Embedded System Security Engineer
Job Description
This hybrid role focuses on strengthening cyber resilience for embedded, cyber-physical systems used in airborne engine control environments.
Responsibilities
- Identify the technology and processes needed to satisfy product requirements for system security against cyber threats.
- Assist customer programs with implementation of secure cyber resilient system (SCRS), including:
- Task planning
- Requirements development and derivation
- Implementation support
- Risk assessments using associated tools and methods
- Completion of product lifecycle deliverables
- Review existing product designs and development plans to find product security scope gaps and drive updates to align with contract requirements.
- Develop, share, and drive product security best practices across product teams and design teams.
- Coordinate with the Product Security capability team to improve techniques, policies, procedures, and knowledge for enterprise-wide adoption of best practices.
- Collaborate with customers, their clients, supply-chain partners, and industry experts to strengthen product security capability and tools for customer programs.
Requirements
- U.S. Citizenship required due to the nature of the work.
- Education and experience:
- Bachelor’s degree in Cybersecurity or a STEM discipline (Electrical, Systems, Controls or equivalent) with 6+ years experience, or
- Master’s degree with 4+ years experience
- Knowledge of embedded systems and the technical skills needed to develop, implement, and secure them.
- Experience applying systems security policies and standards for cyber-physical engineering, including:
- Risk Management Framework (RMF)
- NIST SP 800-160
- DO-326
- DoDI 5000.83
- Working knowledge of the program management lifecycle, processes, procedures, and best practices.
- Ability to operate in a fast-paced hybrid environment, including virtual teams.
- Strong interpersonal skills:
- Inquisitive and communicative approach
- Verbal and non-verbal communication to engage teams and represent customer and stakeholder needs
- Ability to travel periodically, up to 25%.
Technologies
- Risk Management Framework (RMF)
- NIST SP 800-160
- DO-326
- DoDI 5000.83
- DO-326A
- DO-355
- Sharpcloud
- MS Azure DevOps
- Earned value management
Preferred Qualifications
- Familiarity with industry guidance and standards such as DO-326A and DO-355, including certification-related project artifact development and project execution (including Stages of Involvement (SOI)).
- Experience or interest in product security, cybersecurity, and cyber threats.
- Experience or interest with project management concepts (including earned value management), process change management, configuration management, and data analysis.
- Experience with tools such as Sharpcloud and MS Azure DevOps.
- Outcome-focused engineering with problem-solving abilities.
Benefits
- Health care
- Dental
- Vision
- Life insurance
- 401(k)
- Education assistance
- Paid time off including PTO
- Holidays
- Any other paid leave required by law
Compensation: USD 90,000 - 160,000 per year.
Salary/Pay Note: salary rate of $90,000 to $160,000 per hour.