Product Security Analyst (mid-level or Senior)

Boeing Boeing · Aerospace · Richardson, TX

This role focuses on product cybersecurity analysis and engineering within the defense sector, ensuring systems meet security requirements, performing vulnerability assessments, and providing technical guidance on security implementations. It involves analyzing customer and regulatory requirements, designing security countermeasures, and managing security systems across networks. The role requires experience with information assurance, security scanning tools, and incident response, with a strong emphasis on compliance and security frameworks within a DevSecOps environment.

What you'd actually do

  1. Analyze customer and regulatory information system security requirements and decompose them into system security design specifications.
  2. Interface directly with the customers and engineers to ensure that security requirements are designed into the products and evaluated for effectiveness.
  3. Perform as the key system security focal throughout the DevSecOps framework.
  4. Develop IT architecture deliverables, specific to information security countermeasure implementations, for operational systems and systems under development.
  5. Provide technical cyber security guidance to IT Administrators, Systems Architect, Systems Engineers, and Software Developers.

Skills

Required

  • Bachelor’s degree or higher in a technical field
  • 5+ years’ software testing and software verification
  • Active CompTIA Security+ certified (or similar certification meeting DoD Directive 8570.01 Certification Requirements)
  • 1+ years’ experience working with Information Assurance Policy & RMF
  • 1+ years’ experience with security and vulnerability scanning tools such as ACAS/Nessus, STIG's, and SCC
  • 1+ years’ experience working in complex test planning, development, and execution

Nice to have

  • DoD 8570.01-M IAT Level III Certification (e.g., CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP); and IASAE Level II (e.g., CASP+ CE, CISSP (or Associate), CSSLP)
  • Experience acting as a Test Engineer or Software Assurance Engineer.
  • Experience with software development tools, such as, DOORS, ClearCase, GitLab, Jira, Coverity, etc.
  • Experience with developing Threat Modeling, Attack Profiles, Threat and Risk Assessments on aircraft platforms and weapon systems.
  • Experience with evaluating and refining customer security requirements.
  • Experience capturing/documenting system security designs throughout the System Development Lifecycle (SDLC) process (e.g., System Diagrams, System Security Plans, Hardware Baselines, Software Baselines, Network Diagrams, Security Controls Traceability Matrices, Standard Operating Procedures, etc.)
  • Ability to work independently, actively participate on integrated teams, and lead a task, project, or small team.
  • Experience working in a customer facing role executing Information System Security Vulnerability Assessments, to include conducting customer out briefs and generating reports.
  • Experience working with multiple technologies such as RHEL 8 and above, and/or CISCO IOS/NXOS, and/or Windows server 2019 and above, and/or Windows 10 or newer.
  • Experience with multiple scripting languages (e.g., PowerShell, Python, Bash, Ansible, etc.)
  • Experience creating system security implementation solutions against customer requirements.
  • Experience with installation and configuration of Splunk Enterprise; to include creation of Apps and Dashboards to audit analysis specifications.
  • Experience in Group Policy Management and implementation.
  • Experience with Agile development within a DevSecOps environment.

What the JD emphasized

  • active U.S. Top Secret Security Clearance
  • obtain and retain Special Access Program (SAP) approval
  • Active CompTIA Security+ certified (or similar certification meeting DoD Directive 8570.01 Certification Requirements)