Product Security Analyst 2

4 weeks ago


Oklahoma City, United States Boeing Future of Flight Full time

Contract (12 months) Published

2 months

ago CLOSED nessus ACAS SCAP Security + Supports the integration of security and resiliency into products and services throughout the lifecycle of the product/service to meet all applicable certifications and customer requirements. Supports the research, collection, interpretation, test, and analysis of technical data for system-level product security concepts in the projected operational environments to optimize effectiveness over the program lifecycle. Supports product security risk/attack surface/vulnerability analyses and security audits of applications and application stacks of various provenances. Supports the analysis, triage, aggregation, escalation, and reporting of relevant product security and anti-tamper data and other information sources for attack indicators and potential security breaches. Assists in coordination during incidents. Supports the correlation and performance of trend analysis. Analyzes malware and attacker tactics to improve detection capabilities. Prepares and presents basic technical reports and briefings. This position requires an active U.S. Secret Security Clearance (U.S. Citizenship Required). (A U.S. Security Clearance that has been active in the past 24 months is considered active) Basic Qualifications (Required Skills/Experience) (2-3+ years exp): Bachelor’s degree or higher ACTIVE Secret Security Clearance 3+ years’ experience in the aerospace industry Experience performing SCAP scans, ACAS scans, Nessus Scans or similar scans Preferred Qualifications: Security+ (equivalent or higher) certification Experience working on DOD or other classified government systems Position Responsibilities Include: Researches, collects, interprets, tests, and analyzes technical data for system-level product security concepts in the projected operational environments to optimize effectiveness over the program lifecycle. Performs product security risk/attack surface/vulnerability and static code analyses, dynamic code analysis, and security audits of applications and application stacks of various provenances. Analyzes, triages, aggregates, escalates, and reports relevant product security data and other information sources for attack indicators and potential security breaches. Correlates and performs trend analysis. Analyzes malware and attacker tactics to improve detection capabilities. Prepares and presents technical reports and briefings. Additional Position Responsibilities: Support various US, Foreign Military Sales and Direct Military Sales programs The Limited Information Systems Security Officer (LISSO) ensures, on behalf of the Facility Security Officer (FSO) and the Information System Security Manager (ISSM), that the requirements established in the Boeing Security Manual (BSM), the System Security Plan (SSP), and Information System Profile are followed for systems approved for classified operations. Security responsibilities for LISSOs are defined the Boeing Security Manual. The LISSO is delegated to perform ISSO responsibilities for implementing and monitoring procedures applicable to classified operations on an authorized IS. Responsibilities are limited to those identified within this letter which is established by the ISSM. Duties include, but are not limited to, the items listed below: Obtaining guidance from the ISSM in the development of an SSP. Ensuring compliance with all pertinent procedures outlined in the BSM, CSSM, IPSM, and each SSP. Developing and submitting SSP documentation to the ISSM for approval. Controlling access to the IS. This includes physical access, software access, and the validation of security clearances and NTK before allowing access to the system. Designating appropriately cleared personnel to act as escorts for visitors and maintenance personnel when they lack the appropriate clearance level, or NTK for the area being entered or visited, equipment being maintained, or information being processed. Reviewing or designating a knowledgeable person (a qualified and knowledgeable system user) to review the audit trail logs and records in accordance with the approved SSP. When changes are planned or are required for the system, the Limited-ISSO or alternate is responsible for: Initiating a revision to the SSP Submitting the revision to the Information Systems Security Ensuring sufficient lead-time for the reauthorization process to be completed before the revision is implemented for classified operations. Ensuring audit trail logs and records and review documentation are maintained and retained in accordance with the SSP Briefing authorized IS users of their individual responsibilities for safeguarding classified information and the use and protection of the equipment authorized for classified operations. Each IS user and supported person must be briefed before being granted access to an accredited IS and at least annually thereafter. These briefings will include, but are not limited to: The need for sound security practices for protecting information handled by the IS, including all input, storage, and output products. The specific security requirements associated with the IS. The security reporting requirements and procedures in the event of a system malfunction or other security incident. Maintaining an inventory of all approved hardware and software. Coordinating with the ISSM, through the assigned ISSO, to prepare and obtain approval for applicable SSPs before processing any classified information. Reporting any of the following, through the assigned ISSO, to the ISSM: All security incidents or suspected violations of approved procedures. System failure preventing sanitization of system memory or removal of classified information from an IS. Any deviations from approved procedures or knowledge of anything that could result in the compromise of classified information. Obtaining approval from the ISSM before allowing any changes to the system configuration requiring a system SSP update. Obtaining approval from the ISSM when there is a need to connect undocumented test equipment to approved systems while in a classified mode. STIG Checklist Researches, analyzes and compiles technical data to support the integration of security and resiliency into products and services throughout the lifecycle of the product/service to meet all applicable certifications and customer requirements Researches, collects, interprets, tests, and analyzes technical data for system-level product security concepts in the projected operational environments to optimize effectiveness over the program lifecycle Performs product security risk/attack surface/vulnerability analyses and security audits of applications and application stacks of various provenances. Analyzes, triages, aggregates, escalates, and reports relevant product security and anti-tamper data and other information sources for attack indicators and potential security breaches Correlates and performs trend analysis. Analyzes malware and attacker tactics to improve detection capabilities. Prepares and presents technical reports and briefings

