Associate Product Security Engineer - Multi-program

Boeing Boeing · Aerospace · Hazelwood, MO

Boeing is seeking an Associate Product Security Engineer for their Training Systems Product Security Engineering team. The role involves providing technical support for product cybersecurity and resiliency engineering for multi-program/multi-platform training systems. Responsibilities include implementing security controls aligned with DoD Risk Management Framework (RMF), Joint Special Access Program (SAP) Implementation Guide (JSIG), and National Industrial Security Operating Manual (NISPOM). The position requires a relevant certification (DoD 8570 Level II) and experience with RMF and cybersecurity systems.

What you'd actually do

  1. Support development, implementation, and sustainment of product security across the full lifecycle by developing and refining system requirements, architectures, and certification‑ready designs
  2. Coordinate with internal and external partners (systems, software, hardware, customers, suppliers, and industry) to define cybersecurity requirements, artifacts, activities, and solutions
  3. Conduct security assessments (threat analyses, risk assessments, audits), identify assets/vulnerabilities, risk documentation, and mitigation tracking through closure
  4. Advise stakeholders on assessment results and provide actionable recommendations to improve architecture, designs, and software assurance
  5. Establish, integrate, and implement product security standards, processes, and controls to meet program, certification, and regulatory requirements (e.g., JSIG, DoD RMF, NISPOM)

Skills

Required

  • Bachelor of Science degree in Engineering, Engineering Technology (including Manufacturing Technology), Computer Science, Data Science, Mathematics, Physics, Chemistry or non-US equivalent qualifications directly related to the work statement
  • DoD 8570 Level II Certification e.g., CompTIA Security+, CySA+
  • Ability and willingness to travel domestically and internationally up to 15%
  • 1+ years of experience working within the DoD Risk Managed Framework (RMF)
  • 1+ years of experience in development, integration, validation, and verification of cyber security systems
  • 1+ years of experience engineering/technical experience in aircraft, mission systems, or training solutions
  • 1+ years of experience in the field of Cybersecurity, anti-tamper and/or secure computing and knowledge of Department of Defense (DoD) policies and requirements related to Cybersecurity

Nice to have

  • Experience with vulnerability scanning, mitigation, administration and system hardening on multiple operating systems
  • Experience preparing and presenting technical material to diverse audiences (reports, engineering notes, presentations) with coaching from experienced team members
  • Experience in systems/product security engineering for avionics, supporting integration of security into development by assisting senior engineers with requirements, secure architecture patterns, and system-level design activities
  • Experience performing adversity (threat) analysis, security risk assessments, and maturing the analysis throughout the development lifecycle – to inform requirements, and design
  • Experience assisting in identification of risks and opportunities, and collaborating with stakeholders to help define, plan, and deliver technical tasks or work packages.
  • Experience generating product cyber security artifacts for customer/certifiers
  • Experience in requirements analysis
  • Experience with military aircraft systems
  • Software experience: knowledge of higher order language programming languages (C/C++, Ada etc.), understanding of software life cycle, ability to read and understand code, and some understanding of secure code practices.
  • Experience with Program Protection, Software Assurance practices or Supply Chain Risk Management (SCRM) practices.

What the JD emphasized

  • DoD 8570 Level II Certification
  • DoD Risk Management Framework (RMF)
  • Joint Special Access Program (SAP) Implementation Guide (JSIG)
  • National Industrial Security Operating Manual (NISPOM)