Product Security Engineer at Boeing
Colorado Springs, Colorado, USA -
Full Time


Start Date

Immediate

Expiry Date

18 Oct, 25

Salary

91800.0

Posted On

19 Jul, 25

Experience

1 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Technology, Gse, Physics, Cisa, Software Assurance, Collaboration, Cissp, Computer Science, Chemistry, Scna, Data Science, Communication Skills, Sscp, Product Security, Mathematics, Tabletop

Industry

Information Technology/IT

Description

Colorado Springs, Colorado
Job ID JR2025461123 Category Engineering - Product Security Role Type Onsite Post Date Jul. 17, 2025

JOB DESCRIPTION

At Boeing, we innovate and collaborate to make the world a better place. We’re committed to fostering an environment for every teammate that’s welcoming, respectful and inclusive, with great opportunity for professional growth. Find your future with us.
Boeing’s Missile Defense Program is seeking motivated and talented Associate (Level 2), Mid Level (Level 3 ) or Senior (Level 4) Product Security Engineers in Colorado Springs, Colorado! These positions will support the performance of product security and cybersecurity engineering for the National Team Command, Control, Battle Management and Communications (C2BMC) Programs & Networks.
Missile Defense programs are part of the Ballistic Missile Defense System which defends the United States homeland and its regional allies all over the world. Be a part of our passionate and highly motivated team who are excited to be on the forefront of defense of our nation.
Boeing offers a comprehensive benefits package including generous Paid Time Off (PTO), flexible work schedules, paid parental leave for mothers and fathers, 401k matching, tuition assistance for earning advanced degrees, and paid medical leave programs.

BASIC QUALIFICATIONS (REQUIRED SKILLS/EXPERIENCE):

  • Bachelor of Science degree from an accredited course of study in engineering, engineering technology (includes manufacturing engineering technology), chemistry, physics, mathematics, data science, or computer science.
  • Active Top Secret clearance
  • Current DoD 8570 certification at IAT Level II / IAM Level I or higher (e.g., Security+, GSEC, SCNP, SSCP, CISSP, CISA, GSE, SCNA)
  • 1+ years experience in product security / cybersecurity engineering
  • 1+ years experience with industry standard cybersecurity frameworks (NIST, OWASP, DFARS)
  • Experience using analytical, collaboration, communication and organizational skills

PREFERRED QUALIFICATIONS (DESIRED SKILLS/EXPERIENCE):

  • 2 years+ experience in Windows/RHEL System admin experience, installing, tuning & troubleshooting Cyber Tools to include ESS/HBSS, ConfigOS, Splunk/Elastic etc.
  • 2 years+ experience in configuring, running, and scripting audit tools
  • 2 years+ experience using knowledge of Software Assurance (SwA) static and/or dynamic code analysis (e.g. Fortify)
  • Experience with Federal Information Security Management Act (FISMA)/RMF and National institute of Standards and Technology (NIST) 800-53 requirements
  • Experience leading system and component level cyber test and evaluation, including threat and security assessments, and tabletop exercises
  • Experienced self-starter with strong written and oral communication skills, and a focus on translating technically complex issues into simple, easy to understand concept
  • Growing understanding of DoD and missile defense command and control, battle management, architectures and communications system concepts, mission, and common system test and data analysis techniques

TYPICAL EDUCATION/EXPERIENCE:

Associate (2): Education/experience typically acquired through advanced technical education from an accredited course of study in engineering, engineering technology (includes manufacturing engineering technology), computer science, engineering data science, mathematics, physics or chemistry (e.g. Bachelor) and typically 2 or more years’ related work experience or an equivalent combination of technical education and experience or non-US equivalent qualifications. In the USA, ABET accreditation is the preferred, although not required, accreditation standard.
Mid-Level (3): Education/experience typically acquired through advanced technical education from an accredited course of study in engineering, engineering technology (includes manufacturing engineering technology), computer science, engineering data science, mathematics, physics or chemistry (e.g. Bachelor) and typically 5 or more years’ related work experience or an equivalent combination of technical education and experience or non-US equivalent qualifications. In the USA, ABET accreditation is the preferred, although not required, accreditation standard.
Senior (4): Education/experience typically acquired through advanced technical education from an accredited course of study in engineering, engineering technology (includes manufacturing engineering technology), computer science, engineering data science, mathematics, physics or chemistry (e.g. Bachelor) and typically 9 or more years’ related work experience or an equivalent combination of technical education and experience or non-US equivalent qualifications. In the USA, ABET accreditation is the preferred, although not required, accreditation standard.

EDUCATION

Bachelor’s Degree or Equivalent Required

Team member will work with other industry partners in the development and execution of a comprehensive assessment program supporting the C2BMC Element of the Ballistic Missile Defense System. This individual will act as the primary group to for testing and applying patches on all main software/application systems on the system including workstation and servers. This team will be supporting the system by interacting continuously with the cyber team compliance team to remediate any vulnerabilities founding during automated or manual cyber scans. As patching can be an impacting activity, a detailed oriented individual is a must for this position.

