Embedded System Security Engineer
Job Description
This Embedded System Security Engineer role supports cyber-physical embedded systems for engine controls on airborne platforms, with a focus on system security and secure cyber-resilient implementations.
Responsibilities
- Define the technology and processes needed to satisfy product requirements for system security against cyber threats.
- Assist customer programs with secure cyber resilient system (SCRS) implementation, including:
- Task planning
- Requirements development, derivation, and implementation
- Risk assessments using appropriate tools and methods
- Completion of product lifecycle deliverables
- Evaluate existing product designs and development plans to identify gaps in product security scope and ensure alignment with contract requirements.
- Develop, explain, and drive product security best practices across product teams and design teams to improve adoption and implementation.
- Coordinate with the product security capability team to strengthen techniques, policies, procedures, and knowledge used across the business.
- Collaborate with customers, customer clients, supply-chain partners, and industry experts to advance product security capability and tools for customer programs.
Requirements
- U.S. Citizenship required due to the nature of the work.
- Education:
- Bachelor’s degree in Cybersecurity or a STEM discipline (Electrical, Systems, Controls or equivalent) plus 6+ years experience, or
- Master’s degree plus 4+ years experience
- Working knowledge of embedded systems and the technical skills to develop, implement, and secure cyber-physical embedded systems.
- Experience applying systems security policies and standards, including:
- Risk Management Framework (RMF)
- NIST SP 800-160
- DO-326
- DoDI 5000.83
- Knowledge of program management lifecycle processes, procedures, and best practices.
- Ability to operate in a fast-paced dynamic hybrid environment, including work with virtual teams.
- Strong interpersonal skills for inquisitive, communicative collaboration using both verbal and non-verbal communication with teams, customers, and stakeholders.
- Travel periodically up to 25%.
Technologies / Tools
- Risk Management Framework (RMF)
- NIST SP 800-160
- DO-326, DO-326A, DO-355
- DoDI 5000.83
- Sharpcloud
- MS Azure DevOps
- Earned value management
Benefits
- Health care
- Dental
- Vision
- Life insurance
- 401(k)
- Education assistance
- Paid time off including PTO
- Holidays
- Any other paid leave required by law
Preferred Qualifications
- Familiarity with industry guidance and standards such as DO-326A and DO-355, including certification-related project artifact development and project execution (including Stages of Involvement (SOI)).
- Experience or interest in product security efforts, cybersecurity, and cyber threats.
- Experience with project management concepts (earned value management), process change management, configuration management, and data analysis.
- Experience with tools such as Sharpcloud and MS Azure DevOps.
- Outcome-focused problem-solving approach.
Compensation
- Salary range: $90,000 - $160,000 per year
- Salary/pay note: $90,000 to $160,000 per hour
Location: Indianapolis, IN (hybrid)