Product Security Analyst

Boeing Boeing · Aerospace · Hazelwood, MO

Product Security Analyst role at Boeing focusing on cybersecurity and resiliency engineering for embedded systems within defense products. Responsibilities include implementing security controls, coordinating with stakeholders, performing risk/vulnerability analyses, and ensuring compliance with government security standards like RMF, JSIG, and NISPOM.

What you'd actually do

  1. Support the development, implementation, and sustainment of product security for systems, throughout the requirements, design, analysis, build, test, production, operations, support and sustainment lifecycle for embedded avionics systems/subsystems
  2. Coordinate with partners and system-of-systems product security counterparts for requirements, activities, artifacts, and solutions
  3. Coordinate with other engineering stakeholders – systems, software, and hardware – advising on the results of security analysis – to develop secure architectures and designs
  4. Assist in establishing, integrating standards and processes for product security engineering in support of embedded avionics development, and meet applicable program/certification requirements
  5. Supports product security risk/attack surface/vulnerability analyses and security audits of applications and application stacks of various provenances embedded avionics systems

Skills

Required

  • Bachelor’s degree & typically 3 or more years of related work experience or equivalent combination of education and experience
  • Experience in documenting, identifying, scanning and testing for software vulnerabilities
  • Experience in writing and documenting reports on security findings and maintaining that documentation
  • 1+ years’ experience in ability to identify new opportunities and engage with stakeholders to define, plan, resource and deliver solutions
  • 1+ years’ experience in coordinating and presenting technical content to a diverse audience, as well as preparing technical documentation

Nice to have

  • Experience or education in cyber security incident response protocols (identification, impact assessment, containment, remediation, evidence handling, technical reporting, etc.) and safeguarding information
  • 1+ years’ experience in the development of avionics subsystems
  • 1+ years’ experience in assisting with the development of cybersecurity philosophies, patterns, requirements, secure architecture and designs
  • Experience supporting the design, development, and testing of engineering solutions, ensuring compliance with industry standards and regulations
  • Experience in product cyber security for avionics systems and component level assessments
  • Experience performing adversity (threat) analysis, security risk assessments, and maturing the analysis throughout the development lifecycle – to inform requirements, and design
  • Experience generating product cyber security artifacts for customer/certifiers
  • Security certification is desired (e.g. CISSP, Security+); please state/include on resume

What the JD emphasized

  • ability to obtain and maintain an active Secret U.S. Security Clearance
  • Security+ or CISSP to comply with contract requirements