#J-18808-Ljbffr



  • Oklahoma City, United States Insight Global Full time

    Title: SOC AnalystLocation: Onsite in Oklahoma City, OKShift: Rotating shift work (6a-2p CST, 2-10p CST, and 10p-6a CST), including Saturdays and Sundays, and rotating every 3 monthsRequired Skills and Experience - Associates or Bachelors Degree in Security or cybersecurity- 1 year of experience within SOC or Cybersecurity- Security+ Certification-...


  • Oklahoma City, United States Insight Global Full time

    Title: SOC AnalystLocation: Onsite in Oklahoma City, OKShift: Rotating shift work (6a-2p CST, 2-10p CST, and 10p-6a CST), including Saturdays and Sundays, and rotating every 3 monthsRequired Skills and Experience - Associates or Bachelors Degree in Security or cybersecurity- 1 year of experience within SOC or Cybersecurity- Security+ Certification-...


  • Oklahoma City, United States Motion Recruitment Partners LLC Full time

    Product Security Engineer Position Overview: We are looking for a skilled and motivated Medical Device Product Security Engineer to play a key role in securing our medical device products throughout their lifecycle. The successful candidate will work closely with cross-functional teams, including product development, quality assurance, and regulatory...


  • Oklahoma City, Oklahoma, United States Two95 International Inc. Full time

    Title: Information Security Risk Analyst Location: Oklahoma City, OK Type: Full-time Salary: DOE Requirement: Under senior staff supervision, assist in information security policy development, maintenance and auditing; security policy education, training, and awareness activities; monitor compliance with security policy and applicable law....


  • oklahoma city, United States BancFirst Corporation Full time

    Operational Security Loss Control AnalystOklahoma City, OK Onsite PositionBancFirst Tower, Downtown Oklahoma City100 N. Broadway Avenue, Oklahoma City, OK 73102Full Time: 1 to 10 or until work is completed M-FPOSITION SUMMARY....


  • Oklahoma City, United States Prosegur Security Usa Inc Full time

    Join Prosegur in an exciting new role as a Physical Security Specialist overseeing a prestigious high-rise building in Irving, Texas. We're seeking a dynamic individual who embodies knowledge, skill, adaptability, and self-motivation. As a Physical Security Specialist, you'll be an invaluable asset, providing leadership and expertise to a team of highly...


  • Jersey City, United States SMBC Group Full time

    The anticipated salary range for this role is between $66,000.00 and $77,000.00. The specific salary offered to an applicant will be based on their individual qualifications, experiences, and an analysis of the current compensation paid in their geography and the market for similar roles at the time of hire. The role may also be eligible for an annual...

  • Senior analyst

    2 days ago


    Oklahoma City, United States HCL Technologies Full time

    Primary Skills: Should have expertise in administrating of SIEM tool such as SPLUNK Security Enterprise as L3 is must ,Should have worked as SOC Lead/Manager ,Expertise in SOAR tools like Cortex XSOAR, Splunk SOAR, IBM SOAR ,Technical certification on security technologies / products like CCSA/ CCSE / CISSP /CCIE Security etc. ,Should be flexible to work in...

