Skip to main contentA logo with &quat;the muse&quat; in dark blue text.
The Boeing Company

Product Security Software Vulnerability Analyst (Associate or Mid-Level)

Oklahoma City, OK

Job Description

At Boeing, we innovate and collaborate to make the world a better place. From the seabed to outer space, you can contribute to work that matters with a company where diversity, equity and inclusion are shared values. We're committed to fostering an environment for every teammate that's welcoming, respectful and inclusive, with great opportunity for professional growth. Find your future with us.

Boeing Product Security Software Engineering is looking for aProduct Security Software Vulnerability Analyst (Associate or Mid-Level). This position is a part of the Boeing Linux team who works to analyze, mitigate and disseminate vulnerabilities found within a secure variant of the Yocto Linux operating system for use in Boeing platforms, test environments, and open-source applications across our industry. The Boeing Linux team is responsible for creating the next generation of real time embedded operating systems to serve our military and civil aviation needs.

Want more jobs like this?

Get jobs delivered to your inbox every week.

Select a location
By signing up, you agree to our Terms of Service & Privacy Policy.


This position will provide technical support and guidance in the analysis of common vulnerability enumeration (CVE), common weakness enumeration (CWE) and other vulnerabilities found within the operating system and its associated software. The analyst will be responsible to define the security functional requirements, their breakdown into lower tiers and provide a design assurance approach to the security objectives for the project. Additionally, the selected engineer will be responsible for creation of necessary support documentation to support FAA certification of the Operating System.

This position can be based out of Annapolis Junction, MD; Berkeley, MO; Arlington, TX; North Charleston, SC; Colorado Springs, CO; Huntington Beach, CA; Huntsville, AL; Mesa, AZ; Oklahoma City, OK or Ridley Park, PA.

Position Responsibilities:
  • Utilizing vulnerability analysis and static analysis tools to identify vulnerabilities
  • Provide Software Developers guidance on patching, mitigating and risk acceptance for vulnerabilities found
  • Research vulnerabilities and identify its applicability to a Real Time Operating System
  • Familiarity with Linux Kernel Security and Real Time Operating Systems
  • Familiarity with DevSecOps software factory and providing security artifacts to show software security within a pipeline
  • Performing vulnerability management of risks, threats, and vulnerabilities identified during and after system development
  • Generating documentation to show remediation of vulnerabilities and assisting with compliance documentation artifacts

This position is hybrid. This means that the selected candidate will be required to perform some work onsite at one of the listed location options.This is at the hiring team's discretion and could potentially change in the future.

This position requires the ability to obtain a U.S. Security Clearance for which the U.S. Government requires U.S. Citizenship. An interim and/or final U.S. Secret clearance Post Start is required.

Basic Qualifications (Required Skills/Experience):
  • Bachelor of Science degree in engineering, chemistry, physics, mathematics, or computer science
  • Experience with Linux Operating System
  • Experience programming on an embedded or real-time operating system (VxWorks, Integrity, 1553 or SpaceWire) protocols
  • Experience with agile software development
  • Experience with industry standards relating to Vulnerability Management including Common Vulnerabilities and Exposures (CVE)

Preferred Qualifications (Desired Skills/Experience):
  • 3 or more years' related work experience or an equivalent combination of education and experience
  • Understanding of the cybersecurity standards and practices defined within DO-178C, NIST 800-171 and 800-53, or Cybersecurity Maturity Model Certification (CMMC) domains
  • Experience with DevSecOps principles and tools, for example, CI/CD, IaC, CaC, SaC, Gitlab, Terraform, Ansible, Kubernetes, Docker
  • Experience working in a cloud environment
  • Experience in the aerospace and defense industry
  • Experience in using Static Analysis Tools such as Sonarqube, Coverity, Polyspace, etc
  • Experience with security infrastructure, product and cybersecurity systems analysis, design, development, and testing
  • Experience with additional security tools, such as for software composition analysis/software bill of materials (SBOM)
  • Training or Certifications including CISSP, CSSLP, Security +, Cloud +, Certified Cloud Security Professional (CCSP), AWS certifications, or equivalent
  • Experience with Supply-chain Levels for Software Artifacts (SLSA)

Typical Education/Experience:

Associate (Level 2)

Education/experience typically acquired through advanced education (e.g. Bachelor) and typically 3 or more years' related work experience or an equivalent combination of education and experience (e.g. Master+1 years' related work experience , 7 years' related work experience, etc.).

Mid-Level (Level 3)

Education/experience typically acquired through advanced education (e.g. Bachelor) and typically 6 or more years' related work experience or an equivalent combination of education and experience (e.g. Master+4 years' related work experience, 10 years' related work experience, etc.).

Relocation:

Relocation assistance is not a negotiable benefit for this position. Candidates must live in the immediate area or relocate at their own expense.

Drug Free Workplace:

Boeingis a Drug Free Workplace where post offer applicants and employees are subject to testing for marijuana, cocaine, opioids, amphetamines, PCP, and alcohol when criteria is met as outlined in our policies.

Shift Work Statement:

This position is for 1st shift.

At Boeing, we strive to deliver a Total Rewards package that will attract, engage and retain the top talent. Elements of the Total Rewards package include competitive base pay and variable compensation opportunities.

The Boeing Company also provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work.

The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, and the applicability of collective bargaining agreements.

Pay is based upon candidate experience and qualifications, as well as market and business considerations.

Summary pay range for Associate level: $76,500 - $119,600

Summary pay range for Mid-Level: $94,350 - $146,050

Applications for this position will be accepted until April 4th, 2024

Export Control Requirements: U.S. Government Export Control Status: This position must meet export control compliance requirements. To meet export control compliance requirements, a "U.S. Person" as defined by 22 C.F.R. §120.15 is required. "U.S. Person" includes U.S. Citizen, lawful permanent resident, refugee, or asylee.

Export Control Details: US based job, US Person required

Equal Opportunity Employer:

Boeing is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, genetic factors, military/veteran status or other characteristics protected by law.

Client-provided location(s): Oklahoma City, OK, USA; Huntsville, AL, USA; Colorado Springs, CO, USA; Mesa, AZ, USA; Annapolis Junction, MD, USA; Huntington Beach, CA, USA; Berkeley, MO, USA; Ridley Park, PA, USA; Arlington, TX, USA; North Charleston, SC, USA
Job ID: Boeing-00000418055
Employment Type: Other