Senior Vulnerability Assessments Specialist - Operational Technology (OT)
BoeingAbout the role
Company:
The Boeing CompanyThe Boeing Company is currently seeking a Senior Vulnerability Assessments Specialist - Operational Technology (OT) to join the team in Kent, WA; North Charleston, SC; Hazelwood, MO; Mesa, AZ; El Segundo, CA; or Plano, TX.
This role will assess and drive remediation of vulnerabilities that impact OT environments across manufacturing, production, and mission-critical infrastructure.
The ideal candidate brings deep vulnerability lifecycle experience, demonstrated OT/ Industrial Control System (ICS) knowledge, and the ability to translate technical findings into pragmatic remediation and risk-mitigation plans for operational stakeholders.
Position Responsibilities:
Develop and execute vulnerability management processes for OT/ICS environments, including networked controllers, Human-Machine Interfaces (HMIs), Programmable Logic Controllers (PLCs), Supervisory Control and Data Acquisition (SCADA) systems, and supporting enterprise infrastructure
Execute enterprise processes for emergent vulnerabilities
Evaluate risk and recommend prioritized mitigation or remediation actions
Perform detailed exploitability and impact analysis that factors threat context, asset criticality, environmental constraints, and existing controls
Drive remediation and risk reduction efforts end-to-end: develop mitigation plans, coordinate with engineering/operations teams, track remediation progress, and report burndown to stakeholders
Collaborate with cross-functional security, Information Technology (IT), engineering, and operations teams to operationalize new capabilities and harden OT systems
Produce clear, actionable technical reports and stakeholder narratives tailored to technical teams, line-of-business owners, and senior leadership
Maintain and improve assessment methodologies, playbooks, and automation to raise first-time quality and repeatability
Mentor junior team members, review technical analyses, and contribute to continuous improvement of vulnerability management processes
Basic Qualifications (Required Skills/Experience):
5+ years of experience with leading Incident Response and/or Vulnerability Management activities
3+ years of experience in penetrating testing and vulnerability assessments using manual techniques and vulnerability testing tools (including scanners, sniffers, fuzzers and exploit tools such as Burp, Nmap, Kali and Metasploit)
3+ years of experience with vulnerability scanning tools and formats (e.g., Nessus, Qualys, Tenable, Rapid7, Snyk, Veracode, or Burp)
3+ years of experience in performing system administration tasks on Windows and Linux hosts including installing security patches and making configuration changes to support security requirements
Experience with analytical skills in data, with ability to identify gaps in roll out of tools, processes and application of skills in tools within the areas of vulnerability management and endpoint controls
Working knowledge of vulnerability and risk management frameworks, ratings, and contextualizing data based on risk (e.g., CVSS, CVE, NVD, etc)
Preferred Qualifications (Desired Skills/Experience):
Bachelor’s degree or higher
Active certifications including Global Industrial Cyber Security Professional (GICSP), Global Information Assurance Certification (GIAC) GICSP/Generic Routing Encapsulation (GRE)/GIAC Continuous Monitoring Certification (GMON), Certified Information Systems Security Professional (CISSP), Certified Red Team Professional (CRTP), or equivalent OT/ICS security credentials
Experience evaluating exploitability and recommending mitigations that are operationally feasible in production OT environments
Experience with strong written and verbal communication skills with the ability to convey technical risk to non-technical stakeholders and drive cross-functional decisions
Experience being self-directed, adaptable to ambiguity, comfortable working under pressure, and able to operate with minimal guidance when needed
Experience speaking up, contributing to cross-functional discussions, and collaborating effectively to reach resolution
Experience with OT/ICS domain knowledge (Programmable Logic Controller (PLC)/ Remote Terminal Unit (RTU)/HMI architectures, common vendors/protocols such as Modbus, DNP3, OPC, BACnet)
Experience with industrial network segmentation, OT-safe scanning, and safe test
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s