  • Sr Security Analyst

    2 days ago


    Michigan City, United States Visionsoft International Full time

    Interviews: In person interviews ONLY - (Y/N) on coversheet.Duration: 1 year with possible extensionPosition location: Dimondale, MI.Hybrid Role with 2 days onsite from day 1 - Flexible days on site. Clear and concise communication skills required.Top Skills & Years of Experience Required:IDS (Intrusion Detection System) 4-8 yearsIOC (Indicators of...


  • Arizona City, United States Verra Mobility Full time

    Who we are… Verra Mobility is a global leader in smart mobility. We develop technology-enabled solutions that help the world move safely and easily. We are fostering the development of safe cities, working with police departments and municipalities to install over 4,000 red-light, speed, and school bus stop arm safety cameras across North America. We are...


  • Arizona City, United States Verra Mobility Full time

    Who we are Verra Mobility is a global leader in smart mobility. We develop technology-enabled solutions that help the world move safely and easily. We are fostering the development of safe cities, working with police departments and municipalities to install over 4,000 red-light, speed, and school bus stop arm safety cameras across North America. We are also...

  • Security Professional

    4 weeks ago


    Traverse City, United States Sterling Security Full time

    Job DescriptionJob DescriptionProfessional Security OfficerDo you have confidence, great communication skills, neat appearance and a positive attitude? Sterling Security LLC has experience that extends over two decades. Some of our services are guard services, facility patrols, site security, event security, greeter services, and secure transportation. We...


  • California City, United States absolute Full time

    Responsibilities of Information Security Analyst Responsible for managing/advising protection on Local Area Networks (LAN) the Wide Area Networks (WAN) firewalls routers Internet gain access to wireless methods Directory Services Network Intrusion Detection Systems (NIDS) Intrusion Protection Systems (IPS) outside communication products as well as...


  • Oklahoma City, United States Teknor Apex Full time

    ** Inventory Control Coordinator / Analyst** **Job Category****:** Warehouse **Requisition Number****:** INVEN001782 Showing 1 location **Job Details** **Description** **Essential Duties and Responsibilities:** Responsible for the coordinating, movement, and reviewing of raw materials for production. Review materials needed for production against inventory...


  • Arizona City, United States Saxon Global Full time

    PUBLIC FACING JOB DESCRIPTION: Job Description: Information Security Analyst - Kubernetes Security American Express is on an exciting Cloud transformation journey led by a high-energy, delivery-focused team delivering security as code and integration to enable on-premise equivalent security models for cloud workloads. The Cloud Security Engineering group...


  • Iowa City, United States Triwave Solutions Full time

    SkillRequired / DesiredAmountof ExperienceSystems Security Certified Practitioner (SSCP), CompTIA Security+ (Security+ CE), CompTIA Cybersecurity Analyst (CSA+) or other information security cRequired6YearsStrong understanding of security technologies and strategies, including but not limited to: firewall, IDS, policy management, security...

  • Data Analyst

    2 weeks ago


    Oklahoma City, United States TechConnectOK Full time

    TechConnect is seeking a Data Analyst for a cutting-edge technology company in Tulsa, OK. Our client is looking for an individual with a proven track record as a data analyst, working with data analysis tools and selection, experience with multiple databases and industry best practices. In this role you need a keen eye for detail as you will create reports,...

  • Product Analyst

    1 month ago


    Jersey City, United States CHUBB Full time

    Senior Product Analyst, Small Commercial  Reporting to the Small Business Workers’ Compensation Line Lead, the Senior Product Analyst, will be accountable for supporting line management to help enable profitable growth of the Small Business WC product. This role will have supporting level responsibilities in both product development and product...


  • Oklahoma City, United States CACI International Inc Full time

    Service Desk AnalystJob Category: Service Contract ActTime Type: Full timeMinimum Clearance Required to Start: SecretEmployee Type: RegularPercentage of Travel Required: NoneType of Travel: None* * * Come join our CACI team to be part of an innovative fast-paced highly technical IT team as a Help Desk Agent in support of the EITaaS contract for the United...


  • Iowa City, United States University of Iowa Full time

    The University of Iowa Health Care department of Safety and Security is seeking a Financial Analyst to be responsible for assigned financial activities for the Department of Safety and Security, which include assisting in budget preparation, financia Financial Analyst, Security, Analyst, Financial Planning, Financial, Senior, Technology