Jobs Companies RTX Principal Specialist, Cyber security & Risk Management (m/f/d)

Über diese Principal Specialist, Cyber security & Risk Management (m/f/d) Stelle bei RTX

RTX · Hybrid · DE-BW-HEIDELBERG-036-751 ~ Grenzhofer Weg 36 ~ BLDG 751

Date Posted:

2026-09-04

Country:

Germany

Location:

DE-BW-HEIDELBERG-036-751 ~ Grenzhofer Weg 36 ~ BLDG 751

Position Role Type:

Unspecified

At Collins Aerospace, we work side-by-side with our customers to tackle the toughest challenges in aerospace and defense. We’re combining boundless imagination with a broad portfolio and an unmatched dedication to customers – all to make the skies and spaces we touch smarter, safer and more amazing than ever.

Our site in Heidelberg has the following core competencies:

• Avionics Systems

• On-board electronics for land vehicles

• Products for the aerospace industry

Role Overview - Information System Security Officer – ISSO

We are seeking a highly experienced and strategic Information System Security Officer to lead our cyber and regulatory compliance programs across RTX business units for sites located in Germany.  The primary work location is Heidelberg. This role is critical for ensuring the cyber posture of the sites and for establishing the guidelines and actions needed to protect the company's Information Systems against cyber threats, responds to digital compliance risks, and fosters a company-wide culture of cybersecurity.

The successful candidate will provide technical leadership, oversee multi-site governance and risk management, and ensure alignment between RTX ES Cybersecurity services (including IT and OT) with Business functions to safeguard critical assets, applications, systems, and data.

The candidature is expected to follow a hybrid work model, balancing remote and on-site presence based on business needs, key meetings, critical milestones, team collaboration needs, audits or incident response requirements.

What will you do

Governance:

  • Ensure the management and local cyber governance of the Information Systems within the sites under ISSO scope.
  • Ensure adherence to global and regional/local regulatory requirements and applicable frameworks (ISO 27001, 27005, NIST SP800-171 etc.).
  • Maintain the Information Security Management System (ISMS) or equivalent governance model.
  • Define, implement, coordinate, manage and monitor activities related to the Part-IS regulation (acting as Aviation Safety ISMS Manager).
  • Drive internal and external audits, certifications, and compliance readiness across multiple sites.
  • Continuous monitoring of emerging regulations and standards, ensuring proactive & compliance and risk management.
  • Ensure relationship and interface with cyber stakeholders in relation with site ecosystem including security authorities, customers & partners.
  • Define, derive and maintain security policies, procedures and guidance for Restricted and Classified IS located on site (if any) and ensure their implementation with the support of DT team.
  • Ensure accreditation activities on Restricted and Classified networks (when applicable).
  • Develop and execute an annual security awareness plan to reduce business compliance risks, cyber operational risks and to foster a cyber culture within the sites.

Cyber Risk Management:

  • Manage cyber risks (identification, evaluation and treatment) according to applicable enterprise-wide cyber risk program and regulations including but not limited to Part-IS and NIS2. As part of the risk management, the ISSO will perform/lead risk assessment for the sites and associated risk treatment plans with the support of DT Int’l Operations and RTX Global GRC teams.
  • Oversee implementation of security controls (technical, administrative, physical) for applications, infrastructure, Cloud, and OT systems under ISSO scope.
  • Ensure secure enablement of new technologies and digital transformation programs.

Compliance:

  • Ensure compliance with applicable security requirements for the sites (internal policies, applicable regulations and customer frameworks).
  • Ensure compliance with applicable security requirements for the third parties engaged with the sites (internal policies, applicable regulations and customer frameworks). Drive supplier cyber risks identification and treatment for the sites.
  • Support enterprise-wide compliance program (e.g., DT Assessment, Part-IS internal audit) and external audit/assessment from customers and regulators (e.g. CASE audit).

Security event and incident management:

  • Ensure that threat detection capabilities provided by RTX Cyber-Defense team are fully implemented.
  • Monitor, Detect and Respond to cyber threats exposing Restricted and Classified networks (when applicable).
  • Support the RTX Cyber-Defense Operations for any event or incident occurring on the sites. Drive incident response preparedness and act as point of contact for security incidents.

Operations:

  • Provide expert security guidance to DT Int’l Operations (e.g., vulnerability management, remediation plan execution, support on new cyber programs).
  • Support special cyber programs such as SURGE and drive critical vulnerabilities remediation in support to DT Int'l operations and CART team.
  • Champion business resilience by aligning DT and OT security strategies with business continuity and disaster recovery plans.
  • Provide support to the DT team on activities related to business continuity/recovery (BIA, DRP etc.).

Technical Leadership:

  • Act as the point of contact for various compliance programs (e.g., EASA Part-IS, NIS2, DFARS CMMC Global etc.) where applicable.
  • Provide expert security guidance to Engineering, Operations, and Value-Stream Leaders teams. Especially, the ISSO will provide support to business programs and pursuits.
  • Collaborate with local stakeholders (e.g., Engineering, Operations, Safety, Quality) to ensure seamless integration of information security requirements.
  • Represent Information Security with external regulators, customers, and partners.
  • Monitor regulatory, threat landscape and technology evolution in cybersecurity.
  • Mentor and develop junior security professionals, promoting a cybersecurity culture.

