Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Principal Specialist, Cyber Security Auditor image - Rise Careers
Job details

Principal Specialist, Cyber Security Auditor

Date Posted:2024-12-03Country:United States of AmericaLocation:RMA99: RTN Remote, MassachusettsPosition Role Type:RemoteAt Raytheon, the foundation of everything we do is rooted in our values and a higher calling - to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. Our team solves tough, meaningful problems that create a safer, more secure world.What You Will DoThe Principal Specialist Cyber Security & Risk Management Auditor acts as part of a highly talented team of cybersecurity professionals within the Digital Technology Governance, Risk and Compliance (GRC) organization, an entity that evaluates the effectiveness and adequacy of the company's security and operational controls to ensure compliance with all pertinent policy and regulatory requirements. You will provide support and service across all mission areas and act as an integral part of executing on both functional and business strategy that ultimately enables us to fully comply with complex and evolving customer (DoD and USG) and RTX cybersecurity compliance requirements.Responsibilities to Anticipate:• Execute assessment diligence in alignment with business long-term functional and cyber compliance strategy and goals to ensure compliance with company policy, DoD & US cyber regulations, and global contractual cybersecurity requirements for a multi-billion-dollar business unit.• Prepare all mission areas, sites, and programs for internal, 3rd party, DCMA, and Cybersecurity Maturity Model Certification (CMMC) audits and assessments to help detect noncompliance that could result in negative business outcomes (CARs, fines, and/or loss of contract awards, reputation, and market share).• Participate in domestic and international compliance readiness efforts, including establishment and solidification of cybersecurity compliance requirements, to include landed companies and Joint Ventures for all current and future contracts and work requirements supporting U.S. national and coalition warfighters.• Conduct site-level testing and assessment to measure local compliance with RTX policy and associated NIST 800-171 controls. As required, execute onsite visits to conduct validation and verification assessments to confirm issue status and promote high level audit readiness.• Conduct full scale assessment of site level documentation to assess whether critical processes are fully documented and executed per policy.• Execute processes/tools/methodology to detect security control issues and document observations and associated remedial actions in Digital GRC system of record.• Actively identify weaknesses or vulnerabilities, make recommendations for fully remediating/addressing issues noted, and support remedial action closure.• Audit/Assess program Security Accreditation Plans (SAPs) against current and future DoD, DFARS and CMMC regulatory requirements to ensure personnel are executing official security plans as designed.• Travel to company locations as necessaryQualifications You Must Have• Typically, a bachelor's degree in information technology, business, or STEM, and 5 years of related Digital Technology/IT Security experience is required.• Experience with NIST SP 800-171A and NIST SP800-53 control implementation and assessment.• Must have either a Certified Information Systems Auditor (CISA), Certified Information Systems Manager (CISM), and/or Certified Information Systems Security Professional (CISSP) certification• Experience executing baseline audits of physical sites, business applications, and/or frameworks to include control identification, testing, and risk stratification.• Experience with assessment of information system compliance against internal and external standards and policies, accreditation plans, and pertinent regulatory requirements.• Experience summarizing audit / assessment engagements and results, including the composition of formal reports and remedial action plans.• The ability to obtain and maintain a US security clearance. U.S. citizenship is required as only U.S. citizens are eligible for a security clearanceQualifications We Prefer:• Experience designing and deploying audit engagements, overseeing security assessments and/or compliance testing and data analytics, preferably in a medium to large organization.• Knowledge or Experience with IoT/OT Cybersecurity• Knowledge or Experience with Cloud Environments (AZURE, AWS)• Knowledge or Experience with AI/ML• Project Management experience• Proficiency in automating security assessments and audits• Knowledge or Experience with Power BI, Jira, and ArcherWhat We Offer• Our values drive our actions, behaviors, and performance with a vision for a safer, more connected world. At RTX we value: Trust, Respect, Accountability, Collaboration, and Innovation.• Relocation assistance is not available.Learn More & Apply Now!• RTX solves some of the toughest challenges in aerospace and defense. That requires expansive thinking and bold innovation - and that, in turn, requires a culture that is diverse, equitable and inclusive.We embrace individuality and diversity of thought to fuel opportunity for our employees, our customers, and our communities. We work toward progress, knowing that a more inclusive world is critical to our mission. Not just in this moment, but always.Please consider the following role type definition as you apply for this role.• Remote: Employees who are working in Remote roles will work primarily offsite (from home). An employee may be expected to travel to the site location as needed.The salary range for this role is 77,000 USD - 163,000 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.RTX is An Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class.Privacy Policy and Terms:Click on this link to read the Policy and Terms
RTX Glassdoor Company Review
3.7 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
RTX DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of RTX
RTX CEO photo
Gregory J. Hayes
Approve of CEO

