Product Security Engineer, Mid-level

Boeing Boeing · Aerospace · Hazelwood, MO

Product Security Engineer at Boeing, focusing on cybersecurity and resiliency for embedded avionics systems throughout their lifecycle. Responsibilities include supporting security controls, requirements development, risk analysis, and coordination with various engineering stakeholders. Requires experience with RMF, JSIG, NISPOM, and knowledge of cyber incident response.

What you'd actually do

  1. Support the development, implementation, and sustainment of product security requirements for Air Dominance & Phantom Works avionics systems/sub-systems, throughout the requirements, design, analysis, build, test, production, operations, support and sustainment lifecycle.
  2. Coordinate with partners and system-of-systems product security counterparts for requirements, activities, artifacts, and solutions.
  3. Coordinate with other engineering stakeholders – systems, software, and hardware – advising on the results of security analysis – to develop secure architectures and designs.
  4. Assist in establishing, and integrating standards and processes for product security engineering for embedded avionics development, and meet applicable program/certification requirements.
  5. Utilize the Risk Engineering digital thread to inform product requirements surrounding cyber survivability against specified cyber threats – by performing criticality, adversity, threat analysis for avionics systems.

Skills

Required

  • development of avionics computer systems
  • identify risk, new opportunities and engage with stakeholders to define, plan, resource and deliver solutions
  • development of cybersecurity philosophies, patterns, requirements, secure architectures and designs
  • coordinating and presenting technical content to a diverse audience, as well as preparing technical documentation
  • Knowledge of cyber security incident response protocols

Nice to have

  • Master's or higher degree in engineering (e.g., aerospace, mechanical) or material science
  • product cyber security for avionics systems and component level development
  • performing adversity (threat) analysis, security risk assessments, and maturing the analysis throughout the development lifecycle
  • generating product cyber security artifacts for customer/certifiers
  • Security certification is desired (e.g. CISSP)

What the JD emphasized

  • active Secret U.S. Security Clearance
  • Security+ or CISSP
  • DoW Risk Management Framework (RMF)
  • Joint Special Access Program (SAF) Implementation Guide (JSIG)
  • National Industrial Security Operating Manual (NISPOM)