Principal Embedded Systems Security Engineer (Onsite - Cedar Rapids, IA)
$107,500–$204,500 year
On-siteCedar Rapids, Iowa, United States
Job Summary
Lead the security subject matter expert and lead for programs by analyzing systems to identify attack vectors and assess risks for new and existing products. Advise program leaders on including security technologies in strategic roadmaps, ensure proper implementation during development, and develop automated tools for identifying security flaws. Characterize vulnerability assessments, recommend mitigations, and guide adherence to military RMF processes and DO-326A/DO-356A Airworthiness Security standards. Mentor junior engineers and foster organizational adoption of the Avionics SSDLC while participating in industry committees. This onsite role in Cedar Rapids, IA, requires active Secret clearance and 8+ years of embedded systems security experience.
Required Qualifications
- U.S. government issued security clearance
- U.S. citizenship
- Active and existing security clearance
- Active or ability to obtain a SECRET clearance
- Degree in Science, Technology, Engineering or Mathematics (STEM)
- Minimum 8 years prior relevant experience
- Advanced Degree in a related field
- Minimum 5 years of experience (if holding Advanced Degree)
- Experience in product cybersecurity, embedded software engineering, or secure system design
- Embedded software engineering knowledge (Python and Java/C/C++)
- Experience analyzing systems and security architectures
- Relocation assistance availability (implied condition for onsite role in Cedar Rapids, IA)
Desired Qualifications
- Active Secret clearance
- Reviewing system and application vulnerabilities, threat models, and providing mitigations
- Hands-on experience with static analysis and analyzing security impact of code defects
- Executing System & Application Fuzzing / Resiliency Tests
- Analysis experience of SELinux policies for proper process isolation/separation
- Data/network security implementations and understand hardening with Operating Systems
- Experience with system and application penetration testing
- Experience with Public Key Infrastructure (PKI)
- Experience with Military RMF process and RTCA DO-326A / DO-356A
- Security certifications (Sec+, OSCP, CISSP, etc.)
- Networking knowledge (OSI Layers, protocols, etc.)
- Curiosity and desire to continuously learn security concepts
- Willingness to share your knowledge within the organization
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.