Senior Cybersecurity Engineer – UAS / Defense Systems Employment Type: Full-Time Experience: 7+ Years Industry: Defense / Aerospace / Uncrewed Aircraft Systems (UAS) Level: Senior / Technical Lead Work Environment: Engineering / R&D / Defense Programs Position Overview We are seeking an experienced Senior Cybersecurity Engineer – UAS / Defense Systems to lead cybersecurity engineering activities across the development, integration, testing, and deployment of military-use Uncrewed Aircraft Systems (UAS). This position will be responsible for protecting aircraft, ground-control, communications, payload, embedded-computing, and supporting infrastructure against sophisticated cyber threats. The successful candidate will work closely with software, embedded systems, RF/communications, avionics, systems engineering, flight-test, and program teams to implement security-by-design throughout the UAS product lifecycle. This is a hands-on engineering position requiring significant experience securing complex embedded, aerospace, defense, or other mission-critical systems. Key Responsibilities UAS & Embedded Systems Security - Develop and maintain cybersecurity architectures for military UAS platforms and associated ground systems. - Perform security assessments of flight computers, embedded Linux/RTOS platforms, avionics, payload interfaces, ground-control stations, telemetry systems, and supporting infrastructure. - Define cybersecurity requirements at system, subsystem, hardware, firmware, software, network, and communications levels. - Implement defense-in-depth architectures across aircraft and ground systems. - Evaluate security implications of new hardware, software, firmware, sensors, payloads, and third-party components. - Participate in architecture and engineering design reviews throughout the product lifecycle. Communications & Data-Link Security - Assess and secure RF command-and-control, telemetry, video, payload, and tactical data links. - Develop secure approaches to authentication, encryption, key management, certificate management, and device identity. - Evaluate UAS communication architectures for spoofing, interception, unauthorized access, replay, man-in-the-middle, and other cyber threats. - Support secure network segmentation, VPNs, firewalls, secure protocols, PKI, and Zero Trust principles where applicable. Embedded & Firmware Security - Establish requirements for secure boot, signed firmware, authenticated software updates, hardware root of trust, and secure key storage. - Review embedded Linux, RTOS, firmware, and software architectures for security vulnerabilities. - Work with software and firmware engineering teams to integrate secure-development practices throughout the SDLC. - Support secure configuration and hardening of aircraft and ground-system computing platforms. Threat Modeling & Risk Assessment - Conduct threat modeling, attack-surface analysis, cybersecurity risk assessments, and vulnerability assessments. - Identify credible attack paths against aircraft, communications systems, ground stations, payloads, supply-chain components, and mission systems. - Translate threat intelligence and security findings into engineering requirements and mitigation strategies. - Maintain cybersecurity risk registers and provide technical risk recommendations to engineering and program leadership. Cybersecurity Testing - Develop cybersecurity verification and validation plans. - Conduct or coordinate vulnerability assessments, penetration testing, adversarial testing, configuration reviews, and security audits. - Analyze findings from vulnerability scanners, penetration tests, software-assurance tools, and security testing. - Validate cybersecurity controls in laboratory, integration, flight-test, and operational environments. - Support remediation and verification of identified vulnerabilities. Defense & Aerospace Compliance Support cybersecurity engineering and compliance activities against applicable frameworks and customer requirements, which may include: - NIST Cybersecurity Framework - NIST SP 800-53 - NIST SP 800-171 - NIST Risk Management Framework (RMF) - DO-326A / ED-202A – Airworthiness Security Process - DO-356A / ED-203A – Airworthiness Security Methods and Considerations - DO-355 / ED-204 – Continuing Airworthiness Information Security - FIPS 140-3 - ISO/IEC 27001 - Applicable military, government, airworthiness, export-control, and customer cybersecurity requirements The engineer will assist with cybersecurity documentation, security-control implementation evidence, system-security plans, risk assessments, compliance matrices, security cases, and authorization/certification activities as required by individual programs. Required Qualifications Experience - 7+ years of professional cybersecurity engineering experience, preferably involving defense, aerospace, UAS, avionics, embedded systems, tactical communications, critical infrastructure, or other mission-critical systems. - Demonstrated experience designing or assessing security for complex embedded or cyber-physical systems. - Strong understanding of secure system architecture and defense-in-depth