Pittsburgh, PA (onsite) is the backdrop for this Senior Aerospace Cybersecurity Engineer (Hardware) role, where you will help shape cybersecurity outcomes for aerospace and defense programs. The position combines hands-on technical work with customer-facing collaboration, supporting hardware security and compliance across embedded systems, controllers, and aircraft platforms.
As a senior engineer with aerospace-focused experience, you will lead key cybersecurity activities end-to-end, from threat modeling and security architecture reviews to testing, vulnerability assessments, and support for secure development processes.
Responsibilities
- Lead cybersecurity activities for aerospace and avionics programs.
- Perform threat modeling, risk assessments, and security architecture reviews.
- Support secure software development, including code signing, cryptography, secure boot, and secure firmware update processes.
- Conduct cybersecurity testing, vulnerability assessments, and penetration testing.
- Define cybersecurity measures for aerospace embedded systems, controllers, and aircraft platforms.
- Support compliance with aerospace and federal cybersecurity requirements.
- Review customer requirements, RFIs/RFQs, and contribute to proposal development.
- Interface with customers, federal contractors, and internal engineering teams.
- Support lab-based testing and occasional on-site assessments at customer and aircraft locations.
Requirements
- 8+ years of cybersecurity engineering experience.
- 3+ years of aerospace cybersecurity experience.
- Aerospace threat modeling and risk assessments.
- Embedded systems security.
- Cryptography and code signing.
- Vulnerability management.
- Secure Development Lifecycle (SDLC).
- Hardware security and root-of-trust concepts.
- Familiarity with aerospace cybersecurity standards such as DO-326A / ED-202A, DO-356A, NIST Cybersecurity Framework, and FIPS 140-3.
- Experience supporting ITAR-controlled and/or federal aerospace programs.
Tools & Technologies
- DO-326A / ED-202A, DO-356A
- NIST Cybersecurity Framework
- FIPS 140-3
- Secure Development Lifecycle (SDLC)
- Cryptography, code signing
- Secure boot, secure firmware update processes
- Threat modeling, risk assessments, penetration testing
- Vulnerability management, root-of-trust concepts
- ITAR
Preferred Qualifications
- Experience supporting FAA, DoD, defense, or commercial aerospace programs.
- Knowledge of aircraft control systems, avionics, and aerospace hardware security architectures.