Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Principal Specialist, Cyber Security Auditor image - Rise Careers
Job details

Principal Specialist, Cyber Security Auditor

Date Posted:2024-12-03Country:United States of AmericaLocation:RMA99: RTN Remote, MassachusettsPosition Role Type:RemoteAt Raytheon, the foundation of everything we do is rooted in our values and a higher calling – to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today’s mission and stay ahead of tomorrow’s threat. Our team solves tough, meaningful problems that create a safer, more secure world.What You Will DoThe Principal Specialist Cyber Security & Risk Management Auditor acts as part of a highly talented team of cybersecurity professionals within the Digital Technology Governance, Risk and Compliance (GRC) organization, an entity that evaluates the effectiveness and adequacy of the company’s security and operational controls to ensure compliance with all pertinent policy and regulatory requirements. You will provide support and service across all mission areas and act as an integral part of executing on both functional and business strategy that ultimately enables us to fully comply with complex and evolving customer (DoD and USG) and RTX cybersecurity compliance requirements.Responsibilities to Anticipate:• Execute assessment diligence in alignment with business long-term functional and cyber compliance strategy and goals to ensure compliance with company policy, DoD & US cyber regulations, and global contractual cybersecurity requirements for a multi-billion-dollar business unit.• Prepare all mission areas, sites, and programs for internal, 3rd party, DCMA, and Cybersecurity Maturity Model Certification (CMMC) audits and assessments to help detect noncompliance that could result in negative business outcomes (CARs, fines, and/or loss of contract awards, reputation, and market share).• Participate in domestic and international compliance readiness efforts, including establishment and solidification of cybersecurity compliance requirements, to include landed companies and Joint Ventures for all current and future contracts and work requirements supporting U.S. national and coalition warfighters.• Conduct site-level testing and assessment to measure local compliance with RTX policy and associated NIST 800-171 controls. As required, execute onsite visits to conduct validation and verification assessments to confirm issue status and promote high level audit readiness.• Conduct full scale assessment of site level documentation to assess whether critical processes are fully documented and executed per policy.• Execute processes/tools/methodology to detect security control issues and document observations and associated remedial actions in Digital GRC system of record.• Actively identify weaknesses or vulnerabilities, make recommendations for fully remediating/addressing issues noted, and support remedial action closure.• Audit/Assess program Security Accreditation Plans (SAPs) against current and future DoD, DFARS and CMMC regulatory requirements to ensure personnel are executing official security plans as designed.• Travel to company locations as necessaryQualifications You Must Have• Typically, a bachelor’s degree in information technology, business, or STEM, and 5 years of related Digital Technology/IT Security experience is required.• Experience with NIST SP 800-171A and NIST SP800-53 control implementation and assessment.• Must have either a Certified Information Systems Auditor (CISA), Certified Information Systems Manager (CISM), and/or Certified Information Systems Security Professional (CISSP) certification• Experience executing baseline audits of physical sites, business applications, and/or frameworks to include control identification, testing, and risk stratification.• Experience with assessment of information system compliance against internal and external standards and policies, accreditation plans, and pertinent regulatory requirements.• Experience summarizing audit / assessment engagements and results, including the composition of formal reports and remedial action plans.• The ability to obtain and maintain a US security clearance. U.S. citizenship is required as only U.S. citizens are eligible for a security clearanceQualifications We Prefer:• Experience designing and deploying audit engagements, overseeing security assessments and/or compliance testing and data analytics, preferably in a medium to large organization.• Knowledge or Experience with IoT/OT Cybersecurity• Knowledge or Experience with Cloud Environments (AZURE, AWS)• Knowledge or Experience with AI/ML• Project Management experience• Proficiency in automating security assessments and audits• Knowledge or Experience with Power BI, Jira, and ArcherWhat We Offer• Our values drive our actions, behaviors, and performance with a vision for a safer, more connected world. At RTX we value: Trust, Respect, Accountability, Collaboration, and Innovation.• Relocation assistance is not available.Learn More & Apply Now!• RTX solves some of the toughest challenges in aerospace and defense. That requires expansive thinking and bold innovation – and that, in turn, requires a culture that is diverse, equitable and inclusive.We embrace individuality and diversity of thought to fuel opportunity for our employees, our customers, and our communities. We work toward progress, knowing that a more inclusive world is critical to our mission. Not just in this moment, but always.Please consider the following role type definition as you apply for this role.• Remote: Employees who are working in Remote roles will work primarily offsite (from home). An employee may be expected to travel to the site location as needed.The salary range for this role is 77,000 USD - 163,000 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate’s work experience, location, education/training, and key skills.Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company’s performance.This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.RTX is An Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class.Privacy Policy and Terms:Click on this link to read the Policy and Terms
RTX Glassdoor Company Review
3.7 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
RTX DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of RTX
RTX CEO photo
Gregory J. Hayes
Approve of CEO

