About this role
Senior Product Security Engineer to drive secure software solutions for Boeing's Air Dominance programs in Berkeley, MO. Responsible for planning, design, and implementation of security across hybrid-cloud environments, leading DevSecOps initiatives and mentoring engineers, ensuring compliance with government security standards.
Key Responsibilities
- Incorporate security concepts through planning and design of complex engineering environments spanning multiple sites and multi-cloud solutions
- Collaborate with program customers to define security requirements and enable system integration
- Mentor and build a strong software security team
- Build up a robust DevSecOps pipeline with Cybersecurity SCRM and Security Policy Enforcement
- Provide security expertise through technical design reviews and program gate reviews
Technical Overview
Encompasses cloud and on-prem DevSecOps, risk engineering, threat analysis for avionics, and integration of NIST/FedRAMP/DoD DISA security frameworks; build security tooling into DevSecOps pipelines.
Ideal Candidate
The ideal candidate is a senior software security engineer with 9+ years of cloud DevSecOps experience, strong security architecture skills, and the ability to lead security programs across multi-cloud environments for defense programs. They should demonstrate hands-on experience with government security frameworks (NIST, FedRAMP, DoD SRG, DISA STIGs) and be capable of mentoring teams and guiding security reviews.
Must-Have Skills
Bachelor of Science degree in EngineeringEngineering Technology (including Manufacturing Technology)Computer ScienceData ScienceMathematicsPhysicsChemistry or non-US equivalent qualifications directly related to the work statementLevel 4: 9+ years of related work experience or an equivalent combination of education and experienceLevel 5: 14+ years of related work experience or an equivalent combination of education and experienceAbility to obtain a U.S. Security ClearanceExperience with networking in cloud environmentsExperience in cyber security solutions architecturewith a focus on cloud technologiesDevSecOpsand secure system designExperience leading DevSecOps teams to deploy a cloud or on-prem DevSecOps solutionsExperience with cloud security frameworks and compliance standards such as National Institute of Standards and Technology (NIST)Federal Risk and Authorization Management Program (FedRAMP)Department of Defense Security Requirements Guide (DoD SRG)and Defense Information Systems Agency Security Technical Implementation Guides (DISA STIGs)
Nice-to-Have Skills
Active Security ClearanceExperience in Avionic systems: architecturerequirementsdesigninterfacesplatform integrationflight test planningtestingvalidation and verificationExperience in software or hardware engineeringrequirementsdesigndevelopmenttestand working with software and hardwareExperience in aligning operational capabilities to regulatory frameworks and compliance requirements (i.e.ISONISTCMMC)Experience do you have with data linkscryptotrusted guardsmulti-level security?Experience with cyber verification and validation of Avionics Systems?Certified Application Security Engineer (CASE)Security+a CISSP certificationor equivalent Cyber Security certification (CISSP preferred)
Required Skills
DevSecOpsSecure Coding PracticesSoftware AssuranceInfrastructure as CodeIaCNISTFedRAMPDoD SRGDISA STIGsCloud computingMulti-cloudOn-premises computeThreat analysisSecurity design
Hard Skills
DevSecOpsInfrastructure as CodeIaCSecure Coding PracticesSoftware AssuranceRisk Engineering digital threadNational Institute of Standards and Technology (NIST)Federal Risk and Authorization Management Program (FedRAMP)Department of Defense Security Requirements Guide (DoD SRG)Defense Information Systems Agency Security Technical Implementation Guides (DISA STIGs)Cloud computingMulti-cloudOn-premises computeThreat analysisSecurity design
Soft Skills
LeadershipMentoringCollaborationCommunicationProblem-solvingStrategic thinking
Certifications
Required
Certified Application Security Engineer (CASE)Security+Certified Information Systems Security Professional (CISSP)
Preferred
CISSP
Keywords for Your Resume
Senior Product Security EngineerDevSecOpsSecure Coding PracticesSoftware AssuranceInfrastructure as CodeIaCNISTFedRAMPDoD SRGDISA STIGscloudmulti-cloudThreat analysisRisk Engineering digital threadSecure by DesignU.S. Security ClearanceCASESecurity+CISSPActive Security Clearanceavionicsair dominance
Deal Breakers
No ability to obtain a U.S. Security Clearance, Less than 9 years of related experience, Lack of experience with government security frameworks (NIST, FedRAMP, DoD SRG, DISA STIGs), No DevSecOps leadership experience
Get matched to jobs like this
Luna finds roles that fit your skills and career goals — no endless scrolling required.
Create a Free Profile