Senior Information System Security Officer (isso) - Tucson, Az

RTX RTX · Aerospace · tucson, AZ +1 · Digital Technology

Senior Information Systems Security Officer (ISSO) at RTX in Tucson, AZ, responsible for assessing and monitoring system compliance, auditing, security plan development, and information systems security education. The role involves investigating security violations, preparing reports, reviewing configuration management requests, conducting technical assessments, integrating cybersecurity processes, and supporting documentation. Requires a current U.S. government issued security clearance (Secret - Current) and a University Degree or equivalent experience with a minimum of 5 years relevant experience, or an Advanced Degree with 3 years experience. A current IAM Level I certification (Security+ or other) is also required. Experience in cybersecurity, systems security, hardening, IT, compliance auditing (RMF, DAAPM, JSIG, NISPOM, FAA, PCI, ISO 9001, HIPAA), working with computer technologies, physical security, investigations, or project management is considered relevant. Preferred qualifications include experience in DoD classified environments, various information system security tools (Splunk, Forcepoint, Tenable, etc.), familiarity with NIST/CNSSI/DoD directives, RMF A&A processes, large multi-facility networks, DISA STIGs, and cyber incident response.

What you'd actually do

  1. Assessing and monitoring system compliance, auditing, security plan development and delivering information systems security education and awareness.
  2. Investigating information system security violations and help prepare reports specifying corrective and preventative actions.
  3. Reviewing and approving (within authority) configuration management requests.
  4. Conducting technical and administrative assessments.
  5. Integrating new cybersecurity processes, procedures, and tools.

Skills

Required

  • University Degree or equivalent experience and minimum 5 years prior relevant experience, or an Advanced Degree in a related field and minimum 3 years’ experience
  • Current IAM Level I certification (Security+ or other)
  • Cybersecurity
  • Systems security
  • Hardening
  • Information Technology
  • Compliance-based auditing using the Risk Management Framework (RMF)
  • DCSA Assessment and Authorization Process Manual (DAAPM)
  • Joint SAP Implementation Guide (JSIG)
  • National Industrial Security Program Operating Manual (NISPOM)
  • non-defense regulations such as FAA, Payment Card Industry (PCI), ISO 9001 Quality Management standards, or HIPPA
  • Experience working with and/or supporting computer technologies (such as: databases, operating systems, computer network hardware, software programs, hardware troubleshooting or electronics)
  • Physical security/security, policework/criminal justice, investigations, or Border Patrol
  • Project or program management, office management, senior administration, or account management

Nice to have

  • Experience working in DoD classified operating and/or laboratory environments.
  • Experience with various information system security tools that address vulnerability analysis and mitigation. These may include Splunk, Forcepoint, Ivanti, Tenable, ACAS, HBSS, etc.
  • Familiarity with implementation of Government directives and policies derived from NIST, CNSSI, DoD, or other Government Regulatory compliance standards within a professional industry.
  • Experience in the execution of the Assessment & Authorization processes, as defined within the Risk Managed Framework (RMF).
  • Experience providing technical security consultation for complex, cross-domain, heterogeneous classified networked environments in collaboration with internal/external Customers, Information Technology (IT).
  • Familiarity with large multi-facility networks including various complex components, including Windows and Linux environments.
  • Experience interpreting, implementing, and assessing DISA STIGs.
  • Familiarity with the execution and management of cyber incident response; preservation, containment, and eradication.

What the JD emphasized

  • Active and transferable U.S. government issued security clearance is required prior to start date
  • U.S. citizenship is required
  • Current IAM Level I certification (Security+ or other)
  • Risk Management Framework (RMF)
  • DAAPM
  • JSIG
  • NISPOM