principles. - Experience with cybersecurity risk assessment and threat-modeling methodologies. - Experience conducting or supporting vulnerability assessments and penetration testing. - Experience working within structured systems/software engineering development lifecycles. - Experience translating cybersecurity requirements into practical engineering controls. Technical Knowledge Strong knowledge of several of the following: - Embedded Linux and/or real-time operating systems - Secure boot and hardware root of trust - Firmware security - Code signing - Cryptography and encryption - PKI and certificate management - Secure firmware/software updates - Network segmentation - TCP/IP networking - VPN technologies - Firewalls - Authentication and authorization - Identity and access management - Zero Trust architectures - Secure communications - RF/data-link security - Vulnerability management - Secure SDLC / DevSecOps - Security logging and monitoring - Incident response Experience with UAS command-and-control systems, telemetry, RF communications, GNSS-dependent systems, avionics interfaces, sensors, EO/IR payloads, tactical networks, or ground-control stations is highly desirable. Education Required: Bachelor's degree in one of the following or a closely related technical discipline: - Cybersecurity - Computer Science - Computer Engineering - Electrical Engineering - Software Engineering - Systems Engineering - Aerospace Engineering - Information Security Equivalent combinations of advanced technical education and substantial directly relevant defense/aerospace cybersecurity experience may be considered. Preferred: Master's degree in Cybersecurity, Computer Engineering, Electrical Engineering, Systems Engineering, Aerospace Engineering, Computer Science, or a related discipline. Professional Certifications Candidates should hold at least one recognized senior-level cybersecurity certification, or demonstrate equivalent advanced professional expertise. Highly desirable certifications include: - CISSP – Certified Information Systems Security Professional - ISC2 CGRC – Governance, Risk and Compliance - CompTIA SecurityX (formerly CASP+) - GIAC GICSP – Global Industrial Cyber Security Professional - GIAC GSEC – Security Essentials - ISACA CISM – Certified Information Security Manager - ISC2 CSSLP – Certified Secure Software Lifecycle Professional Additional certifications such as Security+, OSCP, GIAC penetration-testing credentials, CCNP Security, or equivalent technical security credentials are considered assets depending on the candidate's specialization. For positions supporting U.S. Department of Defense programs, certification eligibility appropriate to applicable DoD 8140 work roles may be required. Preferred Defense/UAS Experience Preference will be given to candidates with experience involving one or more of the following: - Military UAS / UAV platforms - Counter-UAS systems - Defense aerospace systems - Avionics cybersecurity - Tactical communications - Command-and-control systems - RF and tactical data links - Embedded flight computers - Ground-control stations - EO/IR and other mission payloads - GNSS-dependent systems - Secure communications - Anti-tamper engineering - Program Protection / Critical Program Information - Classified or controlled defense programs - Government cybersecurity authorization processes - Airworthiness cybersecurity - Systems transitioning from prototype/R&D into production and operational deployment Core Competencies The successful candidate will demonstrate: - Strong systems-level cybersecurity thinking - Ability to understand both cyber and physical consequences of security vulnerabilities - Excellent analytical and troubleshooting skills - Ability to communicate complex cybersecurity risks to engineers and non-technical stakeholders - Strong technical documentation capabilities - Ability to operate effectively within multidisciplinary engineering teams - Sound engineering judgment when balancing cybersecurity, performance, reliability, safety, weight, power, schedule, and mission requirements - Ability to work independently on technically complex and sensitive programs Security & Regulatory Requirements Due to the defense nature of the work, candidates must be able to satisfy all applicable citizenship, controlled-goods, export-control, security-screening, and government security-clearance requirements associated with the programs on which they will work. Eligibility requirements will depend on the jurisdiction, customer, program, and classification level. Why Join Us This position offers the opportunity to directly influence the cybersecurity architecture of next-generation military UAS platforms. You will work at the intersection of cybersecurity, aerospace engineering, embedded systems, autonomous systems, tactical communications, and defense technology, helping ensure that mission-critical systems remain secure and resilient in contested operational environments. Experience Required: 7+ years Position Level: Senior Job Type: Full-Time
Pay: From $120,000.00 per year
Benefits:
- Casual dress
- On-site parking
Work Location: In person