Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
RTX

Senior Principal Cybersecurity Engineer, FOSS Governance and Risk Management

RTX

Sr Principal Cybersecurity Engineer defining FOSS governance, vulnerability management, and incident response. Securing software supply chains for RTX’s aerospace and defense systems.

Posted 8/19/2026full-timeRemote • Florida • 🇺🇸 United StatesSenior💰 $132,400 - $251,600 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in FOSS cybersecurity governance, vulnerability management, and incident response, with a strong focus on developing policies, standards, and risk-based decision frameworks. Proficient in collaborating with cross-disciplinary teams and integrating governance controls within software supply chain processes.

Highest-signal resume keywords
FOSS Cybersecurity GovernanceVulnerability ManagementSoftware Supply Chain SecurityTechnical WritingDevSecOps

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Cybersecurity EngineeringIncident Response ProcessesFOSS Vulnerability AnalysisRisk-Based Decision FrameworksSCA ToolingSBOM TechnologiesVulnerability Scoring MethodologiesAgile DevelopmentContinuous IntegrationAutomated Testing
Soft Skills
CollaborationCommunication
Tools & Technologies
JFrogSonatypeCI/CD Environments
Certifications & Qualifications
U.S. Government Security ClearanceDoD Secret Security Clearance
Industry Keywords
NIST SSDFSLSACMMCEO 14028Software Bill of Materials

Tech Stack

Tools & technologies
Cyber Security

About the role

Key responsibilities & impact
  • Define and maintain enterprise FOSS cybersecurity governance, including policies, standards, lifecycle controls, and decision frameworks
  • Establish FOSS vulnerability management requirements for ingestion, approved use, patching, ratings, and escalation
  • Design and operationalize processes for identifying, triaging, and remediating FOSS vulnerabilities
  • Develop and maintain a FOSS cybersecurity incident response model for enterprise coordination, threat assessment, containment, and communications
  • Integrate governance controls with ingestion pipelines, scanning workflows, SBOM generation, and enterprise artifact management
  • Partner with legal, supply chain, platform owners, and cybersecurity governance to align policies with licensing, regulatory, and software supply chain requirements
  • Provide expert guidance to programs and engineering teams on risk-based decisions and FOSS governance adherence
  • Guide teams in effective Software Bill of Materials (SBOM) use
  • Develop technical documentation, governance models, workflows, diagrams, policy standards, and process guidance
  • Travel as needed, estimated at 10–15%

Requirements

What you’ll need
  • Bachelor’s degree in Cybersecurity, Engineering, Computer Science, Software Engineering, or related STEM discipline
  • Minimum of 10 years of experience in cybersecurity engineering, governance, vulnerability management, secure software development, or supply chain security
  • Demonstrated experience developing or operating enterprise security policies, standards, or risk based decision frameworks
  • Expertise in software supply chain security, FOSS vulnerability analysis, threat triage, or incident response processes
  • Practical understanding of SCA tooling, SBOM technologies, and enterprise monitoring of open-source components
  • Experience collaborating with cross disciplinary teams including legal, supply chain, engineering, DT, and cyber governance
  • Strong technical writing skills for creating policies, workflows, and governance documentation
  • Experience with DevSecOps
  • Experience with Agile development such as Scrum, Continuous Integration, Automated Testing, etc.
  • U.S. citizenship required
  • Ability to obtain and maintain a U.S. government security clearance
  • Active and existing DoD Secret security clearance required after day 1
  • Advanced degree in Cybersecurity, Engineering, Computer Science, Software Engineering, or related field preferred
  • Experience with enterprise artifact ecosystems such as JFrog and Sonatype or large-scale CI/CD environments preferred
  • Background in developing vulnerability scoring methodologies or enterprise-wide threat triage models preferred
  • Experience with regulatory bodies, audit organizations, or software supply chain security frameworks such as NIST SSDF, SLSA, CMMC, and EO 14028 preferred
  • Experience leading cybersecurity governance initiatives across multiple business units preferred
  • Preferred: Within 50 miles of an RTX facility

Benefits

Comp & perks
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Life insurance
  • Short-term disability
  • Long-term disability
  • 401(k) match
  • Flexible spending accounts
  • Flexible work schedules
  • Employee assistance program
  • Employee Scholar Program
  • Parental leave
  • Paid time off
  • Holidays
  • Annual short-term and/or long-term incentive compensation programs, where eligible