Sr Manager - Isso (information System Security Officer)

RTX RTX · Aerospace · Central Singapore, Singapore +1 · Digital Technology

This role is for a Sr. Manager - Information System Security Officer (ISSO) at RTX, a defense company, based in Singapore. The position focuses on overseeing cyber and regulatory compliance programs for RTX business units in China, ensuring the cyber posture of sites, and establishing guidelines to protect information systems. Responsibilities include governance, cyber risk management, compliance with regulations (ISO 27001, NIST SP800-171, EASA Part-IS), security event and incident management, and providing technical security guidance.

What you'd actually do

  1. Ensure the management and local cyber governance of the Information Systems within the sites under ISSO scope.
  2. Manage cyber risks (identification, evaluation and treatment) according to applicable enterprise-wide cyber risk program and regulations including but not limited to Part-IS.
  3. Ensure compliance with applicable security requirements for the sites (internal policies, applicable regulations and customer frameworks).
  4. Ensure that threat detection capabilities provided by RTX Cyber-Defense team are fully implemented.
  5. Provide expert security guidance to DT Int’l Operations (e.g., vulnerability management, remediation plan execution, support on new cyber programs).

Skills

Required

  • Information System Security Officer (ISSO) experience
  • Cyber and regulatory compliance program management
  • Information Systems security
  • Risk management
  • Governance, Risk, and Compliance (GRC)
  • ISO 27001
  • NIST SP800-171
  • EASA Part-IS regulation
  • Security event and incident management
  • Threat detection
  • Vulnerability management
  • Technical security guidance
  • Experience in defense or aerospace industry
  • Experience with Chinese regulatory landscape (implied by focus on China)

Nice to have

  • Experience with OT security
  • Experience with Cloud security
  • Experience with Restricted and Classified IS
  • Business continuity and disaster recovery planning

What the JD emphasized

  • regulatory compliance
  • cyber posture
  • cyber threats
  • digital compliance risks
  • cybersecurity
  • cyber posture
  • cyber threats
  • digital compliance risks
  • cybersecurity
  • regulatory requirements
  • risk management
  • security controls
  • security requirements
  • security requirements
  • cyber threats
  • cyber-defense operations
  • incident response
  • security guidance
  • critical vulnerabilities
  • security strategies
  • business continuity/recovery
  • compliance programs
  • security guidance