採用
Job Description Summary
We are currently recruiting for a Senior Product Cyber Security Engineer. This role will collaborate with GE Aerospace Avionics development teams to drive threat modelling exercises, lead security-focused architecture and code reviews, perform security tests, and validate security designs across numerous embedded GE Aerospace Avionics products. You will be a development security evangelist and will provide thought leadership & help guide developers in secure product development practices. The successful candidate will be a highly skilled Engineer who has a passion for security work and collaborating with product managers and developers to drive the successful adoption of innovative methods in developing secure applications.
Job Description
Essential Responsibilities:
In this role, you will:
- Supporting product development teams and project execution related activities in support of customer and regulatory product cybersecurity requirements
- Define embedded product cybersecurity objectives, analyze product architectures for security vulnerabilities, evaluate threats and define threat vectors, qualitatively assess cybersecurity risk, define and manage product cybersecurity requirements, coordinate and conduct cybersecurity test activities to verify cybersecurity requirements, and support regulatory certification responses ensuring continued airworthiness
- Coach product development teams on secure design principles, development practices, and product hardening.
- Perform Threat Modelling and Architecture Risk Analysis on products.
- Perform Security Code Reviews, Vulnerability Analysis and research on application code.
- Coach and mentor developers to write and implement cryptography (PKI, Code Signing, etc)
- Guide developers to write secure code and implement secure engineering practices.
- Provide response for security related incidents reported for software products.
- Engage subject matter experts in successful transfer of complex domain knowledge
- Provide guidance and advise on writing secure code that meets standards and delivers desired functionality using the technology selected for the project.
- Audit and exploit applications and systems under development to expose vulnerabilities, and demonstrate possible fixes.
- Analyze and validate completed security improvements and CVE patches.
Minimum Qualifications:
- Bachelor’s degree from accredited university or college with minimum of 5 years of professional experience OR Associates degree with minimum of 8 years of professional experience OR High School Diploma with minimum of10 years of professional experience
- Minimum 5 years of professional experience in embedded systems and applications.
- Note: Military experience is equivalent to professional experience
Due to the nature of the role you will need to be able to meet the below criteria:
- Eligibility to work in the U.S without restriction.
- Possess or are eligible to obtain DOD clearance
- Travel - up to 5%
Eligibility Requirement:
- Legal authorization to work in the U.S. is required. We will not sponsor individuals for employment visas, now or in the future, for this job.
Preferred Requirements:
- Experience within an Engineering function.
- Bachelor’s degree in computer engineering or in a STEM major (SCIENCE, TECHNOLOGY, ENGINEERING, OR MATH) or equivalent experience.
Desired Characteristics:
- Proficiency in at least one programming language (Java, Node.JS, Python, or C/C++)
- Experience conducting static code reviews and applying security auditing and/or penetration testing principles and tools.
- Knowledge of secure architecture and design principles
- Knowledge of Risk Controls frameworks and procedures (DO-326A, NIST CSF, DOD RMF, NIST800-53, etc.).
- Solid understanding of computer architecture, especially the hardware components, software stack and protocols.
- Experience in security technologies like TPM, Secure Boot, Code Signing, Encryption, etc. This may overlap with experience in embedded systems.
- Solid understanding of applied cryptography fundamentals (Encryption, Authentication, Symmetric Cryptography, Asymmetric Cryptography etc)
- Knowledge/awareness of OWASP Web/API vulnerabilities (CSRF, XSS, SQLI, etc.) and compensating controls.
This role requires access to U.S. export-controlled information. Therefore, employment will be contingent upon the ability to prove that you meet the status of a U.S. Person as one of the following: U.S. lawful permanent resident, U.S. Citizen, have been granted asylee or refugee status (i.e., a protected individual under the Immigration and Naturalization Act, 8 U.S.C. 1324b(a)(3)).
Additional Information
GE Aerospace offers a great work environment, professional development, challenging careers, and competitive compensation. GE Aerospace is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status or other characteristics protected by law.
GE Aerospace will only employ those who are legally authorized to work in the United States for this opening. Any offer of employment is conditioned upon the successful completion of a drug screen (as applicable).
Relocation Assistance Provided: Yes
Total Views
0
Apply Clicks
0
Mock Applicants
0
Scraps
0
Similar Jobs

Cyber Security Third Party Risk Manager (United Kingdom)
Luxoft (DXC) · GBR - ANY CITY

Senior Staff Cloud Security Engineer (HYBRID)
GEICO · 3 Locations

Security Incident Handler
Airbus · Getafe Area

Senior Systems Security Engineer (Anti-Tamper/Program Protection) P3 (Onsite)
Collins Aerospace (RTX) · US-MA-MARLBOROUGH-MA2 ~ 1001 Boston Post Rd ~ BLDG 2

Sr Anlyst Security - Tucson, AZ
Collins Aerospace (RTX) · US-AZ-TUCSON-M05 ~ 1151 E Hermans Rd ~ BLDG M05 (External Site)
About General Electric
Reviews
3.5
5 reviews
Work Life Balance
3.8
Compensation
3.2
Culture
3.1
Career
3.4
Management
2.8
55%
Recommend to a Friend
Pros
Good career development programs (FMP, CAS)
Above-average salary and compensation
Better work-life balance
Cons
Concerns about long-term company viability
Competitive up-or-out culture in programs
Uncertainty about software development management
Salary Ranges
24 data points
Staff/L6
Staff/L6 · Staff Data and Information Architect
1 reports
$191,880
total / year
Base
$147,600
Stock
-
Bonus
-
$191,880
$191,880
Interview Experience
5 interviews
Difficulty
2.8
/ 5
Duration
14-28 weeks
Offer Rate
20%
Experience
Positive 20%
Neutral 40%
Negative 40%
Interview Process
1
Application Review
2
Recruiter/HR Screen
3
Hiring Manager Interview
4
Final Interview Round
5
Offer Decision
Common Questions
Behavioral/STAR
Technical Knowledge
Past Experience
Culture Fit
News & Buzz
Do Flat 2026 Margins Eclipse GE’s 2025 Earnings Strength And Contract Wins (GE)? - simplywall.st
Source: simplywall.st
News
·
5w ago
General Electric unveils brand names as it plans split to three new future companies - Campaign Asia
Source: Campaign Asia
News
·
5w ago
I did it! San Francisco, CA $1.2m 5.875
I technically closed a few weeks ago but I am still celebrating (and just found this community hehe) The house needs some work which I am already deep into. The entire top floor needed to have electrical replaced because it had knob and tube wiring which is exceptionally common for old houses in th
·
5w ago
·
6,582
·
780
What happened after GE moved its HQ out of Connecticut 10 years ago - CT Insider
Source: CT Insider
News
·
5w ago
