Boeing Logo

Boeing

Senior Vulnerability Assessments Specialist - Operational Technology (OT)

Posted 9 Days Ago
Be an Early Applicant
In-Office
Kent, WA
143K-207K Annually
Senior level
In-Office
Kent, WA
143K-207K Annually
Senior level
The Senior Vulnerability Assessments Specialist will assess vulnerabilities in OT systems, drive remediation efforts, collaborate across teams, and produce technical reports, while mentoring junior staff.
The summary above was generated by AI
Job Description
At Boeing, we innovate and collaborate to make the world a better place. We're committed to fostering an environment for every teammate that's welcoming, respectful and inclusive, with great opportunity for professional growth. Find your future with us.
The Boeing Company is currently seeking a Senior Vulnerability Assessments Specialist - Operational Technology (OT) to join the team in Kent, WA; North Charleston, SC; Hazelwood, MO; Mesa, AZ; El Segundo, CA; or Plano, TX.
This role will assess and drive remediation of vulnerabilities that impact OT environments across manufacturing, production, and mission-critical infrastructure.
The ideal candidate brings deep vulnerability lifecycle experience, demonstrated OT/ Industrial Control System (ICS) knowledge, and the ability to translate technical findings into pragmatic remediation and risk-mitigation plans for operational stakeholders.
Position Responsibilities:
  • Develop and execute vulnerability management processes for OT/ICS environments, including networked controllers, Human-Machine Interfaces (HMIs), Programmable Logic Controllers (PLCs), Supervisory Control and Data Acquisition (SCADA) systems, and supporting enterprise infrastructure
  • Execute enterprise processes for emergent vulnerabilities
  • Evaluate risk and recommend prioritized mitigation or remediation actions
  • Perform detailed exploitability and impact analysis that factors threat context, asset criticality, environmental constraints, and existing controls
  • Drive remediation and risk reduction efforts end-to-end: develop mitigation plans, coordinate with engineering/operations teams, track remediation progress, and report burndown to stakeholders
  • Collaborate with cross-functional security, Information Technology (IT), engineering, and operations teams to operationalize new capabilities and harden OT systems
  • Produce clear, actionable technical reports and stakeholder narratives tailored to technical teams, line-of-business owners, and senior leadership
  • Maintain and improve assessment methodologies, playbooks, and automation to raise first-time quality and repeatability
  • Mentor junior team members, review technical analyses, and contribute to continuous improvement of vulnerability management processes

Basic Qualifications (Required Skills/Experience):
  • 5+ years of experience with leading Incident Response and/or Vulnerability Management activities
  • 3+ years of experience in penetrating testing and vulnerability assessments using manual techniques and vulnerability testing tools (including scanners, sniffers, fuzzers and exploit tools such as Burp, Nmap, Kali and Metasploit)
  • 3+ years of experience with vulnerability scanning tools and formats (e.g., Nessus, Qualys, Tenable, Rapid7, Snyk, Veracode, or Burp)
  • 3+ years of experience in performing system administration tasks on Windows and Linux hosts including installing security patches and making configuration changes to support security requirements
  • Experience with analytical skills in data, with ability to identify gaps in roll out of tools, processes and application of skills in tools within the areas of vulnerability management and endpoint controls
  • Working knowledge of vulnerability and risk management frameworks, ratings, and contextualizing data based on risk (e.g., CVSS, CVE, NVD, etc)

Preferred Qualifications (Desired Skills/Experience):
  • Bachelor's degree or higher
  • Active certifications including Global Industrial Cyber Security Professional (GICSP), Global Information Assurance Certification (GIAC) GICSP/Generic Routing Encapsulation (GRE)/GIAC Continuous Monitoring Certification (GMON), Certified Information Systems Security Professional (CISSP), Certified Red Team Professional (CRTP), or equivalent OT/ICS security credentials
  • Experience evaluating exploitability and recommending mitigations that are operationally feasible in production OT environments
  • Experience with strong written and verbal communication skills with the ability to convey technical risk to non-technical stakeholders and drive cross-functional decisions
  • Experience being self-directed, adaptable to ambiguity, comfortable working under pressure, and able to operate with minimal guidance when needed
  • Experience speaking up, contributing to cross-functional discussions, and collaborating effectively to reach resolution
  • Experience with OT/ICS domain knowledge (Programmable Logic Controller (PLC)/ Remote Terminal Unit (RTU)/HMI architectures, common vendors/protocols such as Modbus, DNP3, OPC, BACnet)
  • Experience with industrial network segmentation, OT-safe scanning, and safe testing practices in production environments
  • Experience working with National Institute of Standard Technology (NIST) security controls and frameworks (e.g., NIST CSF, SP 800-82 for ICS security)
  • Experience working with Cloud and container security for hybrid OT/IT environments
  • Experience building or operating vulnerability management platforms and custom integrations (ingestion, correlation, ticketing)
  • Experience contributing to enterprise-wide control effectiveness and resilience