Average salary estimate

$120000 / YEARLY (est.)
min
max
$77000K
$163000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Principal Specialist, Cyber Security Auditor, RTX

Are you ready to take your career to the next level with Raytheon? We are currently seeking a Principal Specialist, Cyber Security Auditor to join our esteemed team based in Massachusetts. In this role, you will contribute to the security and operational integrity of our systems, helping us meet the rigorous cybersecurity compliance requirements of the U.S. Department of Defense and other government contracts. As a Principal Specialist in Cyber Security & Risk Management, you'll be at the forefront of evaluating the effectiveness of our controls and ensuring our compliance with a complex set of regulations. Your expertise will guide internal and external audits, assessing everything from site-level compliance to robust documentation requirements. This is a remote position, allowing you flexibility while still being an integral part of our mission to create a safe and secure environment. You'll be involved in assessing potential vulnerabilities, developing remedial actions, and supporting compliance initiatives that directly impact our national security commitments. We value integrity, collaboration, and innovation at Raytheon, and we're looking for someone who embodies these principles. If you have a background in IT security, solid experience with NIST standards, and relevant certifications like CISA, CISM, or CISSP, we want to hear from you! Join us in shaping a safer future, where your skills can make a tangible difference.

Frequently Asked Questions (FAQs) for Principal Specialist, Cyber Security Auditor Role at RTX
What are the main responsibilities of a Principal Specialist, Cyber Security Auditor at Raytheon?

The Principal Specialist, Cyber Security Auditor at Raytheon plays a vital role in evaluating our cybersecurity and operational controls ensuring compliance with various regulations. You will conduct assessments to prepare sites for audits, perform testing of local compliance, and identify vulnerabilities. This role also involves working closely with all mission areas to understand compliance requirements and recommending effective remediation strategies.

Join Rise to see the full answer
What qualifications are needed for the Principal Specialist, Cyber Security Auditor position at Raytheon?

To qualify for the Principal Specialist, Cyber Security Auditor role at Raytheon, candidates typically need a bachelor's degree in information technology, business, or a STEM field along with 5 years of related experience. Key certifications such as CISA, CISM, or CISSP are essential, along with hands-on experience with NIST compliance and assessing various cybersecurity frameworks.

Join Rise to see the full answer
How does the Principal Specialist, Cyber Security Auditor contribute to Raytheon's mission?

As a Principal Specialist, Cyber Security Auditor at Raytheon, you will help protect vital information and systems from threats, which is crucial for our mission of national defense. Your evaluations and recommendations will ensure the effectiveness of our cybersecurity measures, directly supporting our goal of delivering secure solutions to our clients and maintaining national security.

Join Rise to see the full answer
What is the work environment like for a Principal Specialist, Cyber Security Auditor at Raytheon?

The work environment for the Principal Specialist, Cyber Security Auditor at Raytheon is primarily remote, providing flexibility to balance professional and personal commitments. You will engage with a team of skilled cybersecurity professionals focused on collaboration and innovative solutions, all while being aligned with Raytheon's core values of trust, respect, and accountability.

