Information System Security Manager (Onsite)
At RTX, the world's largest aerospace and defense company, 185,000 great minds are united by purpose and inspired to solve the world’s most complex problems. Pratt & Whitney is a world leader in the design, manufacture, and service of aircraft engines and auxiliary power systems, revolutionizing modern flight for over 100 years.
This role is onsite in East Hartford, Connecticut. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance. An active and transferable U.S. government-issued Secret (or higher) security clearance is required prior to the start date.
About the role
The Pratt & Whitney Government Security Compliance (GSC) cybersecurity team is seeking an Information Systems Security Manager (ISSM) to support National Institute of Standards and Technology (NIST) Special Publications, customer directives, and company policies, including compliance with National Industrial Security Program Operating Manual (NISPOM) Chapter 8 and the Joint Special Access Program Implementation Guide (JSIG).
We are looking for candidates with initiative, creativity, adaptability, strong written and verbal communication skills, analytical abilities, attention to detail, and the ability to work effectively in a time-sensitive, dynamic environment.
Responsibilities
- Ensure information system(s) security objectives are achieved and organizational risk is effectively managed for all Information Systems (IS) under purview.
- Serve as the primary cybersecurity authority for inspections, assessments, audits, and continuous monitoring, leading preparation, execution, and response activities to maintain authorization and inspection readiness.
- Engage with Program Managers to integrate cybersecurity requirements into program execution, schedules, and decision-making, addressing risk impacts to cost, scope, and mission delivery.
- Investigate information system security violations and prepare reports specifying corrective and preventative actions.
- Review and approve, within authority, configuration management requests.
- Communicate with government Security Control Assessors (SCA) and Authorizing Officials (AO) when authorization is required.
- Execute and maintain system authorization using the Risk Management Framework (RMF) and applicable guidance, including the JSIG for SAP systems.
- Support the creation, review, and update of cybersecurity documentation and other technical writing.
- Maintain awareness and working knowledge of DD Form 254s and contractual security requirements, ensuring cybersecurity controls align with approved mission and program objectives.
- Develop, manage, and drive closure of Plans of Action and Milestones (POA&Ms) resulting from inspections, assessments, and continuous monitoring activities.
- Develop, maintain, and validate cybersecurity plans, authorization artifacts, and compliance documentation to support audit-ready operations.
- Identify, assess, and communicate cybersecurity risk, including Security Impact Analysis (SIA), to senior leadership and AOs, covering system changes, vulnerabilities, inspection findings, and authorization conditions.
Requirements
- Advanced degree and 4+ years of combined experience in Systems Administration, Systems Engineering, Security/Cybersecurity, Info-Tech/Networking, or Management role supporting classified programs or government-regulated environments; OR
- Bachelor’s degree and 8+ years of relevant industry experience; OR
- Associate’s degree (or 2-year technical training) and 10+ years of relevant industry experience; OR
- High School diploma or Military/Technical Training and 12+ years of relevant industry experience.
- Current DoD 8570 IAM Level II certification (e.g., Security+, CGRC, CISM) with the ability to acquire IAM Level III certification (e.g., GSLC, CISSP, CISSM) within 6 months.
- Active U.S. Government Secret (or higher) security clearance required on day 1.
- Ability to communicate effectively with Program Management, Government authorities, and Executive-level leadership.
Qualifications (Preferred)
- Active U.S. Government TOP SECRET security clearance with previous SAP experience.
- DoD 8570 IAM Level III certification (e.g., GSLC, CISSP, CISSM).
- Experience working in DoD classified Special Operating Programs and/or laboratory environments.
- Experience with information system security and monitoring tools (e.g., Splunk, Symantec, Ivanti, Tenable, ACAS, HBSS).
- Experience providing technical security consultation for complex, cross-domain, heterogeneous classified networked environments in collaboration with internal/external customers.
- Familiarity with large multi-facility networks, including Windows and Linux environments.
- Experience interpreting, implementing, and assessing security hardening guides and tools (e.g., DISA STIGs/SCAP).
- Familiarity with the execution and management of cyber incident response, including preservation, containment, and eradication.
Pay
The salary range for this role is $107,500 – $204,500 USD. The range provided is a good-faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including role, function, responsibilities, work experience, location, education/training, and key skills.
Benefits
- Medical, dental, and vision insurance.
- Life insurance, short-term disability, and long-term disability.
- 401(k) match.
- Flexible spending accounts.
- Flexible work schedules.
- Employee assistance program.
- Employee Scholar Program.
- Parental leave.
- Paid time off and holidays.
- Eligibility for annual short-term and/or long-term incentive compensation programs (dependent on role level and collective-bargaining agreement status).