Conflict of Interest:
Successful candidates for this job must satisfy the Company's Conflict of Interest (COI) assessment process.
Drug Free Workplace:
Boeing is a Drug Free Workplace where post offer applicants and employees are subject to testing for marijuana, cocaine, opioids, amphetamines, PCP, and alcohol when criteria is met as outlined in our policies.
Pay & Benefits:
At Boeing, we strive to deliver a Total Rewards package that will attract, engage and retain the top talent. Elements of the Total Rewards package include competitive base pay and variable compensation opportunities.
The Boeing Company also provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work.
The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, and the applicability of collective bargaining agreements.
Pay is based upon candidate experience and qualifications, as well as market and business considerations.
Summary pay range: $142,800 - $207,000
Applications for this position will be accepted until Mar. 20, 2026
Export Control Requirements:
This position must meet U.S. export control compliance requirements. To meet U.S. export control compliance requirements, a "U.S. Person" as defined by 22 C.F.R. §120.62 is required. "U.S. Person" includes U.S. Citizen, U.S. National, lawful permanent resident, refugee, or asylee.
Export Control Details:
US based job, US Person required
Relocation
Relocation assistance is not a negotiable benefit for this position.
Visa Sponsorship
Employer will not sponsor applicants for employment visa status.
Shift
This position is for 1st shift
Equal Opportunity Employer:
Boeing is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, genetic factors, military/veteran status or other characteristics protected by law.

Top Skills

Burp)
Industrial Control System (Ics)
Kali
Metasploit)
Nmap
Operational Technology (Ot)
Programming Languages (Not Specified But May Include Scripting For Automation)
Qualys
Rapid7
Security Tools (Burp
Snyk
Tenable
Veracode
Vulnerability Scanning Tools (Nessus

Boeing Bellevue, Washington, USA Office

3265 160th Ave SE, Bellevue, WA, United States, 98008

Similar Jobs at Boeing

20 Hours Ago
In-Office
99K-198K Annually
Senior level
99K-198K Annually
Senior level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
Support design, integration, testing, certification, and lifecycle management of KC-46 mission avionics subsystems. Develop and verify requirements, create test plans, coordinate suppliers and specialty IPTs, troubleshoot hardware/software, and support FAA/military certification and export control compliance.
Top Skills: AvionicsCommunication SystemsCybersecurityData NetworksFaa CertificationFlight Management SystemsHardware/Software IntegrationLine Replaceable Units (Lrus)Military CertificationMission Control SystemsNavigation SystemsRfSoftware Development Processes
Yesterday
In-Office
118K-173K Annually
Expert/Leader
118K-173K Annually
Expert/Leader
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
The Business Operations Specialist role involves project and portfolio management, executive communication, safety management oversight, and cross-functional integration to drive enterprise outcomes at Boeing.
Top Skills: ExcelMS OfficePowerPoint
Yesterday
In-Office
102K-138K Annually
Mid level
102K-138K Annually
Mid level
Aerospace • Information Technology • Software • Cybersecurity • Design • Defense • Manufacturing
The HRBP collaborates with management to provide HR support, drive business value, and enhance employee experience through effective policies and processes.
Top Skills: AnalyticsHr PoliciesProject Management

What you need to know about the Seattle Tech Scene

Home to tech titans like Microsoft and Amazon, Seattle punches far above its weight in innovation. But its surrounding mountains, sprinkled with world-famous hiking trails and climbing routes, make the city a destination for outdoorsy types as well. Established as a logging town before shifting to shipbuilding and logistics, the Emerald City is now known for its contributions to aerospace, software, biotech and cloud computing. And its status as a thriving tech ecosystem is attracting out-of-town companies looking to establish new tech and engineering hubs.

Key Facts About Seattle Tech

  • Number of Tech Workers: 287,000; 13% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Amazon, Microsoft, Meta, Google
  • Key Industries: Artificial intelligence, cloud computing, software, biotechnology, game development
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Madrona, Fuse, Tola, Maveron
  • Research Centers and Universities: University of Washington, Seattle University, Seattle Pacific University, Allen Institute for Brain Science, Bill & Melinda Gates Foundation, Seattle Children’s Research Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account