Jobs and Careers
BO

Product Security Pentester (Experienced or Senior)

Boeing
United Statesfull_timeVerifiedPosted 24 Jun 2024
💰 $166,750/yr($101,150/yr$166,750/yr)

About the role

Product Security Pentester (Experienced or Senior)

Company:

The Boeing Company

Job ID:

00000428267

Date Posted:

2024-06-24

Location:

USA - Berkeley, MO

Job Description Qualifications:

The Boeing Test & Evaluation (BT&E) organization is seeking a Product Security Pentester to support cyber test capability. The selected applicant will join a highly technical Enterprise Test & Evaluation team building an offensive cyber test capability in Berkeley, MO.

This position will be providing testing services to Boeing Defense Space & Security (BDS) portfolio.  The primary responsibilities will include Product Security (Cyber) test planning, integration, and execution, mission-based risk assessments, vulnerability assessments, and penetration tests.  The selected candidate will become a St. Louis area team member trained across the broader BT&E enterprise Product Security Capability team with the opportunity to also contribute to innovation efforts advancing adversarial testing.

BT&E is currently hiring for a broad range of experience levels including Experienced and Senior level Product Security Pentesters.

Position Responsibilities Include:

  • Lead execution of penetration tests to identify, exploit, and assess a target system’s vulnerabilities in a threat-representative manner
  • Subject Matter Expert in analyzing advanced cyber adversary (advanced persistent threats) tactics, techniques and procedures (TTPs).  Associate TTPs with vulnerabilities/penetrations discovered
  • Lead controlled attack simulations that test the effectiveness of a blue team and its capabilities to detect, block, and mitigate attacks and breaches
  • Analyze exploits and malware targeting modern operating systems and defenses
  • Conduct reverse engineering activities
  • Analyze penetration tests on modern Windows and Linux operating systems and IP-based networks
  • Communicate recommendations for improvements via reports or presentations to customers using common frameworks such as MITRE ATT&CK, Cyber Kill Chain, etc.

This position is hybrid.  This means that the selected candidate will be required to perform some work onsite at one of the listed location options.  This is at the hiring team’s discretion and could potentially change in the future.

This position requires an active Secret U.S. Security Clearance (U.S. Citizenship Required). (A U.S. Security Clearance that has been active in the past 24 months is considered active.)

Basic Qualifications (Required Skills/Experience):

  • Bachelor’s  degree or higher
  • 3+ years of experience leading or managing projects and/or teams
  • 3+ years of experience working with Department of Defense (DoD) organizations, projects and/or programs
  • 3+ years of experience planning and executing penetration testing of either IT based systems or Avionics embedded systems

Preferred Qualifications (Desired Skills/Experience):

  • 5 or more years of related work experience or an equivalent combination of education and experience
  • Demonstrated ability to engage with stakeholders to define/plan/resource/analyze solutions
  • Experience testing and/or analyzing product systems
  • Experience building and/or leading a technical test team
  • Experience working with Product Security (non-IT) Cyber Compliance and/or Avionics Embedded systems risk management assessment
  • Experience facilitating and/or supporting Cyber Table Top (or equivalent) exercises
  • Experience planning and executing penetration tests in one or more of the following domains:
    • Windows and Linux Operating Systems and IP-Based Networks
    • Web Applications
    • Avionics, Embedded Systems, Non-Standard Ethernet Protocols (ARINC, MIL-STD)
    • RF interfaces
    • Hardware
  • Experience coordinating and presenting technical content to a diverse audience
  • Experience with program planning (cost and schedule)
  • Experience with Aircraft Platforms, Weapon Systems and/or C5ISR
  • Knowledgeable in Cryptography and Reverse Engineering
  • One or more of the following Certifications:
    • Offensive Security Certified Engineer (OSCE)
    • Offensive Security Certified Professional (OSCP)
    • GIAC Certified Exploit Researcher and Advanced Penetration Testers (GXPN)

Typical Education/Experience:

Experienced (Level 3)

Education/experience typically acquired through advanced education (e.g. Bachelor) and typically 6 or more years' related work experie

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Boeing

View company profile →