Associate Product Security Engineer

Boeing Boeing · Aerospace · Hazelwood, MO

Associate Product Security Engineer at Boeing, focusing on cybersecurity compliance and resiliency for training systems within defense programs. Requires experience with DoD Risk Management Framework (RMF), JSIG, and NISPOM, and involves security assessments, risk mitigation, and implementation of security controls throughout the product lifecycle. Requires an active US Secret Security Clearance and DoD 8570 Level II Certification.

What you'd actually do

  1. Support development, implementation, and sustainment of product security across the full lifecycle by developing and refining system requirements, architectures, and certification‑ready designs
  2. Coordinate with internal and external partners (systems, software, hardware, customers, suppliers, and industry) to define cybersecurity requirements, artifacts, activities, and solutions
  3. Conduct security assessments (threat analyses, risk assessments, audits), identify assets/vulnerabilities, risk documentation, and mitigation tracking through closure
  4. Advise stakeholders on assessment results and provide actionable recommendations to improve architecture, designs, and software assurance
  5. Establish, integrate, and implement product security standards, processes, and controls to meet program, certification, and regulatory requirements (e.g., JSIG, DoD RMF, NISPOM)

Skills

Required

  • Bachelor of Science degree in Engineering, Engineering Technology (including Manufacturing Technology), Computer Science, Data Science, Mathematics, Physics, Chemistry or non-US equivalent qualifications directly related to the work statement
  • Ability and willingness to travel domestically and internationally up to 15% of the time
  • 1+ years of experience working within the DoD Risk Managed Framework (RMF)
  • 1+ years of experience in development, integration, validation, and verification of cyber security systems
  • 1+ years of experience engineering/technical experience in aircraft, mission systems, or training solutions
  • 1+ years of experience in the field of Cybersecurity, anti-tamper and/or secure computing and knowledge of Department of Defense (DoD) policies and requirements related to Cybersecurity

Nice to have

  • Experience with vulnerability scanning, mitigation, administration and system hardening on multiple operating systems
  • Experience preparing and presenting technical material to diverse audiences (reports, engineering notes, presentations) with coaching from experienced team members.
  • Experience in systems/product security engineering for avionics, supporting integration of security into development by assisting senior engineers with requirements, secure architecture patterns, and system-level design activities
  • Experience performing adversity (threat) analysis, security risk assessments, and maturing the analysis throughout the development lifecycle – to inform requirements, and design
  • Experience assisting in identification of risks and opportunities, and collaborating with stakeholders to help define, plan, and deliver technical tasks or work packages.
  • Experience generating product cyber security artifacts for customer/certifiers
  • Experience in requirements analysis
  • Experience with military aircraft systems
  • Software experience: knowledge of higher order language programming languages (C/C++, Ada etc.), understanding of software life cycle, ability to read and understand code, and some understanding of secure code practices.
  • Experience with Program Protection, Software Assurance practices or Supply Chain Risk Management (SCRM) practices.

What the JD emphasized

  • active U.S. Secret Security Clearance
  • DoD 8570 Level II Certification
  • DoD Risk Managed Framework (RMF)
  • Cybersecurity