Senior Cyber Enhanced Assessment (cea) Assessor - Tucson, Az

RTX RTX · Aerospace · tucson, AZ +1 · Digital Technology

This role supports the Continuous Monitoring (ConMon) and Cyber Enhanced Assessment (CEA) programs for classified computing environments. The Senior CEA Assessor will assist in developing and maintaining documentation and tools, conduct assessments, prepare reports on trends and discoveries, assist with root cause analysis, and support self-inspection events. The role requires experience with various information system security tools, cybersecurity, systems security, system hardening, and compliance-based auditing using frameworks like RMF and NISPOM. Scripting knowledge in PowerShell, BASH, and Splunk SPL is preferred.

What you'd actually do

  1. Assists with the development and sustainment of ConMon & CEA documentation (e.g., process, instruction, training) and tools. Identifies challenges and suggests opportunities for the CEA Program.
  2. Conducts ConMon and CEAs. Prepares reports to identify trends and significant discoveries and assists with root cause analysis. Assists in the development of implementation plans to mitigate the risk.
  3. Provides Cybersecurity support for Self-Inspection events, as needed.
  4. Intermittent travel to other Raytheon locations (20-30%).

Skills

Required

  • Bachelor's Degree or equivalent experience and minimum 5 years prior relevant experience, or an Advanced Degree in a related field and minimum 3 years’ experience
  • IAM Level I certification (Security+ or other)
  • Experience with various information system security tools that address vulnerability analysis and mitigation
  • Cybersecurity
  • systems security
  • system hardening
  • Security Control Accessor (SCA) with the government or military
  • Information Technology
  • network security
  • systems security
  • architecture
  • topology
  • protocols
  • components
  • principles
  • configuring and/or auditing operating systems
  • Compliance-based auditing using the Risk Management Framework (RMF), DCSA Assessment and Authorization Process Manual (DAAPM), Joint SAP Implementation Guide (JSIG), National Industrial Security Program Operating Manual (NISPOM), and/or non-defense regulations such as FAA, Payment Card Industry (PCI), ISO 9001 Quality Management standards, or HIPPA
  • working with and/or supporting computer technologies (such as: databases, operating systems, computer network hardware, protocols, security methodologies, software programs, hardware troubleshooting or electronics)

Nice to have

  • Knowledge and capability of writing scripts in PowerShell, BASH, and Splunk Search Processing Language (SPL)
  • Familiarity with implementation of Government directives and policies derived from NIST, CNSSI, DoD, or other Government Regulatory compliance standards within a professional industry.
  • Experience providing technical security consultation for complex, cross-domain, heterogeneous classified networked environments in collaboration with internal/external Customers, Information Technology (IT).
  • Familiarity with large multi-facility networks including complex components, including Windows and Linux environments.
  • Experience interpreting, implementing, and assessing DISA STIGs.
  • Experience with continuous monitoring and Plans of Actions and Milestones (POA&Ms)

What the JD emphasized

  • Active and transferable U.S. government issued security clearance is required prior to start date
  • U.S. citizenship is required
  • Active and existing security clearance required on day 1
  • IAM Level I certification (Security+ or other)
  • Experience with various information system security tools that address vulnerability analysis and mitigation. These include Splunk, Forcepoint, Ivanti, Tenable, ACAS, HBSS, etc.
  • Compliance-based auditing using the Risk Management Framework (RMF), DCSA Assessment and Authorization Process Manual (DAAPM), Joint SAP Implementation Guide (JSIG), National Industrial Security Program Operating Manual (NISPOM), and/or non-defense regulations such as FAA, Payment Card Industry (PCI), ISO 9001 Quality Management standards, or HIPPA