Experienced Product Security Engineer (virtual)

Boeing Boeing · Aerospace · United States · Remote

This role focuses on product security and resiliency throughout the product lifecycle, ensuring compliance with cyber-security and information assurance requirements, and advising customers on maintaining product security. It involves research and development of innovative security solutions and coordination with various stakeholders including government and suppliers.

What you'd actually do

  1. Develops, implements, and sustains product security and resiliency throughout the requirements, design, build, test, production, operations, and support lifecycle
  2. Develops and enhances system requirements and architectures for product security to meet all applicable certification and customer requirements
  3. Ensures security of facilities, equipment, tools, data, networks, and resources used for product: design, development, build, test, storage, delivery, operations, and support
  4. Defines and identifies product security requirements for suppliers of components and subsystems for integration into Boeing products and services
  5. Coordinates with governments, customers, suppliers, and industry to identify risks and improve industry and regulatory security standards and requirements for programs and interfacing systems

Skills

Required

  • Bachelor of Science degree from an accredited course of study in engineering, engineering technology (includes manufacturing engineering technology), chemistry, physics, mathematics, data science, or computer science
  • Ability to obtain a U.S. Security Clearance for which the U.S. Government requires U.S. Citizenship
  • 3+ years of experience in cyber-security, information assurance, or related field
  • Experience interpreting and applying NIST requirements
  • Certified Application Security Engineer (CASE), Security+, a CISSP certification, or equivalent Cyber Security certification (CISSP preferred)

Nice to have

  • 5+ years experience with industry standard cybersecurity frameworks (NIST, OWASP, DFARS)
  • 5+ years of experience with security and vulnerability scanning tools such as ACAS/Nessus, STIG's, and SCC
  • Experience identifying security vulnerabilities within source code
  • 5+ years of experience scanning source code with security tools Fortify and Coverity
  • Software engineering or Information Technology (IT) experience, including knowledge of Microsoft operating systems and client-server and web-based architectures, is desirable
  • Experience with the RMF or DIACAP process
  • Experience interpreting and applying NIST requirements
  • Experience with performing ACAS scans of systems and interpreting results
  • Experience with STIGs and SCAP tool
  • Experience with Vulnerator tool
  • Experience with DISA IAVMS and patching to the notices

What the JD emphasized

  • Ability to obtain a U.S. Security Clearance for which the U.S. Government requires U.S. Citizenship
  • Experience interpreting and applying NIST requirements
  • Certified Application Security Engineer (CASE), Security+, a CISSP certification, or equivalent Cyber Security certification (CISSP preferred)