The Embedded Cybersecurity Engineer II will help strengthen the security of embedded systems used in AeroVironment products. This onsite role works with R&D and Operations to apply security controls, support activities across the development lifecycle, and help meet relevant contract and regulatory requirements.
Location
Moorpark, CA (onsite)
Compensation
USD 82,000 - 125,000 per year
Role Overview
The Embedded Cybersecurity Engineer II addresses embedded system security within AeroVironment products. The position coordinates with engineering teams to implement security controls, identify security needs across embedded hardware and software components, support incident response and vulnerability assessments, and provide security-related deliverables for regulatory bodies and contracts.
Responsibilities
- Collaborate with product R&D teams to support a security mindset and guide implementation of security controls aligned to product and system needs.
- Coordinate with Electrical and Hardware engineering to ensure security requirements are incorporated into hardware selection and design.
- Support embedded system architects and developers to ensure implemented security controls align with intended design.
- Help ensure consistent embedded system security practices are applied across projects.
- Coordinate with SW developers and manufacturing engineering to ensure security needs are met through implementation.
- Identify embedded security needs spanning hardware, firmware, software, and microprocessors.
- Support selection of hardware components, third-party software, security tools, and vendors; identify security vulnerabilities and weaknesses in system design and architecture.
- Contribute to tools, processes, and policies intended to prevent, detect, and resolve recurring issues across the development lifecycle, including supply chain and manufacturing.
- Conduct embedded product and device cybersecurity activities, including incident response, vulnerability assessments, and mitigation implementation.
- Continuously evaluate the effectiveness of cybersecurity controls once implemented.
- Implement new approaches and countermeasures for emerging embedded threats.
- Provide security-related deliverables for regulatory bodies and contracts.
- Assess software applications and control procedures.
- Other duties as assigned.
Required Qualifications
- Bachelor’s degree required in Cybersecurity, Electrical or Computer Engineering, Computer Science, or a similar or related field, or equivalent combination of education, training, and experience.
- Two years of experience in cybersecurity and embedded hardware.
- CompTIA Security+, GIAC Security Essentials (GSEC), or equivalent verifiable credentialed certification.
- Strong written and verbal communication skills.
- Strong analytical, time management, and organizational skills.
- Strong computer skills and proficiency with office software and productivity tools.
- Ability to work with little or no supervision and exercise independent judgment on a regular basis.
- Ability to gain cooperation from others and conduct presentations of technical information concerning specific projects or schedules.
- Computer Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), CompTIA Advanced Security Practitioner (CASP), or equivalent verifiable credentialed certification.
- Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OCSP), or equivalent verifiable credentialed certification.
- Experience achieving ISO 27001 certification.
- Experience complying with NIST Cybersecurity standards and guidance.
- Experience complying with the National Industrial Security Program Operating Manual (NISPOM).
- Experience in one or more technical areas, including:
- Wireless and/or network communications
- Basic knowledge of common hardware components, packaging, and PCBA-level integration
- Basic knowledge of common cryptographic algorithms and protocols, including implementation attacks (side-channel and fault injection)
- Hardware security implementation analysis and exploitation (cryptography, side-channel analysis, and/or fault injection)
- Testing and validation of cybersecurity control implementation using manual methods and automated tools (e.g., ACAS, Tenable.sc, Nessus, Nexpose)
Cybersecurity and Security Tools
- CompTIA Security+, GIAC Security Essentials (GSEC)
- CISSP, CISM, CompTIA Advanced Security Practitioner (CASP)
- Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OCSP)
- ISO 27001
- NIST Cybersecurity standards and guidance
- NISPOM
- ACAS, Tenable.sc, Nessus, Nexpose
Benefits
- Medical, dental, and vision
- 401K with company matching
- 9/80 work schedule
- Paid holiday shutdown
Physical Demands
- Ability to sit, stand, stoop, reach, lift (up to 25 lbs.), bend, etc.
- Hand and wrist dexterity to utilize a computer.
- May require travel to sites/program and special functions.
Environmental Conditions
- Office environment with climate control via central air conditioning/heating.
- Occasional work on the production floor may be required.
- May have some exposure to outside environment while traveling.
Clearance and Special Requirements
- U.S. Citizen
- Must be able to travel within the Continental U.S. and internationally when required.
- Must have a DoD Secret security clearance or be eligible to obtain one.
Clearance Level
Secret
ITAR / EAR Compliance
- This position requires access to information subject to compliance with the International Traffic Arms Regulations (ITAR) and/or the Export Administration Regulations (EAR).
- Applicants must qualify as a U.S. person under ITAR and EAR, or be approved for an export license by the governing agency.
- A “U.S. person” under ITAR includes U.S. citizens, U.S. lawful permanent residents (green card holders), or protected individuals such as refugees or asylees (see 22 CFR § 120.15).
- Some positions will require current U.S. citizenship due to contract requirements.
- ITAR: U.S. Citizenship required; must be willing to work on government contracts and have the ability to obtain a security clearance.