
Senior Principal Cybersecurity Engineer, FOSS Governance and Risk Management
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Florida.
• Define and uphold enterprise FOSS cybersecurity governance, which includes policies, standards, lifecycle controls, and decision frameworks.
• Establish requirements for FOSS vulnerability management, covering ingestion, approved usage, patching, ratings, and escalation procedures.
• Design and implement processes for the identification, triage, and remediation of FOSS vulnerabilities.
• Develop and sustain a FOSS cybersecurity incident response model for enterprise coordination, threat assessment, containment, and communication.
• Integrate governance controls with ingestion pipelines, scanning workflows, SBOM generation, and enterprise artifact management.
• Collaborate with legal, supply chain, platform owners, and cybersecurity governance to ensure alignment of policies with licensing, regulatory, and software supply chain requirements.
• Provide expert advice to programs and engineering teams regarding risk-based decision-making and adherence to FOSS governance.
• Guide teams on effective utilization of Software Bill of Materials (SBOM).
• Create technical documentation, governance models, workflows, diagrams, policy standards, and process guidance.
• Travel as required, estimated at 10–15%.
• Bachelor’s degree in Cybersecurity, Engineering, Computer Science, Software Engineering, or a related STEM field.
• At least 10 years of experience in cybersecurity engineering, governance, vulnerability management, secure software development, or supply chain security.
• Proven experience in developing or implementing enterprise security policies, standards, or risk-based decision frameworks.
• Expertise in software supply chain security, FOSS vulnerability analysis, threat triage, or incident response processes.
• Practical knowledge of SCA tooling, SBOM technologies, and enterprise monitoring of open-source components.
• Experience in collaborating with cross-disciplinary teams, including legal, supply chain, engineering, DT, and cyber governance.
• Strong technical writing abilities for creating policies, workflows, and governance documentation.
• Familiarity with DevSecOps practices.
• Experience with Agile development methodologies such as Scrum, Continuous Integration, Automated Testing, etc.
• U.S. citizenship is required.
• Ability to obtain and maintain a U.S. government security clearance.
• An active and existing DoD Secret security clearance is required from day one.
• An advanced degree in Cybersecurity, Engineering, Computer Science, Software Engineering, or a related field is preferred.
• Experience with enterprise artifact ecosystems like JFrog and Sonatype or large-scale CI/CD environments is preferred.
• Background in developing vulnerability scoring methodologies or enterprise-wide threat triage models is preferred.
• Experience with regulatory bodies, audit organizations, or software supply chain security frameworks such as NIST SSDF, SLSA, CMMC, and EO 14028 is preferred.
• Experience leading cybersecurity governance initiatives across multiple business units is preferred.
• Preferred: Residing within 50 miles of an RTX facility.
• Medical insurance.
• Dental insurance.
• Vision insurance.
• Life insurance.
• Short-term disability.
• Long-term disability.
• 401(k) matching.
• Flexible spending accounts.
• Flexible work schedules.
• Employee assistance program.
• Employee Scholar Program.
• Parental leave.
• Paid time off.
• Holidays.
• Annual short-term and/or long-term incentive compensation programs, where eligible.
Staffing For Doctors
Circle
Lincoln Financial
Affirm
Get handpicked remote jobs straight to your inbox weekly.