Average salary estimate

$120000 / YEARLY (est.)
min
max
$77000K
$163000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Principal Specialist, Cyber Security Auditor, RTX

Are you ready to take your career to the next level as a Principal Specialist, Cyber Security Auditor at Raytheon in Agawam, MA? In this exciting role, you’ll become part of a talented team dedicated to ensuring compliance with complex cybersecurity regulations that protect our nation and allies. You'll delve deep into evaluating effectiveness and adequacy of security controls, preparing various sites for audits, and executing risk assessments that play a crucial role in our multi-billion-dollar operations. If you have a background in IT security and are passionate about safeguarding sensitive information, this position is perfect for you. You will be responsible for conducting comprehensive reviews of cybersecurity practices against established standards like NIST and ensuring remedial actions are implemented. You'll work closely with different programs and sites, performing onsite visits and guiding them on how to bolster their cybersecurity frameworks. We are looking for individuals who thrive in a collaborative and innovative environment, as the responsibilities will extend to identifying vulnerabilities and recommending strategies to enhance security controls. If you hold a degree in a relevant field and have certifications like CISA or CISSP, along with at least five years of related experience, you will be an excellent fit for this position. Join us at Raytheon, where your work will have a significant impact, and enjoy the benefits of a remote role that allows flexibility while contributing to a safer and more secure world.

Frequently Asked Questions (FAQs) for Principal Specialist, Cyber Security Auditor Role at RTX
What are the key responsibilities of a Principal Specialist, Cyber Security Auditor at Raytheon?

As a Principal Specialist, Cyber Security Auditor at Raytheon, your main responsibilities will include executing compliance assessments, preparing various sites for audits, and ensuring adherence to DoD and US cybersecurity regulations. You will play a pivotal role in identifying security vulnerabilities and developing corrective actions, while also conducting detailed testing and assessments relevant to critical cybersecurity protocols.

Join Rise to see the full answer
What qualifications are required for the Principal Specialist, Cyber Security Auditor position at Raytheon?

To qualify for the Principal Specialist, Cyber Security Auditor role at Raytheon, you should have a bachelor's degree in information technology or a related field, along with at least five years of experience in IT security. Certifications such as CISA, CISM, or CISSP are essential, as well as experience with NIST standards and auditing processes.

Join Rise to see the full answer
What is the work environment like for the Principal Specialist, Cyber Security Auditor at Raytheon?

The Principal Specialist, Cyber Security Auditor at Raytheon primarily works in a remote setting, promoting a flexible work-life balance. While you'll enjoy the comfort of working from home, the role does require some travel to various company locations for onsite assessments and audits, allowing you to engage directly with teams across the organization.

Join Rise to see the full answer
What skills are important for a Principal Specialist, Cyber Security Auditor at Raytheon?

Critical skills for the Principal Specialist, Cyber Security Auditor role at Raytheon include strong analytical abilities, proficiency in security compliance frameworks such as NIST SP 800-171, and expertise in conducting audits. Familiarity with cloud environments and management tools like Power BI and Jira will further enhance your suitability for this position.

Join Rise to see the full answer
What opportunities for growth exist for the Principal Specialist, Cyber Security Auditor at Raytheon?

Raytheon is committed to the professional development of its employees, providing numerous growth opportunities for a Principal Specialist, Cyber Security Auditor. You can access training programs, gain experience in diverse cyber compliance areas, and potentially partake in leadership roles as you advance within the organization.