Qualifications you must have

  • Master’s degree in Computer Science, Information Security, Engineering, or related field with 8+ years of experience in cybersecurity.
  • Knowledge or experience in the following domains (at least 5): Risk Management, Security Architecture & Engineering, Asset Security, Communication & Network security, Security Assessment and Testing, IAM, Security Operations.
  • Strong working knowledge of security frameworks: ISO 27001, 27005, NIST (CSF, SP800-171, SP800-82) etc.
  • Experience leading multi-site/global compliance programs.
  • Excellent knowledge of risk management methodologies and audit practices.
  • Strong communication and stakeholder management skills at C level.
  • Relevant certifications (one or more): CISSP, CISM, CRISC, ISO 27001 Lead Implementer/Auditor, ISO 27005 Risk Manager, OSCP, CEH, GIAC etc.

Qualifications we prefer

  • Experience in regulated industries (e.g., aerospace, defence, manufacturing, or critical infrastructure).
  • Knowledge on EASA Part-IS, NIS2, national MoD security regulations.
  • Experience working with/for regulators/authorities or customers (e.g., Aerospace & Defense OEMs).
  • Experience and expertise in the following security fields: threat monitoring & detection, security incidents mgt, penetration testing and/or technical audit, software development security (threat modeling, secure coding).
  • Familiarity with Industrial Control Systems (ICS) / OT cybersecurity.
  • Background in safety-critical or regulated environments.

Soft skills :

  • Demonstrate ownership and accountability for assigned projects/programs.
  • Curious, passionate.
  • Ability to withstand pressure.
  • Ability to work across the organization.
  • Ability to influence.
  • Ability to report back to management.
  • Team management.
  • Sense of general interest, committed.

Nationality/Clearance: this job may require having national security clearance. Must be eligible to obtain a higher security clearance.

Be part of the Collins Heidelberg Team:

  • Join our international team
  • Flexible working times
  • 30 days of vacation
  • Industry-specific pay
  • Company sponsored pension plan
  • Corporate health management
  • Internal and external training opportunities to promote the continuous learning and development of our employees
  • Global career opportunities at over 300 sites worldwide

RTX adheres to the principles of equal employment. All qualified applications will be given careful consideration without regard to ethnicity, color, religion, gender, sexual orientation or identity, national origin, age, disability, protected veteran status or any other characteristic protected by law.  

Privacy Policy and Terms:

Click on this link to read the Policy and Terms

Bereit, sich bei RTX zu bewerben?
Bei RTX bewerben

Über RTX

RTX is an aerospace and defense company that provides advanced systems and services for commercial, military and government customers worldwide. It comprises three industry-leading businesses – Collins Aerospace, Pratt & Whitney, and Raytheon. Its 195,000 employees enable the company to operate at the edge of known science as they imagine and deliver solutions that push the boundaries in quantum physics, electric propulsion, directed energy, hypersonics, avionics and cybersecurity. The company, formed in 2020 through the combination of Raytheon Company and the United Technologies Corporation aerospace businesses, is headquartered in Arlington, Virginia.

Alle Jobs bei RTX ansehen →

Ähnliche Jobs

RTX
Chief Inspector (Onsite)
RTX
⚡ Früh bewerben US-WV-BRIDGEPORT-1527 ~ 1527 M... Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
RTX
QEC Mechanic (Onsite)
RTX
⚡ Früh bewerben US-GA-MIDLAND-MPC ~ 8801/8987... Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
RTX
Air & Space Defense Systems Senior Flight Test Lead
RTX
⚡ Früh bewerben US-AZ-TUCSON-848 ~ 1151 E Herm... Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
RTX
Additive Manufacturing Operations Manager
RTX
⚡ Früh bewerben US-CT-EAST HARTFORD-RTRC H ~ 4... Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
RTX
Senior Electrical Engineer - Hardware (Onsite)
RTX
⚡ Früh bewerben US-IA-CEDAR RAPIDS-137 ~ 855 3... Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
RTX
Spécialiste en automatisation manufacturière / Manufacturing Automation Specialist
RTX
⚡ Früh bewerben CA-QC-LONGUEUIL-J01 ~ 1000 Blv... Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
RTX
Intern Systems Engineer- (Onsite)
RTX
⚡ Früh bewerben US-CO-SCHRIEVER-AFB-CUST ~ 720... Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
RTX
Electrical Firmware (Winter/Spring Co-op)(Onsite)
RTX
⚡ Früh bewerben US-IA-CEDAR RAPIDS-193 ~ 1120... Hybrid
● Neu 👁 Gesehen ✓ Beworben vor 13 Std.
RTX
Senior Lead Engineer
RTX
⚡ Früh bewerben IN-KA-BENGALURU-NORTHGATE ~ Sy... Vor Ort
● Neu 👁 Gesehen ✓ Beworben vor 21 Std.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei RTX

Alle Jobs bei RTX ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos