Senior Cybersecurity Risk and Compliance Analyst

Raytheon Technologies
Sterling, VA, USA
$96K-$200K a year
Full-time

Date Posted : 2024-07-22

2024-07-22

Country :

United States of America

Location :

VA543 : 22270 Pacific Blvd, Dulles 22270 Pacific Boulevard Building CC5, Sterling, VA, 20166-6924 USA

Position Role Type : Hybrid

Hybrid

You have been redirected to RTX’s career page as we have recently transitioned from RTX to become a standalone company, which provides us with greater autonomy and opportunities for growth.

As a prospective employee of Nightwing, you’ll have the chance to contribute to our continued success and shape the future of our cybersecurity, intelligence, and services offerings.

As a Senior Cybersecurity Risk and Compliance Analyst, you will play a pivotal role in achieving these objectives by leveraging your expertise in DFARs, NIST 800-171, and CMMC.

As a Cybersecurity Risk and Compliance Analyst at Nightwing, you will be responsible for assessing and managing cybersecurity risks, ensuring compliance with DFARs (Defense Federal Acquisition Regulation Supplement), NIST 800-171 (National Institute of Standards and Technology), and CMMC (Cybersecurity Maturity Model Certification) requirements.

You will collaborate closely with cross-functional teams to enhance the organization's cybersecurity posture and meet regulatory obligations.

Support internal audit processes for control validation Includes compliance with DFARs cybersecurity requirements including 800-171.

Guide the organization through the process of achieving and maintaining CMMC certification, including conducting readiness assessments and facilitating audits.

Conduct comprehensive cybersecurity risk assessments, identify vulnerabilities, and recommend mitigation strategies on corporate networks / systems and Program Unique Environments (PUEs)

Collaborate with ISSOs to achieve Authorization and Accreditation of US government systems on programs as required.

Develop and maintain cybersecurity policies, procedures, and documentation to ensure alignment with regulatory standards.

Promote a culture of cybersecurity awareness and best practices among employees through training and communication.

Implement continuous monitoring programs to track compliance and security status, and report findings to management.

Collaborate with Legal and Supply Chain functions to create a framework to evaluate and assess third-party vendors for cybersecurity compliance and risk management.

Prepare and present compliance reports and findings to senior management and external auditors.

Review outputs from POAMs to assess completeness and make recommendations for any further work needed or POAM closure.

Required

Bachelor's degree in Cybersecurity, Information Technology, or a related field. Advanced certifications such as CISSP, CISM, or CISA are a plus.

Minimum of 8 years of experience in cybersecurity risk and compliance, with a strong focus on DFARs, NIST 800-171, and CMMC.

In-depth understanding of cybersecurity frameworks, standards, and best practices. (i.e. NIST, ISO27001, CMMC)

Strong analytical and problem-solving skills, with the ability to assess and mitigate cybersecurity risks effectively.

Excellent communication skills to convey complex cybersecurity concepts to both technical and non-technical stakeholders.

Experience with GRC and Information security tools / technologies to collect and maintain security and risk information

Experience with cybersecurity tools and technologies for monitoring and compliance tracking.

Ability to work independently, prioritize tasks, and meet deadlines in a dynamic and fast-paced environment.

Desired :

Advanced certifications such as CISSP, CISM, or CISA are a plus.

Previously part of a leading Fortune 100 company and headquartered in Dulles, VA; Nightwing became independent in 2024 but continues to support the nation’s most mission impactful initiatives.

When we formed Nightwing, we brought a deep set of credentials and an unfaltering commitment to the mission. For over four decades, our team has been providing some of the world’s most technically advanced full-spectrum cyber, data operations, systems integration and intelligence support services to the U.

S. government on its most important missions.

At Nightwing, we value collaboration and teamwork. You’ll have the opportunity to work alongside talented individuals who are passionate about what they do.

Together, we’ll leverage our collective expertise to drive innovation, solve complex problems, and deliver exceptional results for our clients.

Thank you for considering joining us as we embark on this new journey and shape the future of cybersecurity and intelligence together as part of the Nightwing team.

The salary range for this role is 96,000 USD - 200,000 USD. The salary range provided is a good faith estimate representative of all experience levels.

RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate’s work experience, location, education / training, and key skills.

Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays.

Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.

Hired applicants may be eligible for annual short-term and / or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement.

Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and / or the company’s performance.

This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.

RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.

28 days ago
Related jobs
Promoted
The Aerospace Corporation
Chantilly, Virginia

From systems architecture development to system analysis and optimization, astrodynamics, orbital debris, navigation, failure analysis, mission assurance, cost and schedule assessment, and economic market analysis, SED exploits an incredibly broad array of engineering and business disciplines agains...

Freddie Mac
McLean, Virginia

Identifies control weaknesses and opportunities for improvement in the Seller/Servicer’s current operating environment and may discuss recommendations for corrective action; drafts the related Audit issues and Audit reports with oversight from Audit Leadership for issuance to respective Seller/Servi...

Splunk Inc
Virginia, United States
Remote

Splunk is looking for a motivated Senior Analyst who is passionate about delivering technology assurance, advisory, compliance and risk management services to the company. You will ensure proper identification and mitigation of risks / processes / internal control gaps that have potential operationa...

Capital One
McLean, Virginia

At least 5 years of experience developing and implementing industry risk frameworks, quantitative analysis, tools, and methodologies (COSO Framework, quantitative analysis, Factor Analysis Information Risk (FAIR), Process, Risk & Control (PRC) library), or assessment methodologies (Risk and Control ...

Na Ali'i Consulting & Sales, LLC.
Reston, Virginia

Plan, research, develop, and communicate in-depth analyses of complex and significant national, regional, and/or global issues for senior policymakers and key components of the Department of Defense and the Intelligence Community (IC). Cultivate and maintain productive and collaborative working rela...

LexisNexis Risk Solutions FL Inc. Company
Virginia
Remote

Learning and applying industry-standard analytic software tools at an Expert level, including but not limited to, Microsoft Suite of tools, ESRI ArcGIS, i2 Analysts Notebook, and proprietary LexisNexis suite of solutions. This position will be capable of large dataset analysis and well-versed in bot...

GDIT
Falls Church, Virginia

Deputy ISSO (Senior Cybersecurity Compliance Analyst): Assesses and mitigates system security threats and risks throughout the program life cycle. Security and Privacy Support responsibilities include participating in infrastructure design reviews, identifying security and privacy risks, providing i...

Freddie Mac
McLean, Virginia

Will collaborate closely with I&CM key partners, and regularly engage with I&CM Business and Technology Office (BTO) personnel in monitoring the compliance of information risk policies, standards, and procedures. The successful candidate will perform data governance and compliance activities as part...

The Aerospace Corporation
Chantilly, Virginia

From systems architecture development to system analysis and optimization, astrodynamics, orbital debris, navigation, failure analysis, mission assurance, cost and schedule assessment, and economic market analysis, SED exploits an incredibly broad array of engineering and business disciplines agains...

Peraton
Reston, Virginia

As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all doma...