Product Security Analyst /Cyber Security Analyst (Associate)
BoeingAbout the role
Company:
The Boeing CompanyBoeing Global Services (BGS) is currently looking for a Product Security Analyst / Cyber Security Analyst, Level 2 to join our team in Oklahoma City, OK. The successful candidate will focus on cybersecurity efforts at the multiple avionics laboratories used by the C-17 Globemaster III program. The C-17 avionics laboratories are comprised of a number of complex software development and formal qualification facilities that use both emulated and physical avionics that are used on the aircraft.
This role focuses on protecting the C-17 product (hardware, avionics, software, and supporting systems) across development, test, and sustainment phases by identifying and mitigating security risks, ensuring compliance with DoD and company requirements, and enabling secure engineering and test practices.
The C-17 Product Security Analyst researches, analyzes, and compiles technical data to integrate security and resiliency into products and services across the lifecycle, ensuring compliance with certifications and customer requirements. The role conducts system-level security assessments including risk, attack-surface, vulnerability, and anti-tamper analyses and performs security audits of applications and stacks from diverse sources. Responsibilities include triaging, aggregating, escalating, and reporting security indicators, coordinating incident response, correlating trends, and analyzing malware and adversary tactics to enhance detection and mitigation. The analyst produces and delivers technical reports and briefings to inform program decisions and sustain security posture over the program lifecycle.
Position Responsibilities:
- Ensure Cybersecurity, NIST 800, and IT compliance for C-17 Avionics Labs.
- Develops, implements, and sustains product security and resiliency throughout the requirements, design, build, test, production, operations, and support lifecycle
- Develops and enhances system requirements and architectures for product security to meet all applicable certification and customer requirements.
- Ensures security of facilities, equipment, tools, data, networks, and resources used for product: design, development, build, test, storage, delivery, operations, and support
- Defines and identifies product security requirements for suppliers of components and subsystems for integration into Boeing products and services.
- Coordinates with governments, customers, suppliers, and industry to identify risks and improve industry and regulatory security standards and requirements for programs and interfacing systems
- Conducts research and development activities resulting in innovative solutions
- Advises customers on maintaining product security and certification, including security consequences of modifying products and services.
- Support cyber risk assessments and the development of Risk Assessment Report (RAR)
- Develop and maintain a Security Assessment Plan (SAP) for the labs
- Support development of Interim Authority to Test (IATT) and Authority to Operate (ATO) packages
- Knowledge of the DoW policies and requirements related to cybersecurity are a plus, along with certifications such as Security+ or CISSSP
- Ability to understand the big picture and the inter-relationships of all positions and activities in the system, including the impact of changes in one area on another area. This includes the ability to see and understand the inter-relationships between components of systems and plans, anticipate future events, and apply the principles of systems thinking to accelerate performance
- Knowledge of aircraft systems, components, and loadable/non-loadable software
- Skill and ability to: collect, organize, synthesize, and analyze data; summarize findings; develop conclusions and recommendations from appropriate data sources
- Resolves cross-functional technical issues
Basic Qualifications (Required Skills/Experience):
- Bachelor’s degree in a technical discipline or equivalent experience
- 2+ years’ experience in project or security operations teams
- Experience with system security domains (e.g., information assurance, intrusion detection, software protection, software assurance, communications security, encryption and key management, network security, certification and accreditation) and applicable industry and government guidance and regulations to produce secure systems.
- Experience working in a distributed environment and multiple teams
- Experience working with Information Technology in a Weapon System context
- Experience with network and host-based Intrusion Detection Systems (IDSs) and Security Incident Event Management
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s