Product Security Engineer
// Role Summary
Boeing is seeking an experienced Product Security Engineer to join their team in Bristol or Yeovil, focusing on integrating security and resilience into products and services throughout their lifecycle.
// Key Responsibilities
- Lead the development, implementation, and sustainment of product security across all lifecycle phases.
- Shape technical approaches and influence program-level decisions with subject matter expertise.
- Collaborate with multidisciplinary teams to protect complex systems (IT, embedded, non-IT).
- Solve high-impact security challenges and contribute to the resilience and certification posture.
- Requires deep knowledge in system security, systems engineering, safety/airworthiness, and security architecture.
- Opportunity to influence next-generation security engineering practices.
// Role Specification
About the Role
Boeing is seeking an experienced Product Security Engineer to join their growing team in Bristol or Yeovil. This critical role focuses on integrating security and resiliency across Boeing's products and services, ensuring product integrity against evolving cyber threats. You will be part of a dynamic team dedicated to developing innovative security measures, standards, practices, and tools.
Responsibilities
As an experienced Product Security Engineer, you will lead the development, implementation, and sustainment of product security and resiliency throughout the entire product lifecycle, from requirements and design to operations and support. You will independently shape technical approaches, influence program-level decisions, and provide subject matter expertise to both internal and external stakeholders. Your role will involve collaborating with a diverse, enterprise-wide community to create and apply best practices, tools, and solutions that protect complex systems, including IT, embedded, and non-IT environments. This position offers the opportunity to solve high-impact security challenges, influence next-generation security engineering, and directly contribute to the resilience and certification posture of Boeing’s commercial and defence offerings.
Key responsibilities include:
- Developing and implementing product security requirements and architectures to meet certification, regulatory, and customer needs.
- Defining security design approaches and leading the integration of security features into product architectures.
- Conducting and leading cybersecurity risk analysis and threat assessments, evaluating impact and residual risk, and determining mitigations.
- Performing and leading security assessments, audits, and vulnerability analyses, preparing mitigation strategies, and driving remediation actions.
- Establishing and sustaining security practices across the product lifecycle through coordination with cross-functional teams and program leadership.
- Communicating and documenting product security and certification implications to internal stakeholders, suppliers, and customers.
- Identifying and defining product security requirements for suppliers, coordinating their activities, and evaluating deliverables for compliance.
- Coordinating with governments, customers, and suppliers to identify program risks and improve industry and regulatory security standards.
- Conducting research and development for innovative security solutions, tools, or processes, and leading pilot implementations.
- Performing system analysis and trade studies to define technical concepts, security architectures, and optimal security solutions.
- Developing and improving team tools, processes, and automation to enhance productivity and repeatability.
- Leading or contributing to program boards and design reviews, analyzing data, preparing briefings, and communicating recommendations.
- Monitoring emerging threats, vulnerabilities, and security technologies, assessing applicability to programs, and recommending adoption or mitigations.
- Ensuring the security of tools, data, networks, and resources used throughout the product lifecycle.
- Responding to program-level security incidents or findings, coordinating remediation, documenting results, and communicating status.
- Advising customers and program teams on maintaining product security and certification.
Qualifications
Ideal candidates bring deep knowledge and experience in system security, systems engineering, safety/airworthiness, security architecture, and verification/validation activities. Applied experience in multiple of the following areas is required:
- Cybersecurity and security risk / threat assessment
- Security architecture, design, and analysis
- Network security architecture for embedded and enterprise systems
- Embedded systems security and cyber-physical systems
- Systems hardening and security control implementation
- Cryptography and PKI design or integration
- Security testing, evaluation, and verification activities
- Trusted computing & anti-tamper engineering
- Aircraft communications standards & protocols (ARINC 400, 600, 800 series etc.)
- Secure Software Development Lifecycle (SDLC) and DevSecOps practices
Preferred qualifications include experience defining Concept of Operations (ConOps), system requirements, and use-case driven security requirements; broad experience in risk assessment and management; experience leading or participating in cybersecurity audits, certification activities, and investigations; experience with security incident response; familiarity with malware analysis and advanced security analysis techniques; proven knowledge or hands-on experience with DevSecOps toolchains and automation; familiarity with avionics, embedded computing, and communications systems; proficiency with networking and computing protocols & architectures; understanding of hardware and software integration for safety-critical platforms; familiarity with Secure by Design principles; experience applying relevant standards and frameworks (RTCA/EUROCAE, NIST, ISO/IEC, DEFSTAN); and experience with Model-Based Engineering (MBE) tools.
Education and Experience
Typically 5+ years of related work experience or an equivalent combination of technical education and experience, with demonstrated progression of increasing responsibility. A Bachelor’s degree or equivalent in Engineering, Engineering Technology, Computer Science, Engineering Data Science, Mathematics, Physics, or Chemistry is required; an advanced degree is preferred. Relevant security and engineering certifications are strongly preferred.
Working Arrangement
This role is hybrid, requiring 3 days per week on-site. This position does not offer relocation assistance; candidates must live in the immediate area or relocate at their own expense. Employer will not sponsor applicants for employment visa status.
Benefits
Boeing offers a comprehensive benefits package including competitive salary and annual incentive plans, continuous learning opportunities, flexible working arrangements, a diverse and inclusive culture, 23 days plus UK public holidays and a Winter Break, a pension plan with 10% employer contribution, company-paid BUPA Medical Plan, short-term and long-term sickness pay, life insurance, a Learning Together Programme, and access to Well Being Programs.
Equal Opportunity
Boeing is an equal opportunity employer and is committed to a diverse and inclusive workplace. They are a Disability Confident Committed employer and welcome applications from candidates with disabilities, encouraging them to share any accommodation requirements during the recruitment process.