Date Posted:2026-09-23
Country:United States of America
Location:US-FL-LARGO-382SS ~ 7887 Bryan Dairy Rd. ~ BLDG 100
Position Role Type:Onsite
U.S. Citizen, U.S. Person, or Immigration Status Requirements: Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance
Security Clearance Type: TS/SCI - Current
Security Clearance Status: Active and existing security clearance required on day 1
We're hiring for a Senior Information Assurance and Cybersecurity professional with extensive experience independently leading
RMF, ICD 503, NISPOM, and security authorization activities for sensitive systems. Provides senior-level technical leadership across risk assessments, security control implementation and assessment, vulnerability management, continuous monitoring, compliance audits, and development of critical RMF artifacts including
SSPs, SCTMs, SARs, RARs, and POA&Ms.
This role will be worked onsite in Largo, FL and requires an active and transferrable TS/SCI clearance. Relocation assistance is not available.What You Will Do:- Independently lead and execute Information Assurance (IA) and Risk Management Framework (RMF) activities for information systems processing National Security Information, from system categorization and control selection through assessment, authorization, and continuous monitoring
- Provide senior-level technical expertise and recommendations under the general direction of the Information Assurance Domain Lead and/or Information Technology leadership, exercising independent judgment in resolving complex cybersecurity, compliance, and risk-management issues
- Ensure applicable National Industrial Security Program Operating Manual (NISPOM) requirements are effectively implemented, operationally functional, periodically assessed, and accurately documented within the RMF process
- Lead the development, review, maintenance, and presentation of RMF and ICD 503 artifacts, including System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Plans of Action and Milestones (POA&Ms), Continuous Monitoring Plans, security control assessment evidence, and other authorization documentation
- Analyze system architectures, security controls, vulnerabilities, and operational environments to identify cybersecurity risks and develop risk-based recommendations and mitigation strategies
- Develop and maintain comprehensive System Security Plans (SSPs) and supporting certification and authorization documentation, ensuring technical implementations and supporting evidence accurately reflect the operational environment
- Interpret and implement applicable requirements from the NIST 800 Series, ICD 503, JSIG, DCID, NISPOM, ICD 705, and other government security policies, directives, and standards
- Conduct or support technical computer and network system audits, security control assessments, vulnerability assessments, configuration reviews, and compliance evaluations to identify security gaps and validate implementation effectiveness
- Work directly with Information System Security Managers (ISSMs), Security Control Assessors (SCAs), Information System Security Officers (ISSOs), system administrators, engineers, and customer personnel to review, update, defend, and explain accreditation and authorization documentation
- Serve as a technical point of contact during RMF assessments, audits, inspections, customer reviews, and authorization activities, coordinating responses to findings and ensuring timely closure of identified deficiencies
- Evaluate and interpret STIGs, ACAS results, vulnerability scan data, configuration baselines, and other security-hardening requirements to identify security deficiencies and develop appropriate remediation plans
- Lead continuous monitoring activities and establish processes for tracking security controls, vulnerabilities, POA&Ms, configuration changes, system modifications, and other events that may affect an authorization boundary or risk posture
- Provide technical leadership in the assessment and implementation of security controls across enterprise, network, host, application, and enclave environments
- Identify opportunities to improve RMF processes, documentation quality, security posture, and operational efficiency; develop and implement process improvements where appropriate
- Mentor and provide technical guidance to junior IA/RMF personnel, including review of security documentation, assessment evidence, control implementations, and remediation activities
- Collaborate across engineering, information technology, program management, security, and functional organizations to integrate cybersecurity requirements into system development, deployment, modification, and sustainment activities
- Communicate complex cybersecurity and RMF requirements clearly to technical and non-technical stakeholders and provide actionable recommendations to management and customers
- Support security investigations, risk assessments, remediation activities, and other cybersecurity initiatives as required
Travel in support of program, customer, assessment, audit, and security requirements on an as-needed basis
Qualifications You Must Have:- Typically requires a degree in Science, Technology, Engineering or Mathematics (STEM) and minimum 8 years prior relevant experience or an Advanced Degree in a related field and minimum 5 years of experience
- Active and transferable U.S. government issued TS/SCI security clearance is required prior to start date
- DoD 8570 IAT Level III certification (CISM, CASP or CISSP preferred)
Qualifications We Prefer:- Deep understanding of NIST SP 800-series publication
- Experience conducting vulnerability scans, security assessments, and risk analysis
- Knowledge of system security architecture, network protocols, and information systems
- Ability to work with an extremely risk adverse customer and their policies
- Ability to quickly switch tasks based on changing priorities
- Ability to adapt both an offensive and defensive mindset to support securing information systems
- Excellent writing, speaking, analytical, project management, organizational, and customer service skills
What We Offer:Some of our competitive benefits package includes: - Medical, dental, and vision insurance
- Three weeks of vacation for newly hired employees
- Generous 401(k) plan that includes employer matching funds and separate employer retirement contribution, including a Lifetime Income Strategy option
- Tuition reimbursement program
- Student Loan Repayment Program
- Life insurance and disability coverage
- Optional coverages you can buy pet insurance, home and auto insurance, additional life and accident insurance, critical illness insurance, group legal, ID theft protection
- Birth, adoption, parental leave benefits
- Carrot Health, fertility, and family planning
- Adoption Assistance
- Autism Benefit
- Employee Assistance Plan, including up to 10 free counseling sessions
- Healthy You Incentives, wellness rewards program
- Doctor on Demand, virtual doctor visits
- Bright Horizons, child and elder care services
- Teladoc Medical Experts, second opinion program
- And more!
Learn More & Apply Now!Please ensure the role type defined below is appropriate for your needs before applying to this role. This position is classified as:
Onsite: Employees who are working in Onsite roles will work primarily onsite. This includes all production and maintenance employees, as they are essential to the development of our products.
As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote.The salary range for this role is 107,500 USD - 204,500 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills.
Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.
Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance.
This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.
RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.