Jobs and Careers
BO

Senior Offensive Security Engineer

Boeing
United Statesfull_timeVerifiedPosted 12 Jun 2024
💰 $185,150/yr($136,850/yr$185,150/yr)

About the role

Senior Offensive Security Engineer

Company:

The Boeing Company

Job ID:

00000429113

Date Posted:

2024-06-12

Location:

USA - Berkeley, MO

Job Description Qualifications:

The Boeing Company seeks a Senior Offensive Security Engineer to support the Boeing Test & Evaluation (BT&E) cyber test capability. The selected applicant will join a highly technical Enterprise Test & Evaluation team building an offensive cyber test capability in Berkeley, MO.

This position will be providing testing services to Boeing Defense Space & Security (BDS) portfolio.  The primary responsibilities will include Product Security (Cyber) test planning, integration, and execution, mission-based risk assessments, vulnerability assessments, and penetration tests.  The Selected applicant will become a St. Louis team member trained across the broader BT&E enterprise Product Security Capability team with the opportunity to also contribute in innovation efforts advancing adversarial testing.

In addition to the specific program responsibilities, the selected candidates will be joining the growing BT&E Product Security Engineering Capability with established teams in Seattle, WA and Huntsville, AL.

Position Responsibilities Include:

  • Lead execution of penetration tests to identify, exploit, and assess a target system’s vulnerabilities in a threat-representative manner
  • Subject Matter Expert for emulating advanced cyber adversary tactics, techniques and procedures (TTPs)
  • Perform Operational Technology (OT) penetration testing and assessment as cyber Opposing Forces (OPFOR) for exercises simulating cyber threat actor capabilities
  • Lead controlled attack simulations that test the effectiveness of a blue team and its capabilities to detect, block, and mitigate attacks and breaches
  • Develop exploits and malware targeting modern operating systems and defenses
  • Conduct reverse engineering activities
  • Execute penetration tests on modern Windows and Linux operating systems and IP-based networks
  • Support the development of cyber test tools as necessary to achieve threat emulation objectives
  • Communicate recommendations for improvements via reports or presentations to customers using common frameworks such as MITRE ATT&CK, Cyber Kill Chain, etc.
  • Participate in event design and development for cyber training objectives

This position is hybrid.  This means that the selected candidate will be required to perform some work onsite at one of the listed location options.  This is at the hiring team’s discretion and could potentially change in the future.

This position requires an active Secret U.S. Security Clearance (U.S. Citizenship Required). (A U.S. Security Clearance that has been active in the past 24 months is considered active.)

Basic Qualifications (Required Skills/Experience):

  • Bachelor of Science degree from an accredited course of study in engineering, engineering technology (includes manufacturing engineering technology), chemistry, physics, mathematics, data science, or computer science    
  • 5+ years of experience planning and executing penetration testing of either IT based systems or Avionics embedded systems
  • Experience in system and software architectures
  • Experience programming with C, C++, Python and/or shell scripts

Preferred Qualifications (Desired Skills/Experience):

  • Experience leading teams on programs/projects
  • Demonstrated ability to engage with stakeholders to define/plan/resource/deliver solutions
  • Experience designing and/or testing product systems
  • Experience working with Product Security (non-IT) Cyber Compliance and/or Avionics Embedded systems risk management assessment
  • Experience facilitating and/or supporting Cyber Table Top (or equivalent) exercises
  • Experience planning and executing penetration tests in one or more of the following domains:
    • Windows and Linux Operating Systems and IP-Based Networks
    • Web Applications
    • Avionics, Embedded Systems, Non-Standard Ethernet Protocols (ARINC, MIL-STD)
    • RF interfaces
    • Hardware
  • Experience coordinating and presenting technical content to a diverse audience
  • Knowledgeable in Cryptography and Reverse Engineering
  • One or more of the following Certifications:
    • Offensive Security Certified Engineer (OSCE)
    • Offensive Security Certified Professional (OSCP)
    • GIAC Certified Exploit Researcher and Advanced Penetration Testers (GXPN)

Typical Education/Experience:

Education/experience typically acquired through advanced technical education from an accredited course of study in engineering, computer science

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Boeing

View company profile →