Product Security Analyst
BoeingAbout the role
Company:
The Boeing CompanyBoeing Defense Space & Security (BDS) is seeking an associate, experienced or senior Product Security Analyst to support the P-8A program in Richardson, TX. The candidate will join a team supporting product cybersecurity efforts across multiple systems and labs for both training and development efforts. The BDS Product Security Engineering team is responsible for the cybersecurity and resiliency of Boeing products and services, bridging the gap between high level security policies/requirements and technical/operational implementation of those requirements. The work is multi-disciplinary and includes activities in cyber and systems security analysis, engineering, test, and vulnerability assessments and mitigation.
At Boeing, we innovate and collaborate to make the world a better place. By joining our team, you will become an integral part of an organization that deeply values teamwork, fosters creativity, and upholds the highest standards of engineering technical excellence to ensure our products are secure. Contribute to work that matters with a company where diversity, equity and inclusion are shared values. Find your future with us!
Position Responsibilities:
Analyze customer and regulatory information system security requirements and decompose them into system security design specifications.
Interface directly with the customers and lead engineers to ensure that security requirements are designed into the products and evaluated for effectiveness.
Perform as the key system security focal throughout the DevSecOps framework.
Develop IT architecture deliverables, specific to information security countermeasure implementations, for operational systems and systems under development.
Provide technical cyber security engineering guidance to IT Administrators, Systems Architect, Systems Engineers, and Software Developers.
Provide system security engineering guidance on the design and implementation of technical policies for user/computer groups and network devices.
Responsible for the design and implementation of security systems across the entire organization's networks, including IDS, firewalls, log capture, host-based protections, vulnerability scanning tools, and more.
Conduct assessments of existing IT architecture for compliance with security requirements from applicable security frameworks.
Analyzes, triages, aggregates, escalates, and reports relevant product security and anti-tamper data and other information sources for attack indicators and potential security breaches.
Provide ISSO and IT administrators with system security level expertise to assist with the gathering/securing of data to support incident investigation and response.
Assist ISSO in monitoring, interpreting, and reacting to security device outputs, create documentation in support of authorization/accreditation packages, and deploy security policies, standards, and guidance.
This position is expected to be 100% onsite. The selected candidate will be required to work onsite at one of the listed location options.
This position requires an active U.S. Top Secret Security Clearance (US Citizenship Required). (A U.S. Security Clearance that has been active in the past 24 months is considered active.)
Basic Qualifications (Required Skills & Experience): (see required education and experience for the levels below)
CompTIA Security+ Certification
1 or more years experience with the implementation of security controls IAW DoD Risk Management Framework (RMF).
1 or more years experience with common DoD vulnerability and compliance assessment tools (e.g., SCAP, STIGs, ACAS) and processes.
1 or more years experience in security control test plan development and execution.
Preferred Qualifications (Desired Skills/Experience):
BS technical degree or 4 or more year of relevant experience.
DoD 8570.01-M IAT Level II Certification
DoD 8570.01-M IAT Level III Certification (e.g., CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP); and IASAE Level II (e.g., CASP+ CE, CISSP (or Associate), CSSLP)
Experience acting as a Test Engineer or Software Assurance Engineer.
Experience with development and implementation of Anti-Tamper technologies and security controls.
Experience with software development tools, such as, DOORS, ClearCase, GitLab, Jira, Coverity, etc.
<
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s