Join Rise to see the full answer
What opportunities for advancement and development are available for a Principal Specialist, Cyber Security Auditor at Raytheon?

Raytheon is committed to the professional development of its employees. As a Principal Specialist, Cyber Security Auditor, you will have access to various training programs, mentorship opportunities, and resources to support your career growth. The skills you develop in this role can lead to further opportunities within the company in cybersecurity management or related disciplines.

Join Rise to see the full answer
Common Interview Questions for Principal Specialist, Cyber Security Auditor
Can you describe your experience with NIST SP 800-171A and how it applies to your role as a Cyber Security Auditor?

In responding to this question, share specific examples of audits or assessments you have conducted using NIST SP 800-171A. Explain the processes you followed, the controls you focused on, and the outcomes of those assessments, highlighting how you identified and remediated vulnerabilities.

Join Rise to see the full answer
How do you prepare for an internal audit or assessment at a site?

When preparing for an internal audit, discuss your process for reviewing documentation, understanding compliance requirements, and communicating with site personnel. Emphasize the importance of setting clear objectives and conducting preliminary assessments to identify potential issues.

Join Rise to see the full answer
What methodologies do you use to identify vulnerabilities in cybersecurity controls?

Share the methodologies you leverage, such as risk assessments, control testing, and gap analyses. Discuss specific tools you may use to enhance your assessments and how your findings contribute to overall security improvements.

Join Rise to see the full answer
How would you handle a situation where a site fails to meet compliance standards?

Describe how you would approach the situation by first conducting a thorough assessment to understand the cause of noncompliance. Illustrate the importance of documenting findings, providing clear recommendations, and collaborating with site leadership to develop a remediation plan.

Join Rise to see the full answer
What strategies do you employ for ensuring the documentation of audit processes is thorough and effective?

Discuss your best practices for documentation, which may include standardizing audit reports, using clear and consistent language, and ensuring that all findings are well-supported by evidence. Highlight the role of effective documentation in facilitating future audits.

Join Rise to see the full answer
Describe how you stay updated with evolving cybersecurity compliance regulations.

Discuss the resources you utilize for staying informed, such as industry publications, professional organizations, and continuing education. Emphasize your proactive approach towards understanding new regulations and how you apply this knowledge to enhance your audit practices.

Join Rise to see the full answer
What is your approach when working collaboratively with teams across different mission areas?

When answering this question, highlight your communication and interpersonal skills. Discuss how you build relationships, facilitate discussions around compliance, and work to create a unified understanding of cybersecurity objectives across diverse teams.

Join Rise to see the full answer
Can you describe a challenging audit you have conducted and what you learned from it?

Share a specific example of an audit that had complexities, such as a tight timeframe or significant noncompliance issues. Discuss the strategies you used to navigate those challenges and the insights you gained that improved your future audit approaches.

Join Rise to see the full answer
How do you assess the effectiveness of remedial actions taken after an audit?

Explain your process for evaluating the effectiveness of remedial actions, which may include follow-up audits, testing controls, and ongoing monitoring of compliance. Discuss the importance of ensuring that corrective actions are not only implemented but also effective in mitigating risks.

Join Rise to see the full answer
What role does communication play in your work as a Cyber Security Auditor?

Emphasize the critical nature of communication in audit processes. Explain how you ensure transparency with stakeholders, report findings clearly, and engage teams in discussions about compliance requirements and remediation plans.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 1 hour ago
Photo of the Rise User
Posted 12 days ago
Photo of the Rise User
Foodics Remote No location specified
Posted 13 days ago
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Trendyol Remote Istanbul / Maslak
Posted 10 days ago
Photo of the Rise User
Posted 2 days ago

RTX is comprised of three market-leading businesses – Collins Aerospace, Pratt & Whitney and Raytheon – working as one to answer the biggest questions and solve the hardest problems in aerospace and defense. At RTX, we're a diverse team of explor...

14 jobs
MATCH
Calculating your matching score...
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
December 7, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!