FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Principal Cybersecurity Engineer, FOSS Governance and Risk Management
RTXSr Principal Cybersecurity Engineer defining FOSS governance, vulnerability management, and incident response. Securing software supply chains for RTX’s aerospace and defense systems.
Posted 8/19/2026full-timeRemote • Florida • 🇺🇸 United StatesSenior💰 $132,400 - $251,600 per yearWebsite
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in FOSS cybersecurity governance, vulnerability management, and incident response, with a strong focus on developing policies, standards, and risk-based decision frameworks. Proficient in collaborating with cross-disciplinary teams and integrating governance controls within software supply chain processes.
Highest-signal resume keywords
FOSS Cybersecurity GovernanceVulnerability ManagementSoftware Supply Chain SecurityTechnical WritingDevSecOps
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Cybersecurity EngineeringIncident Response ProcessesFOSS Vulnerability AnalysisRisk-Based Decision FrameworksSCA ToolingSBOM TechnologiesVulnerability Scoring MethodologiesAgile DevelopmentContinuous IntegrationAutomated Testing
Soft Skills
CollaborationCommunication
Tools & Technologies
JFrogSonatypeCI/CD Environments
Certifications & Qualifications
U.S. Government Security ClearanceDoD Secret Security Clearance
Industry Keywords
NIST SSDFSLSACMMCEO 14028Software Bill of Materials
Tech Stack
Tools & technologiesCyber Security
About the role
Key responsibilities & impact- Define and maintain enterprise FOSS cybersecurity governance, including policies, standards, lifecycle controls, and decision frameworks
- Establish FOSS vulnerability management requirements for ingestion, approved use, patching, ratings, and escalation
- Design and operationalize processes for identifying, triaging, and remediating FOSS vulnerabilities
- Develop and maintain a FOSS cybersecurity incident response model for enterprise coordination, threat assessment, containment, and communications
- Integrate governance controls with ingestion pipelines, scanning workflows, SBOM generation, and enterprise artifact management
- Partner with legal, supply chain, platform owners, and cybersecurity governance to align policies with licensing, regulatory, and software supply chain requirements
- Provide expert guidance to programs and engineering teams on risk-based decisions and FOSS governance adherence
- Guide teams in effective Software Bill of Materials (SBOM) use
- Develop technical documentation, governance models, workflows, diagrams, policy standards, and process guidance
- Travel as needed, estimated at 10–15%
Requirements
What you’ll need- Bachelor’s degree in Cybersecurity, Engineering, Computer Science, Software Engineering, or related STEM discipline
- Minimum of 10 years of experience in cybersecurity engineering, governance, vulnerability management, secure software development, or supply chain security
- Demonstrated experience developing or operating enterprise security policies, standards, or risk based decision frameworks
- Expertise in software supply chain security, FOSS vulnerability analysis, threat triage, or incident response processes
- Practical understanding of SCA tooling, SBOM technologies, and enterprise monitoring of open-source components
- Experience collaborating with cross disciplinary teams including legal, supply chain, engineering, DT, and cyber governance
- Strong technical writing skills for creating policies, workflows, and governance documentation
- Experience with DevSecOps
- Experience with Agile development such as Scrum, Continuous Integration, Automated Testing, etc.
- U.S. citizenship required
- Ability to obtain and maintain a U.S. government security clearance
- Active and existing DoD Secret security clearance required after day 1
- Advanced degree in Cybersecurity, Engineering, Computer Science, Software Engineering, or related field preferred
- Experience with enterprise artifact ecosystems such as JFrog and Sonatype or large-scale CI/CD environments preferred
- Background in developing vulnerability scoring methodologies or enterprise-wide threat triage models preferred
- Experience with regulatory bodies, audit organizations, or software supply chain security frameworks such as NIST SSDF, SLSA, CMMC, and EO 14028 preferred
- Experience leading cybersecurity governance initiatives across multiple business units preferred
- Preferred: Within 50 miles of an RTX facility
Benefits
Comp & perks- Medical insurance
- Dental insurance
- Vision insurance
- Life insurance
- Short-term disability
- Long-term disability
- 401(k) match
- Flexible spending accounts
- Flexible work schedules
- Employee assistance program
- Employee Scholar Program
- Parental leave
- Paid time off
- Holidays
- Annual short-term and/or long-term incentive compensation programs, where eligible