Product Security Engineer
Boeing Defence United Kingdom Limited is seeking an experienced Product Security Engineer to join our growing team in Bristol or Yeovil and shape the future of integrating security and resiliency across our products and services. Product security engineering is a cross‑cutting engineering function and a critical element of designing, delivering, and maintaining Boeing products and services. Our mission is to influence designs and implement security solutions that protect product integrity. You will join a highly energized team committed to staying ahead of evolving cyber threats, developing innovative security measures, consistent standards, practices, and tools.
As an experienced Product Security Engineer, you will lead development, implementation, and sustainment of product security and resiliency across the requirements, design, build, test, production, operations, and support lifecycle. You will be expected to independently shape technical approaches, influence program‑level decisions, and provide subject matter expertise to internal and external stakeholders.
Responsibilities
- Develop and implement product security requirements and architectures to satisfy certification, regulatory, and customer requirements.
- Define security design approaches and lead integration of security features into product architectures and designs.
- Conduct and lead cybersecurity risk analysis and threat assessments, evaluate likelihood, impact, and residual risk, and determine mitigations.
- Perform and lead security assessments, audits, and vulnerability analyses; prepare mitigation strategies and drive remediation actions.
- Establish and sustain security practices across the product lifecycle through coordination with cross‑functional teams and program leadership.
- Communicate and document product security and certification implications, including security consequences of product modifications, to internal stakeholders, suppliers, and customers.
- Identify and define product security requirements for suppliers of components and subsystems; coordinate supplier security activities and evaluate supplier deliverables for compliance.
- Coordinate with governments, customers, suppliers, and industry to identify program risks and improve industry and regulatory security standards and requirements for programs and interfacing systems.
- Independently conduct research and development activities that result in innovative security solutions, tools, or processes; lead pilot implementations and evaluate outcomes.
- Perform system analysis and trade studies to define technical concepts, security architectures, and optimal security solutions; document rationale and recommendations for program decision makers.
- Develop and improve team tools, processes, and automation to increase productivity and repeatability across programs.
- Lead or contribute to program boards and design reviews: gather and analyze data, prepare briefings, communicate recommendations, and support cross‑team decision making.
- Monitor emerging threats, vulnerabilities, and security technologies; assess applicability to programs and recommend prioritized adoption or mitigations.
- Ensure security of tools, data, networks, and resources used for product design, development, build, test, storage, delivery, operations, and support.
- Respond to program‑level security incidents or findings; coordinate remediation, document results, and communicate status to stakeholders.
- Advise customers and program teams on maintaining product security and certification, including the security consequences of modifying products and services.
Qualifications
Basic Qualifications (Required Skills/Experience)
- Applied experience in multiple of the following areas:
- Cybersecurity and security risk / threat assessment
- Security architecture, design, and analysis
- Network security architecture for embedded and enterprise systems
- Embedded systems security and cyber‑physical systems
- Systems hardening and security control implementation
- Cryptography and PKI design or integration
- Security testing, evaluation, and verification activities
- Trusted computing & anti‑tamper engineering
- Aircraft communications standards & protocols (ARINC 400, 600, 800 series etc.)
- Secure Software Development Lifecycle (SDLC) and DevSecOps practices
Preferred Qualifications (Desired Skills/Experience)
- The ability to obtain UK Security Clearance
- Experience defining Concept of Operations (ConOps), system requirements, and use‑case driven security requirements.
- Broad experience in risk assessment and management, including threat modelling and vulnerability analysis for networked and embedded systems.
- Experience leading or participating in cybersecurity audits, certification activities, and investigations.
- Experience with security incident response, root cause analysis, and trend analysis.
- Familiarity with malware analysis, attack surface reduction, and advanced security analysis techniques.
- Proven knowledge or hands‑on experience with DevSecOps toolchains and automation.
- Familiarity with avionics, embedded computing, and communications systems (ARINC series).
- Proficiency with networking and computing protocols & architectures (TCP/IP, OSI, UDP, serial/parallel communications, bus architectures).
- Understanding of hardware and software integration processes for safety‑critical platforms.
- Familiarity with Secure by Design principles and techniques.
- Experience applying relevant standards and frameworks, including:
- RTCA/EUROCAE: DO‑326B/ED‑202B, DO‑356A/ED‑203A
- NIST: Risk Management Framework and SPs 800‑30, 800‑53, 800‑160
- ISO/IEC: 27001/27002, 62443
- DEFSTAN: 05‑138, 05‑139
- Experience with Model‑Based Engineering (MBE) tools and languages such as UML/SysML, 3DX, CATIA, Cameo, and MagicDraw is desirable.
- Proven contributions to industry standards, professional organizations, or cross‑industry working groups are a plus.
Benefits
- Competitive salary and annual incentive plans
- Continuous learning: You’ll develop the approach and skills to navigate whatever comes next
- Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way
- Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs
- 23 days plus UK public holidays and a Winter Break between Christmas and New Year
- Pension Plan with 10% employer contribution
- Company paid BUPA Medical Plan
- Short Term Sickness: 100% pay for the first 26 weeks
- Long Term Sickness: 66.67% of annual salary from 27th week; life insurance 6x annual salary
- Learning Together Programme to support your ongoing personal and career development
- Access to Boeing’s Well Being Programs, tools and incentives
- Parental leave options available
Additional Information
Employer will not sponsor applicants for employment visa status.
Shift: Not a Shift Worker (United Kingdom)
Location: Bristol or Yeovil, United Kingdom. This position does not offer relocation. Candidates must live in the immediate area or relocate at their own expense.
Security Clearance: This position requires the ability to obtain United Kingdom Security Check.
#J-18808-Ljbffr…