Join Rise to see the full answer
Common Interview Questions for Principal Specialist, Cyber Security Auditor
How do you conduct a compliance assessment for cybersecurity protocols?

To effectively conduct a compliance assessment, start by understanding the specific regulations and standards applicable to the environment. Next, review the existing security documentation, conduct site visits, and utilize assessment tools to test controls. Follow this with a detailed analysis of findings, documenting any gaps and recommending remedial actions.

Join Rise to see the full answer
Can you explain your experience with NIST standards in cybersecurity?

Highlight specific experiences where you applied NIST standards to enhance cybersecurity practices. Discuss roles where you executed compliance checks, developed security plans, and how your efforts contributed to meeting regulatory requirements. Be sure to mention any relevant certifications that solidify your expertise in this area.

Join Rise to see the full answer
What strategies do you implement for remediation after an audit reveals vulnerabilities?

After identifying vulnerabilities, I prioritize them based on risk severity and potential impact. Next, I create a detailed remediation plan outlining corrective actions, timelines, and responsible parties. Ensuring thorough communication with the affected teams is key, as is follow-up assessment to verify closure of the issues.

Join Rise to see the full answer
How do you stay current with emerging cybersecurity threats and regulations?

I actively attend webinars, read industry publications, and participate in professional networks to stay informed of latest trends in cybersecurity. Engaging in continuous learning through certifications and courses is also a priority, as the cybersecurity landscape is constantly evolving.

Join Rise to see the full answer
Describe a challenging project you were involved in and how you handled it.

I once led an organization-wide audit with a tight deadline during which we discovered several compliance gaps. I quickly organized a task force, delegated responsibilities, and crafted a timeline with clear goals, which allowed us to address the issues collectively and complete the audit on time with substantial findings.

Join Rise to see the full answer
What role does collaboration play in cybersecurity auditing?

Collaboration is essential in cybersecurity auditing, as it ensures alignment among various departments on security protocols. Building rapport with teams allows for more effective information sharing, fostering a culture of compliance and proactive risk management across the organization.

Join Rise to see the full answer
How do you evaluate and select audit methodologies?

When selecting audit methodologies, I consider the specific context of the audit, including regulatory frameworks, the complexity of systems, and organizational risk appetite. I also review industry best practices to ensure the chosen methodology is comprehensive and effective.

Join Rise to see the full answer
What metrics do you monitor to evaluate cybersecurity compliance?

Key metrics for evaluating cybersecurity compliance include the number of vulnerabilities identified, vulnerability remediation timelines, compliance percentages against standards, incident response times, and overall audit results. Regular monitoring of these metrics provides insights into the organization's cybersecurity health.

Join Rise to see the full answer
How do you handle resistance from teams during compliance audits?

Resistance can often stem from misunderstandings of the compliance process. To handle this, I prioritize clear communication, explaining the benefits of compliance and fostering collaborative conversations to address concerns. Conducting workshops can also demystify the audit process for team members.

Join Rise to see the full answer
Describe how you ensure thorough documentation during audits.

I maintain thorough documentation by following a structured approach, ensuring that every assessment, finding, and action is logged accurately. Using documentation tools helps streamline this process, and I regularly review the records to ensure completeness and clarity for future audits.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 5 days ago
Photo of the Rise User
webook.com Remote No location specified
Posted 5 days ago
Drees & Sommer SE Remote C/ Trinidad Grund, 12, Distrito Centro, 29001 Málaga, Spain
Posted 9 days ago
Photo of the Rise User
Kate Farms Remote No location specified
Posted 7 days ago
Photo of the Rise User
Posted 8 days ago
Photo of the Rise User
Avery Dennison Hybrid 8080 Norton Pkwy, Mentor, OH 44060, USA
Posted 6 days ago

RTX is comprised of three market-leading businesses – Collins Aerospace, Pratt & Whitney and Raytheon – working as one to answer the biggest questions and solve the hardest problems in aerospace and defense. At RTX, we're a diverse team of explor...

126 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
December 6, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!