Devsecops Security Engineer

RTX RTX · Aerospace · andover, MA +1 · Digital Technology

RTX is seeking a DevSecOps Security Engineer to design, develop, and implement security tools, integrate security tooling into CI/CD pipelines, and support cybersecurity compliance activities for IT products and services. The role requires a STEM degree, experience with information assurance and cybersecurity concepts, and the ability to obtain a U.S. government security clearance.

What you'd actually do

  1. Design, develop, and implement security tools to detect, prevent, and remediate security issues in TSG-managed IT products & services.
  2. Assist in the development and integration of security tooling into CI/CD pipelines to automate and accelerate security testing of IT service assets.
  3. Work with software developers and system engineers to develop security testing automations using static and dynamic application security tools (SAST/DAST).
  4. Provide operational support to internal RTX developers and engineers on common security processes and tools.
  5. Build and maintain dashboards, alerts, and reports for the team's Splunk-based observability platform.

Skills

Required

  • STEM degree
  • 2 years of prior relevant experience
  • Solid understanding of information assurance and cybersecurity concepts
  • experience implementing security controls in information systems and networks

Nice to have

  • Experience with on-premise system and network vulnerability assessment tools such as Nessus, Rapid7, or similar.
  • Experience with the Splunk observability platform and creating queries, dashboards, and reports to monitor IT products and services.
  • Experience creating, managing, and maintaining continuous integration and delivery (CI/CD) pipelines for automated security testing. (GitLab Runners, Jenkins)
  • Experience with static and dynamic application security testing (SAST/DAST) tools like Coverity, SonarQube, and OWASP ZAP.
  • Experience of Git-based version control systems and experience creating and maintaining code and configuration repositories. (GitLab, GitHub)
  • Experience with scripting languages. (e.g., Python, PowerShell, or Bash)
  • Experience with Linux- and/or Windows-based operating systems running in virtual, containerized, and cloud-based operating platforms.
  • Active cybersecurity certifications such as Security+, GSEC, SSCP, or CISSP Associate recommended.

What the JD emphasized

  • The ability to obtain and maintain a U.S. government issued security clearance is required
  • U.S. citizenship is required
  • Active and existing security clearance required after day 1