This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
At Boeing, we innovate and collaborate to make the world a better place. We’re committed to fostering an environment for every teammate that’s welcoming, respectful and inclusive, with great opportunity for professional growth. Find your future with us. The Boeing Company is currently seeking Open Source Security Compliance Engineer, (Experienced or Senior) (Virtual)to support ourOpen Source Program Office located inOrlando, Florida(Virtual).This position will focus on supporting the Products and Capabilities team. The Open Source Program Office’smission is to champion open-source engagement across the enterprise and deliver a world class open-source management experience with flawless compliance.To fulfill that mission, we are looking for a Software Security Engineer to evaluate and mitigate security risks within the enterprise’s use and contribution of open-source software, perform product security risk, vulnerability analyses, and security audits. The individual selected will also be automating security assessments and translating the Chief Engineer's strategic security analysis (risk assessments, policy definitions) into automated and integrated open-source security practices for the rest of the company.
Job Responsibility:
Operationalize the open-source policy and process through automation
Independently investigate, analyze, and resolve licensing issues, driving for business-based outcomes
Automate Software Composition Analysis (SCA) through a combination of COTS, open source, and in-house tooling. Conduct trade studies and work with Product Owners to meet requirements for a broad range of stakeholders
Manage the configuration and output of dependency scanners, triage critical open-source software vulnerabilities, and ensure timely remediation with development teams
Translate approved legal/license policies into code-based checks and automated tooling to prevent incompatible license usage in new projects
Engineer and maintain security and license scanning tools
enforce compliance by ensuring automated build failures upon policy violation
Document all automated processes and serve as the technical liaison, transferring security analysis into scalable, repeatable engineering practices across the enterprise
Collaborate with the Product Owner on the backlog and technical roadmap
Seek out additional automation opportunities
Track and improve KPIs
Requirements:
1+ years’ experience with software licensing and knowledge of issues with the use of third party and open-source software
2+ years’ experience in the application of software cybersecurity principles and techniques
3+ years’ experience in software development lifecycle
Ability to obtain a U.S. Security Clearance for which the U.S. Government requires U.S. Citizenship
Bachelor of Science degree from an accredited course of study in engineering, engineering technology, chemistry, physics, mathematics, data science, or computer science
Nice to have:
Ability to independently make and execute Software product level licensing decisions
Ability to interact effectively with Legal, Ethics, and Program Management
Previous experience performing license assessments and working licensing issues
Excellent communication skills, both verbal and written
What we offer:
Generous company match to your 401(k)
Industry-leading tuition assistance program pays your institution directly
Fertility, adoption, and surrogacy benefits
Up to $10,000 gift match when you support your favorite nonprofit organizations