Incident Handler
RTX (Raytheon)
- Location
- US-CT-FARMINGTON-0004 ~ 4 Farm Springs Rd ~ 4 FARM SPRINGS
- Work model
- On-Site
- Level
- Mid
- Posted
- Sep 3, 2026
Skills
About this role
Location: US-CT-FARMINGTON-0004 ~ 4 Farm Springs Rd ~ 4 FARM SPRINGS

 Position Role Type: Onsite

 U.S. Citizen, U.S. Person, or Immigration Status Requirements: U.S. citizenship is required, as only U.S. citizens are authorized to access information under this program/contract.

 Security Clearance Type: None/Not Required

 Security Clearance Status: Not Required RTX Corporation is an Aerospace and Defense company that provides advanced systems and services for commercial, military and government customers worldwide. It comprises three industry-leading businesses – Collins Aerospace Systems, Pratt & Whitney, and Raytheon. Its 185,000 employees enable the company to operate at the edge of known science as they imagine and deliver solutions that push the boundaries in quantum physics, electric propulsion, directed energy, hypersonics, avionics and cybersecurity. The company, formed in 2020 through the combination of Raytheon Company and the United Technologies Corporation aerospace businesses, is headquartered in Arlington, VA.
Role
Overview: Enterprise Services (ES) Cybersecurity has an immediate opening for a qualified technical analyst to join RTX Cyber Defense reporting to the Sr. Manager, Security Operations Center. As an Incident Handler of Security Operations Center, you will be responsible for leading our organization's cyber defense capabilities to minimize impact to RTX operations from cyber adverse events and incidents. You will collaborate with multiple stakeholders, including Incident Command, HR, Legal, Ethics, Privacy, Security Operations, Cyber Insider Threat, and Global Security to create a comprehensive strategy for mitigating cyber threats while maintaining a culture of trust and transparency.
What You Will Do
The ideal candidate shall perform specific activities that include, but are not limited to the following: Monitor, identify, investigate and escalate security events using enterprise security tools and automation platforms. Conduct hands‑on technical investigation and analysis during cyber incidents under the guidance of Senior Incident Responders and Incident Commanders. Lead analysis, containment and remediation activities by following established playbooks and procedures Provide technical enrichment and contextual data to support incident investigations. Collaborate with cross‑functional partners during incident handling and follow standard communication channels, including Incident Command, Legal, HR, Ethics, Privacy, Security Operations, Cyber Insider Threat, and Global Security. Contribute to improving detection content, playbooks, and operational workflows through feedback and testing. Create and maintain detailed records of investigations, produce reports, and communicate findings to senior management and relevant stakeholders. Support continuous enhancements to Cyber Defense processes and perform additional duties as assigned.
Qualifications
You Must Have : Typically requires a University Degree or equivalent experience and a minimum 5 years of experience, or an Advanced Degree and a minimum 3 years experience. Minimum 5 years of experience in technical Cyber Defense operational roles, including Incident Response, SOC, and / or Forensics.
Qualifications
We Prefer: Hands‑on experience with EDR/XDR tools, SIEM technologies, and common security platforms. Working knowledge of digital forensics concepts, insider threat indicators, and TTPs. CompTIA CySA+, Cloud certifications, CEH, GIAC certifications such as GSEC, GCIH or similar are a plus.. Excellent written and verbal communication skills; must be able to effectively communicate technical details to peers and all levels of executive leadership with varying levels of technical expertise. Operating knowledge of MITRE ATT&CK (or other industry frameworks), incident handling methodologies, and AI\automation concepts