Source description
About the role
As a Senior Product Security Cybersecurity Engineer at our company, you will play a crucial role in enhancing our Product Security team by incorporating cybersecurity practices into the entire lifecycle of our In-Flight Entertainment and Connectivity (IFEC) products. Your responsibilities will include: - Embedding cybersecurity best practices throughout the product development lifecycle, ensuring robust and compliant solutions for our cutting-edge IFEC products and services. - Conducting thorough security testing, such as vulnerability assessments, penetration testing, and evaluations mandated by OEMs like Airbus and Boeing. - Validating testing reports, collaborating with engineering teams to implement secure solutions, and maintaining essential OEM-required security documentation. - Developing and maintaining internal governance materials to promote a culture of compliance and crafting clear engineering tasks based on regulatory, OEM, and industry standards. - Leading cross-functional initiatives to integrate security consistently and staying updated on evolving cybersecurity standards and their impact on IFEC offerings. - Contributing to security reviews, risk assessments, audits, and certifications, driving ongoing improvements in product security, and serving as the main contact with OEM security teams. - Monitoring OEM requirement shifts, implementing strategies for sustained compliance, and championing process improvements in product security governance. We are looking for a candidate with the following qualifications: - Strong foundation in product security principles, risk management, and secure development lifecycles. - Expertise in risk assessment and governance methodologies like EBIOS, ISO 27001, ISO 31000, NIST CSF, and STRIDE. - Familiarity with OEM cybersecurity standards in the aviation or IFEC space, particularly Airbus and Boeing. - Proven experience in leading compliance projects and technical writing for auditable governance documentation. - Solid organizational and project management skills, exceptional communication, and leadership abilities. - Analytical capabilities to interpret and integrate OEM requirements into compliance and governance frameworks. Qualifications: - Bachelor's degree in Computer Science, Cybersecurity, Information Security, Engineering, or related field. - 5+ years of experience in cybersecurity, product security, or compliance roles, preferably in aviation or regulated industries. - Hands-on experience with risk assessments, threat modeling, and governance documentation. - Background in compliance frameworks and technical security documents. - Exposure to OEM requirements, especially Airbus and Boeing standards. - Certifications like CISSP, CSA, ISO 27001 Lead Implementer/Auditor, GIAC GSEC, or equivalents are advantageous. As a Senior Product Security Cybersecurity Engineer at our company, you will play a crucial role in enhancing our Product Security team by incorporating cybersecurity practices into the entire lifecycle of our In-Flight Entertainment and Connectivity (IFEC) products. Your responsibilities will include: - Embedding cybersecurity best practices throughout the product development lifecycle, ensuring robust and compliant solutions for our cutting-edge IFEC products and services. - Conducting thorough security testing, such as vulnerability assessments, penetration testing, and evaluations mandated by OEMs like Airbus and Boeing. - Validating testing reports, collaborating with engineering teams to implement secure solutions, and maintaining essential OEM-required security documentation. - Developing and maintaining internal governance materials to promote a culture of compliance and crafting clear engineering tasks based on regulatory, OEM, and industry standards. - Leading cross-functional initiatives to integrate security consistently and staying updated on evolving cybersecurity standards and their impact on IFEC offerings. - Contributing to security reviews, risk assessments, audits, and certifications, driving ongoing improvements in product security, and serving as the main contact with OEM security teams. - Monitoring OEM requirement shifts, implementing strategies for sustained compliance, and championing process improvements in product security governance. We are looking for a candidate with the following qualifications: - Strong foundation in product security principles, risk management, and secure development lifecycles. - Expertise in risk assessment and governance methodologies like EBIOS, ISO 27001, ISO 31000, NIST CSF, and STRIDE. - Familiarity with OEM cybersecurity standards in the aviation or IFEC space, particularly Airbus and Boeing. - Proven experience in leading compliance projects and technical writing for auditable governance documentation. - Solid organizational and project management skills, exceptional communication, and leadership abilities. - Analytical capabilities to interpret and integrate OEM requirements
More at Antal International