Jobs and Careers
RT

Cybersecurity Risk Analyst (Hybrid)

RTX
United Statesfull_timeVerifiedPosted 24 Oct 2024
💰 $179,000/yr($85,000/yr$179,000/yr)

About the role

Date Posted:

2024-09-12

Country:

United States of America

Location:

HMD31: Annapolis, MD 2551 Riva Road , Annapolis, MD, 21401-7435 USA

Position Role Type:

Hybrid

Do you want to be part of a growing team of cybersecurity analysts & experts working to identify real-world threats, analyze risks, and develop novel solutions for complex cyber challenges?

Collins Aerospace, an RTX company, is a leader in advanced technologically and intelligent solutions for the global aerospace and defense industry. Our Connected Aviation Solutions (CAS) Cybersecurity team is searching for a Cybersecurity & Risk Analyst.  As a member of the Governance, Risk and Compliance team, this analyst will lead risk assessments of new and legacy products as well as have meaningful conversations in mitigating risk, providing guidance of RTX Cyber Policies, and knowledge transfer to fellow team members as well as product engineering teams.  As we launch a new Issues Management and Authorization to Operate (ATO) processes for CAS Products, the Cybersecurity Risk Analyst will play an integral role in the success of the program through the implementation of the process and coordination with product teams and their cyber support staff. 

The Cybersecurity Risk Analyst will provide training and guidance to stakeholders across the organization, collaborating with other risk management professionals to share knowledge, best practices, and lessons learned to help Product Team members build a strong risk-aware culture.  This role requires collaboration with RTX Corporate Cyber teams, stakeholders, and leaders across multiple teams to achieve objectives and manage updates on multiple processes.
 

Regardless of role, we expect excellent interpersonal and communication skills across all hires at Collins Aerospace. We look for candidates who will thrive here, meaning they demonstrate clear communication, embrace open feedback, trust their colleagues, and are driven to execute, deliver, and complete projects independently and efficiently.  

This role is Hybrid (3 days/week on site) based in Annapolis, Maryland.

What You Will Do: 

Internal product Risk Assessments:

  • Provide consultation and guidance to product teams, facilitate assessment activities, & document findings.

  • Conduct probability and impact analyses & prepare and maintain risk assessment reports for the duration of the product lifecycle.

Authorization to Operate (ATO) Processes:

  • Provide guidance to internal product teams on conducting control assessments / gap analyses in accordance with NIST 800-171.

  • Review evidence for completeness and adequacy & vulnerability, SAST, DAST, etc. scan results.

  • Support issues identification and risk register preparation & prepare ATO reports and participate in ATO leadership evaluations.

Issues Management Processes:

  • Provide guidance to internal product teams on identifying, assessing, and documenting cybersecurity issues, gaps, vulnerabilities, etc.

  • Review submitted issues and risk evaluations, offering feedback and consulting services to product teams.

  • Support risk register management activities & aid in the preparation of issue management reports and participate in issue analysis and review.

Cybersecurity Documentation Management:

  • Support periodic reviews and updates of existing cybersecurity documentation (e.g., procedures, guidance, forms, etc.).

  • Develop new documentation as needed to align with changing industry best practices and corporate requirements.

Consulting:

  • Help product teams interpret and align with new cybersecurity policies, laws, and regulations & provide cybersecurity guidance, training, and awareness.

Qualifications You Must Have: 

  • U.S. citizenship is required, as only U.S. citizens are authorized to access information under this program/contract 

  • Typically requires a University Degree and minimum 5 years prior relevant experience or an Advanced Degree in a related field and minimum 3 years of experience or in absence of a degree, 9 years of relevant experience.

  • Cyber security experience developing policies/governance, conducting security control assessments/gap analysis, and risk assessmen

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

RTX

View company profile →