About this role
Boeing is seeking a Product Security Analyst to support program lifecycle information system security, including RMF processes and security requirements coordination. The role focuses on risk and vulnerability assessment, remediation cost estimation, and executing Accreditation and Authorization (A&A) activities.
Key Responsibilities
- Implement cybersecurity features and RMF processes for embedded computing systems
- Evaluate customer and operational needs to define and coordinate system security requirements
- Assess assets, risks, threats, and vulnerabilities to ensure security design integrity
- Develop remediation recommendations and cost to mitigate estimates
- Implement Accreditation and Authorization (A&A) activities per ICD 503 RMF, NISPOM, or DoD Overprint
Technical Overview
You will implement cybersecurity features and apply RMF processes for embedded computing systems, evaluating assets, risks, threats, and vulnerabilities against accepted standards. Responsibilities also include executing A&A activities per ICD 503 RMF and coordinating security requirements using NISPOM and DoD Overprint guidance.
Ideal Candidate
The ideal candidate is a product security cybersecurity analyst with 6+ years of directly relevant experience (or 4+ years with a Masters) focused on Information Systems Security. They hold a DoD 8570 IAT Level II Certification and have an active TS/SCI clearance, with hands-on RMF (including ICD 503 RMF) and Accreditation and Authorization (A&A) responsibilities for embedded computing systems.
Must-Have Skills
DoD 8570 IAT Level II Certification.Experience with Information Systems Security is required.Active U.S. TS/SCI Security Clearance is required pre-start.active U.S. security clearance (active in past 24 months considered active)Bachelor and typically 6 or more years of work related experience or Masters and typically 4 or more years of work related experience; ten (10) or more years directly related experience in lieu of a degree is acceptable.
Nice-to-Have Skills
Experience with DevSecOps and Continuous Integration/Continuous Delivery (CI/CD)
Tools & Platforms
RMF (including ICD 503 RMF)NISPOMDoD Overprint to the NISPOM
Required Skills
product securitycybersecurity analystinformation system security solutionsRMF processesICD 503 RMFembedded computing systemssystem security requirementsasset risk threat vulnerability assessmentconfidentiality availability non-repudiationremediation recommendationscost to mitigate estimatesystem security processes methods toolsAccreditation and Authorization (A&A)NISPOMDoD OverprintDoD 8570 IAT Level II CertificationDevSecOpsContinuous Integration/Continuous Delivery (CI/CD)
Hard Skills
plandesigndevelopvalidate and verify lifecycle balanced information system security solutionscybersecurity features implementationRMF processes for embedded computing systemssystem security requirementssystem security requirements integrationcompatibility of physicalfunctional and program interfacestotal system of systems analysissystem architecture analysisasset identificationrisk assessmentthreat assessmentvulnerability assessmentsecurity design integrityavailabilityconfidentialitynon-repudiationcontract complianceremediation recommendations evaluationcost to mitigate estimatesystem security processessystem security methodssystem security toolsAccreditation and Authorization (A&A) activitiesICD 503 RMFNISPOMDoD Overprint to the NISPOMsecurity related activities and requirements coordinationinformation systems securitysecurity clearance complianceDoD 8570 IAT Level II Certification
Soft Skills
interdisciplinarycollaborative approachwork closely with the customercoordinate with system administratorsnetwork and software engineerstest and validation engineers and program managementresolve cross-functional technical issuesworks under minimal directiontravel for meetings (25%)
Certifications
Required
DoD 8570 IAT Level II Certification
Keywords for Your Resume
Cybersecurity AnalystProduct SecurityProduct Security Analystinformation system security solutionsRMF processesembedded computing systemsassetsrisksthreatsvulnerabilitiesconfidentialityavailabilitynon-repudiationcontract complianceremediation recommendationscost to mitigate estimatesystem security processesAccreditation and Authorization (A&A) activitiesICD 503 RMFNISPOMDoD OverprintDoD 8570 IAT Level II CertificationInformation Systems SecurityDevSecOpsContinuous Integration/Continuous Delivery (CI/CD)TS/SCI Security ClearanceU.S. Security ClearanceCybersecurity Analyst - Product SecurityAccreditation and Authorization (A&A)
Deal Breakers
DoD 8570 IAT Level II Certification required, Active U.S. TS/SCI Security Clearance required pre-start, Experience with Information Systems Security required, Bachelor degree (or Masters) with required years of related experience (or 10+ years in lieu)
Get matched to jobs like this
Luna finds roles that fit your skills and career goals — no endless scrolling required.
Create a Free Profile