Lead cybersecurity strategy and implementation for all-electric vertical takeoff and landing (eVTOL) aircraft, ensuring compliance with aviation cybersecurity standards and maintaining robust security across flight-critical systems.
Responsibilities
- Serve as a principal cybersecurity engineer on a high-performance team, applying deep expertise in embedded safety-critical systems and compliance with RTCA DO-326B, DO-355A, DO-356A, ISO27001, and ASTM F3532-22.
- Contribute to the development and documentation of cybersecurity planning, including security certification, threat environment definition, risk management, verification strategies, and continued airworthiness.
- Conduct cybersecurity assessments involving data flow analysis, identification of data and control coupling, development of threat scenarios based on Aircraft Functional Hazard Assessment, and creation of Preliminary Security Risk Assessments.
- Support the definition of aircraft-level security architecture to ensure comprehensive protection of critical systems.
- Assist in designing ground-based security infrastructure, such as Public Key Infrastructure (PKI), to support secure operations.
- Validate layered security architectures using techniques like common mode analysis to identify potential single points of failure.
- Evaluate security controls and measure their effectiveness through defined metrics and analytical methods.
- Define cybersecurity requirements based on identified security measures and architectural decisions.
- Oversee system-level cybersecurity across key subsystems including platform software, flight controls, motor control, battery management, displays, communications, navigation, and surveillance.
- Verify cybersecurity requirements using formal analysis or blue team testing methodologies.
- Manage red team testing initiatives to simulate adversarial attacks and assess system resilience.
- Develop and maintain cybersecurity documentation, processes, and policies, including conducting supplier audits and assessments.
- Collaborate with certification authorities to support cybersecurity aspects of aircraft certification.
- Promote team collaboration and support professional growth and development within the cybersecurity team.
Requirements
- Minimum of 10 years of professional experience in a relevant cybersecurity or engineering field.
- Bachelor of Science degree in Cybersecurity, Electrical Engineering, Computer Engineering, Computer Science, or a related technical discipline.
- Proven experience working through full systems and software development life cycles in regulated industries.
- Demonstrated cybersecurity mindset with attention to threat modeling and risk mitigation.
- Excellent organizational abilities and strong communication skills, both written and verbal.
Nice to Have
- Hands-on experience with DevOps practices and tools.
- Practical knowledge of Site Reliability Engineering principles.
- Experience managing third-party suppliers and vendor cybersecurity compliance.
- Familiarity with Agile development methodologies.
- Proficiency in applying the ISO27000 family of standards.
- Experience working within AS9100 quality management systems.
- Holding a CISSP certification is preferred.
Tech Stack
RTCA DO-326B, DO-355A, DO-356A, ISO27001, ASTM F3532-22, isograph, CVE database
Benefits
- Performance-based compensation structure
- Base pay range targeted between $220,000 and $290,000
- Commitment to fostering an equitable and inclusive workplace
- Active support and recognition of all team members
Compensation
Target base pay between $220,000 - $290,000
Work Arrangement
onsite — San Jose, California
Team
Principal-level contributor on a world class cybersecurity team focused on embedded safety-critical systems
- Diversity and inclusivity in the workplace
- Equitable and inclusive environment
- Embraces differences
- Supports and celebrates all team members
- Pay-for-performance culture
Additional Information
- Work visa sponsorship is not currently available for this position.
- Reasonable accommodations are provided for job applicants with disabilities or sincerely held religious beliefs.
- Employment decisions are based on merit, qualifications, and business needs.
- External recruiting agencies are not engaged without prior written agreement.
- Candidate application data is handled in accordance with the Candidate Privacy Policy.
