Product Security Engineer

Boeing Boeing · Aerospace · Colorado Springs, CO

Product Security Engineer role at Boeing supporting Missile Defense Program (C2BMC). Responsibilities include developing and verifying installation instructions for cyber tools and patches, applying STIGs, managing CTOs, integrating and automating the Elastic Stack, working with cyber teams for vulnerability remediation, and performing risk assessments. Requires a Bachelor's degree, active Top Secret clearance, DoD 8570 certification, and experience with cybersecurity frameworks.

What you'd actually do

  1. Developing and verifying installation instructions for Cyber Tools and Vendor Patches
  2. Applying Security Technical Implementation Guides (STIGs)
  3. Managing and addressing any Cyber Tasking Orders (CTOs) related to the Cyber Tools
  4. Integrating, configuring and automating the installation of the Elastic Stack with the existing set of Cyber Tools on the C2BMC system
  5. Working with various C2BMC teams to ensure compatibility and seamless integration of Cyber Tools within the larger system

Skills

Required

  • Bachelor of Science degree from an accredited course of study in Engineering, Engineering Technology (includes Manufacturing Engineering Technology), Chemistry, Physics, Mathematics, Data Science, or Computer Science
  • Active Top Secret clearance
  • Current DoD 8570 certification at IAT Level II / IAM Level I or higher (e.g., Security+, GSEC, SCNP, SSCP, CISSP, CISA, GSE, SCNA)
  • 1+ years experience in product security / cybersecurity engineering
  • 1+ years experience with industry standard cybersecurity frameworks (NIST, OWASP, DFARS)
  • Experience using analytical, collaboration, communication and organizational skills

Nice to have

  • 2 years+ experience in Windows/RHEL System admin experience, installing, tuning & troubleshooting Cyber Tools to include ESS/HBSS, ConfigOS, Splunk/Elastic etc.
  • 2 years+ experience in configuring, running, and scripting audit tools
  • 2 years+ experience using knowledge of Software Assurance (SwA) static and/or dynamic code analysis (e.g. Fortify)
  • Experience with Federal Information Security Management Act (FISMA)/RMF and National institute of Standards and Technology (NIST) 800-53 require

What the JD emphasized

  • Active Top Secret U.S. Security Clearance
  • Current DoD 8570 certification at IAT Level II / IAM Level I or higher
  • 1+ years experience in product security / cybersecurity engineering
  • 1+ years experience with industry standard cybersecurity frameworks (NIST, OWASP, DFARS)