Sr Principal Cybersecurity Engineer, FOSS Governance and Risk Management

RTX
Florida
Workplace: RemoteFull timeUSD 132,400 - 251,600 annuallyFunction: CybersecurityExperience: 10+ yearsEducation: bachelorsSkills: ["Technical writing","Cross-disciplinary collaboration","Risk-based decision making","Vulnerability triage","Incident response coordination"]

Define and maintain enterprise governance for Free and Open Source Software (FOSS), including policies, standards, and lifecycle controls. Drive FOSS vulnerability management and triage, operationalize vulnerability remediation processes, and develop incident response models for consistent enterprise coordination. Ensure governance integrates with ingestion, scanning, SBOM generation, and artifact management, while partnering with legal, supply chain, platform owners, and engineering to support compliant, risk-based decisions across RTX.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
RTX
RTX
2 days ago

Sr Principal Cybersecurity Engineer, FOSS Governance and Risk Management

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 1 hour agoStatus: Live

Job Summary

Define and maintain enterprise governance for Free and Open Source Software (FOSS), including policies, standards, and lifecycle controls. Drive FOSS vulnerability management and triage, operationalize vulnerability remediation processes, and develop incident response models for consistent enterprise coordination. Ensure governance integrates with ingestion, scanning, SBOM generation, and artifact management, while partnering with legal, supply chain, platform owners, and engineering to support compliant, risk-based decisions across RTX.
Location: Florida
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Sr. Manager level

Key Responsibilities

  • •Define and maintain enterprise FOSS cybersecurity governance (policies, standards, lifecycle controls, decision frameworks).
  • •Establish FOSS vulnerability management requirements, including ingestion, approved use, patching, ratings, and escalation.
  • •Design and operationalize processes for identifying, triaging, and remediating FOSS vulnerabilities aligned to cyber risk practices and guidance (e.g., NIST SSDF, SLSA, EO 14028).
  • •Develop and maintain a FOSS cybersecurity incident response model, including coordination, threat assessment, containment, and communication workflows.
  • •Ensure governance integrates with ingestion pipelines, scanning workflows, SBOM generation, and enterprise artifact management; provide expert guidance and documentation for programs and engineering teams.
Travel: Low travel

Pay and Benefits

Salary: USD 132,400 - 251,600 annually
Perks:Health InsuranceDentalVisionLife Insurance401kParental LeavePaid Leave

Key Requirements

  • •Bachelor’s degree in Cybersecurity, Engineering, Computer Science, Software Engineering, or related STEM.
  • •10+ years of experience in cybersecurity engineering, governance, vulnerability management, secure software development, or supply chain security.
  • •Experience developing or operating enterprise security policies, standards, or risk-based decision frameworks.
  • •Expertise in software supply chain security, FOSS vulnerability analysis, threat triage, or incident response processes.
  • •Practical understanding of SCA tooling, SBOM technologies, and enterprise monitoring of open-source components.
Experience:10+ yearsAerospace and defenseSoftware supply chain securityOpen sourceDevSecOpsSBOM
Education:Bachelor's
Skills:Technical writingCross-disciplinary collaborationRisk-based decision makingVulnerability triageIncident response coordination
Tech Stack:DevSecOpsAgileScrumCI/CDAutomated TestingSCA toolingSBOMJFrogSonatypeNIST SSDFSLSAEO 14028CMMC

Eligibility

Security Clearance:DoD Clearance: Secret

Company Brief

RTX
Designs, manufactures, and services aerospace and defense systems, including aircraft engines, avionics, aerostructures, missiles, and cybersecurity solutions for commercial, military, and government customers worldwide.
Industry: Aerospace Manufacturing
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Arlington, United States
Founded: 2020
Website