  • Developing and verifying installation instructions for Cyber Tools and Vendor Patches
  • Applying Security Technical Implementation Guides (STIGs)
  • Managing and addressing any Cyber Tasking Orders (CTOs) related to the Cyber Tools
  • Integrating, configuring and automating the installation of the Elastic Stack with the existing set of Cyber Tools on the C2BMC system
  • Working with various C2BMC teams to ensure compatibility and seamless integration of Cyber Tools within the larger system
  • Documentation and verification of all installation and configuration steps for the labs and operations deliveries
  • Providing feedback to Cyber Leadership and engineers to improve the cybersecurity tools and processes
  • Verifying the Elastic Stack meets contractual requirements
  • Documenting the installation and delivering installation instructions to deploy the Elastic Stack
  • Installing, deploying, and unit testing other Cyber Tools such as ACAS, ArcSight, BigFix, Delinea, Endgame, ESS, Axway Repeater, and Responder for Windows MFA in National Team (NT) labs, the C2BMC Testbed (CTB), and Operations.
  • Collaborating with local Information System Security Officers (ISSOs) to ensure compliance with relevant cybersecurity standards and regulations
  • Assess organization-wide security and privacy risk and update assessment results on an ongoing basis
  • Perform system analysis and develop system test for cyber threats, cyber test activities, and the cybersecurity of large-scale events
  • Perform cyber risk assessments and develop risk mitigation plans
  • Support the engineering installation & analysis of patches and various system updates and upgrades to determine system consequence of these changes
  • Attend, collect data from, out brief, and facilitate collaboration and project management from various program boards
  • Support cyber threat intelligence activities
  • Support the development and maintenance of cyber scanning, patching, remediation, tools and applications
  • Support, as required, TEMPEST, DFARS, COMSEC, CNSSI, and other compliance drivers as needed
  • Support and facilitate various ATO packages including processing IAVMs and CTOs for the same
  • Perform and/or support the development of tools for cyber forensics
  • Develop, define efficiencies and improvements to tools to improve team productivity
  • Perform system analysis trade studies to define technical concepts and solution
Responsibilities

Team member will work with other industry partners in the development and execution of a comprehensive assessment program supporting the C2BMC Element of the Ballistic Missile Defense System. This individual will act as the primary group to for testing and applying patches on all main software/application systems on the system including workstation and servers. This team will be supporting the system by interacting continuously with the cyber team compliance team to remediate any vulnerabilities founding during automated or manual cyber scans. As patching can be an impacting activity, a detailed oriented individual is a must for this position.

  • Developing and verifying installation instructions for Cyber Tools and Vendor Patches
  • Applying Security Technical Implementation Guides (STIGs)
  • Managing and addressing any Cyber Tasking Orders (CTOs) related to the Cyber Tools
  • Integrating, configuring and automating the installation of the Elastic Stack with the existing set of Cyber Tools on the C2BMC system
  • Working with various C2BMC teams to ensure compatibility and seamless integration of Cyber Tools within the larger system
  • Documentation and verification of all installation and configuration steps for the labs and operations deliveries
  • Providing feedback to Cyber Leadership and engineers to improve the cybersecurity tools and processes
  • Verifying the Elastic Stack meets contractual requirements
  • Documenting the installation and delivering installation instructions to deploy the Elastic Stack
  • Installing, deploying, and unit testing other Cyber Tools such as ACAS, ArcSight, BigFix, Delinea, Endgame, ESS, Axway Repeater, and Responder for Windows MFA in National Team (NT) labs, the C2BMC Testbed (CTB), and Operations.
  • Collaborating with local Information System Security Officers (ISSOs) to ensure compliance with relevant cybersecurity standards and regulations
  • Assess organization-wide security and privacy risk and update assessment results on an ongoing basis
  • Perform system analysis and develop system test for cyber threats, cyber test activities, and the cybersecurity of large-scale events
  • Perform cyber risk assessments and develop risk mitigation plans
  • Support the engineering installation & analysis of patches and various system updates and upgrades to determine system consequence of these changes
  • Attend, collect data from, out brief, and facilitate collaboration and project management from various program boards
  • Support cyber threat intelligence activities
  • Support the development and maintenance of cyber scanning, patching, remediation, tools and applications
  • Support, as required, TEMPEST, DFARS, COMSEC, CNSSI, and other compliance drivers as needed
  • Support and facilitate various ATO packages including processing IAVMs and CTOs for the same
  • Perform and/or support the development of tools for cyber forensics
  • Develop, define efficiencies and improvements to tools to improve team productivity
  • Perform system analysis trade studies to define technical concepts and solutions

This position is expected to be 100% onsite. The selected candidate will be required to work onsite at one of the listed location options. (Colorado Springs, CO.)
This position may require the ability to obtain access to an MDA facility. Access to the facility requires a background investigation by U.S. government authorities.

Loading...