The Boeing Company is seeking a Lead Product Security (Cyber) Test Engineer to support the Air Proprietary 1 (AP1) program by leading the execution of the cyber test lifecycle, performing threat assessments, and executing adversarial testing to ensure the security and resiliency of their products, platforms, and services.
Requirements
- 5+ years of experience in product security, cybersecurity research, or a related field
- 5+ years of experience planning and executing penetration testing of either IT based systems or Avionics embedded systems
- Experience designing and/or testing product systems
- Experience working with Product Security (non-IT) Cyber Compliance and/or Avionics Embedded systems risk management assessment
- Experience planning and executing penetration tests in one or more of the following domains: Windows, Linux, VxWorks, and INTEGRITY Operating Systems, IP-Based Networks, Avionics, Embedded Systems, Non-Standard Ethernet Protocols (ARINC, MIL-STD), RF interfaces
- Experience evaluating cybersecurity of proprietary protocols, applications, and firmware within a complex, integrated environment
- Experience with scripting languages such as Bash, Python, PowerShell
Responsibilities
- Lead execution of penetration tests to identify, exploit, and assess a target system’s vulnerabilities in a threat-representative manner on embedded systems and IP-based networks
- Subject Matter Expert for emulating advanced cyber adversary (advanced persistent threats) tactics, techniques and procedures (TTPs)
- Lead controlled attack simulations that test the effectiveness of a blue team and its capabilities to detect, block, and mitigate attacks and breaches
- Develop exploits and malware targeting modern operating systems and defenses
- Reverse engineering firmware and software to support vulnerability identification
- Develop cyber test tools as necessary to achieve threat emulation objectives
- Communicate recommendations for improvements to customer stakeholders via reports or presentations using common frameworks such as MITRE ATT&CK, Cyber Kill Chain, etc.
Other
- 100% onsite
- 5+ years of experience leading projects or engineering teams
- 5+ years of experience working with Department of Defense (DoD) organizations, projects and/or programs
- 3+ years of experience leading and mentoring a technical team
- Able to travel both domestically and internationally