RTX

Embedded Product Security System Engineer

RTX Cedar Rapids, Iowa, United States · $69K–$131K/yr

Aviation and Aerospace Component Manufacturing · 10,001+ employees

Yesterday
Mid (2-5 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The engineer will develop threat models and implement mandatory access controls to secure mission-critical embedded systems. They will also conduct vulnerability assessments, perform penetration testing, and manage cybersecurity certification artifacts.

What they look for

Embedded systems security Linux OS C C++ Python Rust Networking protocols Threat modeling Data flow diagrams SELinux Fuzzing Penetration testing Vulnerability assessment SSDLC Cybersecurity certification

Requirements

Candidates must have a STEM bachelor's degree with 2 years of experience or equivalent, along with proficiency in Linux and C/C++/Python/Rust. U.S. citizenship is strictly required for this role due to program access requirements.

Benefits

Medical Dental Vision Life insurance Short-term disability Long-term disability 401(k) match Flexible spending accounts Flexible work schedules Employee assistance program Employee scholar program Parental leave Paid time off Holidays

Full description

Date Posted:

2026-09-02

Country:

United States of America

Location:

US-IA-CEDAR RAPIDS-121 ~ 350 Collins Rd NE ~ BLDG 121

Position Role Type:

Onsite

U.S. Citizen, U.S. Person, or Immigration Status Requirements:

U.S. citizenship is required, as only U.S. citizens are authorized to access information under this program/contract.

Security Clearance Type:

None/Not Required

Security Clearance Status:

Not Required

At RTX, the world's largest aerospace and defense company, 185,000 great minds are united by purpose and inspired to make a difference solving the world’s most complex problems. With our three market leading businesses, world-class operations and investments in research and development, we offer capabilities and opportunity no one else can. Together, we push the boundaries of known science and find new ways to connect and protect our world.

Collins Aerospace is a leader in technologically advanced, intelligent solutions that help redefine the aerospace and defense industry. With a comprehensive portfolio and deep technical expertise, we help customers meet the demands of the global market. Join us and help shape the future of aerospace and defense.

Complex systems require world-class protection. We are seeking a driven System Security Engineer to join our Embedded Product Cybersecurity Engineering team and defend mission-critical platforms from evolving cyber threats. This shared services team supports the development of products throughout the company wherever the customer has security requirements, or the system is exposed to cyber threats by its connectivity or operational use. We develop tools and testing techniques to highlight residual defects in product design or implementation. These defects can lead to vulnerabilities that negatively impact the confidentiality, integrity, or availability of a system. Members of the security engineering team pursue security excellence by embedding with the design and implementation teams as subject matter experts supporting our Secure System Development Life Cycle (SSDLC).   

This is an on-site position located in Cedar Rapids, Iowa, an established hub for aerospace and systems engineering excellence.   

Primary Responsibilities:  

Developing threat model / data flow diagrams to ensure data can be properly isolated in motion and at rest   Implementing mandatory access controls (MAC) through the development of SELinux policies    Reviewing code to identify weaknesses in the implementation of security functions    Developing and executing fuzzing and penetration tests to evaluate the robustness of the attack surface    Conducting vulnerability assessments of proposed and in-service systems    Authoring and managing cybersecurity certification artifacts to ensure alignment with industry standards and customer requirements    Basic Qualifications:  

Bachelor’s degree in a STEM field and 2 years of relevant experience OR Advanced degree in Cybersecurity OR In absence of a degree, 6 years of relevant experience is required   Embedded software development experience in Linux OS environment    Experience coding in C, C++, Python or Rust    Networking experience - Layer 2/Layer 3/Layer 4 protocols   Candidates for this position should be fluent in the software development domain and have a passion for Product Security, and understand the difference between enterprise cybersecurity and securing embedded systems with physical, real-world impacts    Preferred Qualifications:  

Familiarity with Aviation cybersecurity standards: RTCA DO-326, DO-356, DO-355   Knowledge of Threat Models and Data Flow Diagrams   Data/network security implementations with Linux OS   Understanding tailoring and hardening of Linux OS   Familiarity with system and application penetration testing   Experience with SAST and analyzing security impact of code defects   Executing System & Application Fuzzing / Resiliency Tests   Knowledge of Public Key Infrastructure (PKI)   Industry recognized security certifications (Sec+, OSCP, CISSP, etc.) is desirable    

The candidate is required to have excellent communications skills to communicate technical issues and status in both written and oral form. The candidate must be adaptable to change, determined to accomplish tasks based on program schedule, collaborate with teammates in order to learn and make good decisions, enjoy learning new technologies, and contribute to a positive work environment.

Please ensure the role type defined below is appropriate for your needs before applying to this role. This position is classified as:

Onsite: Employees who are working in Onsite roles will work primarily onsite. This includes all production and maintenance employees, as they are essential to the development of our products.

Hybrid: Employees who are working in Hybrid roles will work regularly both onsite and offsite. Ratio of time working onsite will be determined in partnership with your leader.

Remote: Employees who are working in Remote roles will work primarily offsite (from home). If you live within a reasonable commute of an RTX site with other colleagues you interact with, your manager will discuss whether there is a degree of onsite presence associated with this role.

Candidates will learn more about role type and current site status throughout the recruiting process. For onsite and hybrid roles, commuting to and from the assigned site is the employee’s personal responsibility.

Requires theoretical to advanced knowledge of work area typically obtained through University Degree combined with experience. Practical knowledge of RTX projects, programs or systems with the ability to make enhancements and leverage in daily work.

Typically requires a University Degree or equivalent experience and minimum 2 years of prior relevant experience.

Engineering/Other Technical Positions:Typically requires a degree in Science, Technology, Engineering or Mathematics(STEM) and a minimum of 2 years of prior relevant experience unless prohibited by local laws/regulations.

As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote.

The salary range for this role is 68,900 USD - 131,100 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate’s work experience, location, education/training, and key skills.

Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement.

Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company’s performance.

This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply.

RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window.

RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans’ Readjustment Assistance Act.

Privacy Policy and Terms:

Click on this link to read the Policy and Terms