Hiring.Camp

Sr Principal Cybersecurity Engineer, FOSS Governance and Risk Management

RTX

·

Today

Location
US-FL-REMOTE, United States of America
Workplace
Remote
Type
Full-time
Department
Engineering
Seniority
Lead
Clearance
Required
Source
Workday

Description

Date Posted:

2026-08-19

Country:

United States of America

Location:

US-FL-REMOTE

Position Role Type:

Remote

U.S. Citizen, U.S. Person, or Immigration Status Requirements:

The ability to obtain and maintain a U.S. government issued security clearance is required.​ U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance

Security Clearance Type:

DoD Clearance: Secret

Security Clearance Status:

Active and existing security clearance required after day 1

At RTX, the world's largest aerospace and defense company, 185,000 great minds are united by purpose and inspired to make a difference solving the world’s most complex problems. With our three market leading businesses, world-class operations and investments in research and development, we offer capabilities and opportunity no one else can. Together, we push the boundaries of known science and find new ways to connect and protect our world. 

Raytheon brings the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today’s mission and stay ahead of tomorrow’s threat. We deliver solutions that help our nation and allies defend freedoms and deter aggression, creating a safer, more secure world. Join us and help shape the future of aerospace and defense.

The RTX Product Cybersecurity Center (PCsC) is a leader in securing RTX products, enabling resilience, trust, and compliance throughout the product lifecycle. We foster a cyber aware engineering culture by integrating security controls, modern tooling, and supply chain integrity practices into every aspect of development. Through collaboration, automation, and proactive risk management, we strengthen the foundation that protects RTX customers, partners, and mission critical aerospace and defense systems from evolving global threats.

As part of the PCsC, the FOSS Governance and Risk Management function provides enterprise level cybersecurity oversight for Free and Open Source Software (FOSS). This organization ensures that every open-source component used across RTX engineering and digital technology workflows is governed by robust security policies, monitored for vulnerabilities, and supported by well defined incident response processes. These capabilities improve software supply chain resilience, reduce enterprise risk exposure, and ensure compliance with emerging regulations related to FOSS usage, traceability, and secure lifecycle management.

There is an exciting opportunity for a Sr Principal Cybersecurity Engineer (P5) specializing in FOSS governance, vulnerability management, and incident response. This role is highly visible and will define enterprise processes, influence cybersecurity governance direction, and enable scalable, compliant, and secure FOSS usage across RTX. The Sr Principal Engineer will partner closely with Cyber Engineering, FOSS ecosystem teams, legal, supply chain, program engineering, DT platform owners, and senior leadership to establish end to end governance that meets regulatory, business, and security requirements in a rapidly evolving threat landscape.

This is a full‑time remote position.

What You Will Do

  • Define and maintain enterprise FOSS cybersecurity governance (policies, standards, lifecycle controls, decision frameworks).

  • Establish FOSS vulnerability management requirements (ingestion, approved use, patching, ratings, escalation).

  • Design and operationalize the enterprise process for identifying, triaging, and remediating FOSS vulnerabilities, aligned to RTX cyber risk management practices and industry guidance (NIST SSDF, SLSA, EO 14028, etc.).

  • Develop and maintain a FOSS cybersecurity incident response model, enabling consistent enterprise coordination, rapid threat assessment, containment actions, and communication workflows.

  • Ensure governance controls seamlessly integrate with ingestion pipelines, scanning workflows, SBOM generation, and enterprise artifact management.

  • Partner with legal, supply chain, platform owners, and cybersecurity governance to align FOSS policies with licensing requirements, regulatory expectations, and software supply chain controls.

  • Provide expert guidance to programs and engineering teams, enabling risk based decision making and supporting enterprise adherence to FOSS governance requirements.

  • Guide teams in effective Software Bill of Material (SBOM) use to support risk‑based decisions and compliance with FOSS governance.

  • Develop technical documentation, including governance models, workflows, diagrams, policy standards, and detailed process guidance.

  • Travel as needed (estimated 10–15%).

Qualifications You Must Have

  • Bachelor’s degree in Cybersecurity, Engineering, Computer Science, Software Engineering, or related STEM discipline.

  • Minimum of 10 years of experience in cybersecurity engineering, governance, vulnerability management, secure software development, or supply chain security.

  • Demonstrated experience developing or operating enterprise security policies, standards, or risk based decision frameworks.

  • Expertise in software supply chain security, FOSS vulnerability analysis, threat triage, or incident response processes.

  • Practical understanding of SCA tooling, SBOM technologies, and enterprise monitoring of open‑source components.

  • Experience collaborating with cross disciplinary teams (legal, supply chain, engineering, DT, cyber governance).

