations to integrate cybersecurity requirements into system development, deployment, modification, and sustainment activities
Communicate complex cybersecurity and RMF requirements clearly to technical and non-technical stakeholders and provide actionable recommendations to management and customers
Support security investigations, risk assessments, remediation activities