Product Security Software Engineer (Mid-Level Or Experienced)

Boeing Berkeley , CA 94705

Posted 2 months ago

Job Description

At Boeing, we innovate and collaborate to make the world a better place. From the seabed to outer space, you can contribute to work that matters with a company where diversity, equity and inclusion are shared values. We're committed to fostering an environment for every teammate that's welcoming, respectful and inclusive, with great opportunity for professional growth. Find your future with us.

The Boeing Company is looking for a Product Security Software Engineer (Mid-Level or Experienced) to support Boeing Commercial Airplanes. This position will join The Boeing Linux team is responsible for creating the next generation of real time embedded operating systems to serve our military and civil aviation needs.

The selected candidate will derive requirements for software security based on Federal Aviation Administration (FAA) standards and compliance in order to develop a secure variant of the Yocto Linux operating system for use in Boeing platforms, test environments, and open-source applications across our industry. This position will provide technical support and guidance in the adoption of secure architectures and practices based on FAA requirements in order to ensure the Operating System is designed, implemented, and operated to meet FAA certifications. The Product Security Software Systems Engineer will be responsible to define the security functional requirements, their breakdown into lower tiers and provide a design assurance approach to the security objectives for the project. Additionally, the selected Engineer will be responsible for creation of necessary support documentation to support FAA certification of the Operating System.

This position can be based out of Berkeley, MO; Annapolis Junction, MD; North Charleston, SC; Huntsville, AL; Mesa, AZ; Oklahoma City, OK; or Ridley Park, PA.

Position Responsibilities:

  • Assess the adversity of airborne software subsystems in the context of the larger system

  • Manage risk in accordance with accepted industry, professional, and government standards to ensure security design integrity, availability, confidentiality, and regulatory compliance

  • Develop security requirements and coordinate with multiple system stakeholders to identify and properly implement and verify security measures to mitigate the risks, threats and vulnerabilities

  • Perform requirements verification on software security engineering products using inspection, analysis, demonstration, and test methods

  • Perform Common Vulnerabilities and Exploits (CVE) analysis and coordinate with system stakeholders to appropriately mitigate and address to reduce likelihood and consequences of CVE impacting system safety and operation

  • Support airplane system certification by providing required artifacts to the Boeing Cybersecurity Certification organization

  • Provide technical data and develop documentation in accordance with requirements and system security engineering processes and procedures for internal reference and external delivery

  • Support Product Security Incident Response Team to respond to security events

  • Organize several software teams to ensure consistent application of security standards within the Software Development Lifecycle

  • Identify improvements to ensure software implementation is aligned to industry and Boeing software assurance best practices

This position is hybrid. This means that the selected candidate will be required to perform some work onsite at one of the listed location options. This is at the hiring team's discretion and could potentially change in the future.

This position requires the ability to obtain a U.S. Security Clearance for which the U.S. Government requires U.S. Citizenship. An interim and/or final U.S. Secret clearance Post-Start is required.

Basic Qualifications (Required Skills/Experience):

  • Bachelor of Science degree from an accredited course of study in engineering, engineering technology (includes manufacturing engineering technology), chemistry, physics, mathematics, data science, or computer science

  • Experience Hardening a custom Operating System (preferably SELinux)

  • Experience with expertise in Compliance and certification of an operating system (for example ANSSI-BP-28 or NIST 800-153)

  • Experience developing software for real-time embedded systems

  • Experience with security tools, for example software composition analysis/software bill of materials, and vulnerability scanning

  • Experience with security infrastructure, product and cybersecurity systems analysis, design, development, and testing

  • Experience with agile software development

  • Experience with industry standards relating to Vulnerability Management including Common Vulnerabilities and Exposures (CVE)

Preferred Qualifications (Desired Skills/Experience):

  • 5 or more years' related work experience or an equivalent combination of education and experience

  • Understanding of the cybersecurity standards and practices defined within NIST 800-171 and 800-53, or Cybersecurity Maturity Model Certification (CMMC) domains

  • Experience with DevSecOps principles and tools, for example, CI/CD, IaC, CaC, SaC, Gitlab, Terraform, Ansible, Kubernetes, Docker

  • Experience working in a cloud environment

  • Experience with Real Time Embedded Operating Systems

  • Experience in the aerospace and defense industry

  • Training or Certifications including CISSP, CSSLP, Security +, Cloud +, Certified Cloud Security Professional (CCSP), AWS certifications, or equivalent

Typical Education/Experience:

Mid-Level (Level 3)

Education/experience typically acquired through advanced technical education from an accredited course of study in engineering, computer science, mathematics, physics or chemistry (e.g. Bachelor) and typically 5 or more years' related work experience or an equivalent combination of technical education and experience (e.g. PhD, Master+3 years' related work experience). In the USA, ABET accreditation is the preferred, although not required, accreditation standard.

Experienced (Level 4)

Education/experience typically acquired through advanced technical education from an accredited course of study in engineering, computer science, mathematics, physics or chemistry (e.g. Bachelor) and typically 9 or more years' related work experience or an equivalent combination of technical education and experience (e.g. PhD+4 years' related work experience, Master+7 years' related work experience). In the USA, ABET accreditation is the preferred, although not required, accreditation standard.

Relocation:

Relocation assistance is not a negotiable benefit for this position. Candidates must live in the immediate area or relocate at their own expense.

Drug Free Workplace:

Boeing is a Drug Free Workplace where post offer applicants and employees are subject to testing for marijuana, cocaine, opioids, amphetamines, PCP, and alcohol when criteria is met as outlined in our policies.

Shift Work Statement:

This position is for 1st shift.

At Boeing, we strive to deliver a Total Rewards package that will attract, engage and retain the top talent. Elements of the Total Rewards package include competitive base pay and variable compensation opportunities.

The Boeing Company also provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work.

The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, and the applicability of collective bargaining agreements.

Pay is based upon candidate experience and qualifications, as well as market and business considerations.

Summary pay range for Mid-Level: $104,550 - $162,150

Summary pay range for Experienced: $127,500 - $197,800

Applications for this position will be accepted until April 8th, 2024

Export Control Requirements: U.S. Government Export Control Status: This position must meet export control compliance requirements. To meet export control compliance requirements, a "U.S. Person" as defined by 22 C.F.R. §120.15 is required. "U.S. Person" includes U.S. Citizen, lawful permanent resident, refugee, or asylee.

Export Control Details: US based job, US Person required

Equal Opportunity Employer:

Boeing is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, genetic factors, military/veteran status or other characteristics protected by law.

Read more Shows the full job description for sighted users

Apply Now Save JobRemove Job


icon no score

See how you match
to the job

Find your dream job anywhere
with the LiveCareer app.
Mobile App Icon
Download the
LiveCareer app and find
your dream job anywhere
App Store Icon Google Play Icon
lc_ad

Boost your job search productivity with our
free Chrome Extension!

lc_apply_tool GET EXTENSION

Product Security Software Engineer (Mid-Level Or Experienced)

Boeing