This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
At Boeing, we innovate and collaborate to make the world a better place. We’re committed to fostering an environment for every teammate that’s welcoming, respectful and inclusive, with great opportunity for professional growth. Find your future with us. Boeing Information Digital Technology & Security (IDT&S) is seeking a Senior Cloud Application Security Lifecycle Specialist to join the team in Seattle, WA; North Charleston, SC; Hazelwood, MO; Long Beach, CA; Mesa, AZ; Kent, WA; Plano, TX; or Tukwila, WA. The Cloud and Development Platform team aims to provide consumer services which deliver agility, self-service and automation of compute, network and storage capability to enable business competitiveness and keep Boeing and its partners connected in the most innovative, efficient and effective way. We are looking for passionate individuals to continuously create and sustain the secure operating environment across the cloud service providers (Amazon Web Services (AWS), Azure, Google Cloud Platform (GCP)). This role will work closely with cross-functional teams to define, implement, maintain policies as code, automate policy enforcement, ensure compliance with regulatory standards, and enhance the overall security posture for the cloud platform and hosted workloads.
Job Responsibility
Work closely with product owner, technical integrator, and architect collaborating within agile teams to deliver user story/tasks
Develop Security-first solution architecture, documentation and support infrastructure services deployed on cloud
Assist in the creation of automation solutions
Develop and maintain policies in a code format using tools such as Terraform, Open Policy Agent (OPA), or similar frameworks
Collaborate with security, compliance, and engineering teams to identify policy requirements and translate them into code
Automate policy enforcement and monitoring to ensure compliance with internal and external regulations
Conduct regular audits and assessments of policy implementations to identify gaps and areas for improvement
Create and maintain documentation for policies, procedures, and code implementations
Provide training and support to teams on policy as code practices and tools
Stay updated on industry trends, best practices, and regulatory changes related to policy management and compliance
Create and maintain necessary software design and relevant documentation
Identify Technical Debt and recommendations for removal
Participate in group sessions within developer community and share knowledge
Resolve problems and roadblocks as they occur, consistently following through details while driving innovation as well as issue resolution
Monitor the implementation of architecture throughout the system development lifecycle and seek and provide clarification when needed
Requirements
3+ years of experience with Development Operations (DevOps) or Development Security Operations (DevSecOps)
3+ years of experience with Continuous Integration and Continuous Delivery (CI/CD), deploying to cloud environments
3+ years of experience with cloud-platform technologies (AWS, Azure, GCP)
3+ years of experience with Software Defined Networking and Network Function Virtualization
3+ years of experience with release tools (Azure DevOps, Artifactory, Gitlab, Maven), configuration management, monitoring, virtualization and containerization
1+ years of experience working with technical infrastructure configurations such as servers, databases, networks, development environments, services and software
Experience in Infrastructure as Code (IaC) and CI/CD environments
Nice to have
3+ years of experience with Cloud Infrastructure scripting including ARM/Cloud Formation, Terraform, Node, Python, and PowerShell
3+ years of experience with security compliance tools such as AWS Inspector, AWS Security Hub, AWS Cloud Watch, Google Security Command Center, Microsoft Defender for Cloud, Microsoft Defender for Endpoint, and Azure Monitoring Agent
What we offer
Generous company match to your 401(k)
Industry-leading tuition assistance program pays your institution directly
Fertility, adoption, and surrogacy benefits
Up to $10,000 gift match when you support your favorite nonprofit organizations