  • Strong technical writing skills for creating policies, workflows, and governance documentation.

  • Experience with DevSecOps

  • Experience with Agile development such as Scrum, Continuous Integration, Automated Testing, etc.

  • U.S. citizenship required; ability to obtain and maintain a U.S. government security clearance (if needed by program or business).

Qualifications We Prefer

  • Advanced degree in Cybersecurity, Engineering, Computer Science, Software Engineering, or related field.

  • Experience with enterprise artifact ecosystems (JFrog, Sonatype) or largescale CI/CD environments.

  • Background in developing vulnerability scoring methodologies or enterprise wide threat triage models.

  • Experience working with regulatory bodies, audit organizations, or frameworks related to software supply chain security (NIST SSDF, SLSA, CMMC, EO 14028).

  • Experience leading cybersecurity governance initiatives across multiple business units.

  • Excellent communication, facilitation, and senior leader engagement skills.

  • Preferred: Within 50 miles of an RTX facility.

Learn More & Apply Now

Please ensure the role type defined below is appropriate for your needs before applying to this role. This position is classified as:

Remote: Employees who are working in Remote roles will work primarily offsite (from home). If you live within a reasonable commute of an RTX site with other colleagues you interact with, your manager will discuss whether there is a degree of onsite presence associated with this role.

As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote.

The salary range for this role is 132,400 USD - 251,600 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate’s work experience, location, education/training, and key skills.

Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.

Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company’s performance.

This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.

RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.

RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans’ Readjustment Assistance Act.

Privacy Policy and Terms:

Click on this link to read the Policy and Terms

Skills

CI/CDCybersecurityAgileScrumRisk ManagementComplianceTechnical Writing

Similar Jobs

20

[LTA-ITCD] PRINCIPAL / SENIOR / EXECUTIVE CYBERSECURITY ENGINEER

Sggovterp · LTA HSO B6 02, Singapore

Today

Sr Principal Cybersecurity Architect - AI

JPMorgan Chase · Plano, TX, United States, US

2 days ago

Sr Principal Cybersecurity Architect - AI

JP Morgan Chase · Plano, TX, United States, US

2 days ago

Sr / Principal Cybersecurity Analyst - 19364 - Roy Utah

Northrop Grumman · Roy, UT,US, US · Onsite

6 days ago

Sr / Principal Cybersecurity Analyst - 19364 - Roy Utah

Northrop Grumman · UTRO01, United States of America · Onsite

6 days ago

Sr Principal Classified Cybersecurity Analyst - TS/SCI

Northrop Grumman · Dulles, VA,US, US · Onsite

6 days ago

Sr Principal Classified Cybersecurity Analyst - TS/SCI

Northrop Grumman · VADU01, United States of America · Onsite

6 days ago

Sr Principal Classified Cybersecurity Analyst - Secret

Northrop Grumman · Corinne, UT,US, US · Onsite

2 weeks ago

Sr Principal Classified Cybersecurity Analyst - Secret

Northrop Grumman · UTCO11, United States of America · Onsite

2 weeks ago

Sr / Principal Cybersecurity Analyst - 19150 - Redondo Beach California

Northrop Grumman · Redondo Beach, CA,US, US · Onsite

2 weeks ago

Sr / Principal Cybersecurity Analyst - 19150 - Redondo Beach California

Northrop Grumman · CARBR5, United States of America · Onsite

2 weeks ago

Consultant, Senior Principal (Cybersecurity)

American Bureau of Shipping (ABS) · United States, US · Remote

3 weeks ago

Sr. Principal Cybersecurity Engineer Lead

Northrop Grumman · Chantilly, VA,US, US

3 weeks ago

Sr. Principal Cybersecurity Engineer Lead

Northrop Grumman · VACH10, United States of America

3 weeks ago

Cybersecurity - Senior Sales Specialist/Principal Architect/Field CISO

Converge Technology Solutions · Seattle, WA, USA +4

4 weeks ago

Senior Principal Cybersecurity Engineer

Aptiv · USA Remote Worksite, United States of America · Remote

1 month ago

[LTA-T&ID] PRINCIPAL / SENIOR / EXECUTIVE CYBERSECURITY ENGINEER, AV CYBERSECURITY

Sggovterp · LTA BCO B5 L3, Singapore

1 month ago

Sr Principal Classified Cybersecurity Analyst - Secret

Northrop Grumman · FLME229, United States of America · Remote, Onsite

2 months ago

Senior Principal Cybersecurity Architect

GM Financial · Irving, TX, United States, US · Hybrid

3 months ago

Senior Principal Cybersecurity Researcher

Twosixtechnologies · Arlington, Virginia +1 · Onsite

4 months ago