Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior Cloud Application Security Lifecycle Specialist image - Rise Careers
Job details

Senior Cloud Application Security Lifecycle Specialist

Senior Cloud Application Security Lifecycle Specialist

Company:

The Boeing Company

Boeing Information Technology & Data Analytics (IT&DA) is seeking a Senior Cloud Application Security Lifecycle Specialist to join the team in either Seattle, WA; North Charleston, SC; Hazelwood, MO; or Mesa, AZ.

The Cloud and Development Platform team aims to provide a consumer like services which deliver agility, self-service and automation of compute, network and storage capability to enable business competitiveness and keep Boeing and its partners connected in the most innovative, efficient and effective way.

We are looking for passionate individuals to continuously create and sustain the secure operating environment across the cloud service providers (AWS, Azure, GCP). This role will work closely with cross-functional teams to define, implement, maintain policies as code, automate policy enforcement, ensure compliance with regulatory standards, and enhance the overall security posture for the cloud platform and hosted workloads.

Position Responsibilities:

  • Partner with product owner, technical integrator, and architect collaborating within agile teams to deliver complex and highly complex technical user story/tasks

  • Security-first development of solution architecture, documentation and support infrastructure services deployed on cloud

  • Design, develop, and implement advanced technical automation solutions

  • Develop and maintain policies in a code format using tools such as Terraform, Open Policy Agent (OPA), or similar frameworks

  • Collaborate with security, compliance, and engineering teams to identify policy requirements and translate them into code

  • Automate policy enforcement and monitoring to ensure compliance with internal and external regulations

  • Conduct regular audits and assessments of policy implementations to identify gaps and areas for improvement

  • Create and maintain documentation for policies, procedures, and code implementations

  • Provide training and support to teams on policy as code practices and tools

  • Stay updated on industry trends, best practices, and regulatory changes related to policy management and compliance

  • Create and maintain necessary software design and relevant documentation

  • Provide suggestions in identifying Technical Debt and make recommendations for removal

  • Participate in group sessions within developer community and share knowledge

  • Resolve problems and roadblocks as they occur, consistently following through details while driving innovation as well as issue resolution

  • Monitor the implementation of architecture throughout the system development lifecycle and seek and provide clarification when needed

Basic Qualifications (Required Skills/Experience):         

  • 5+ years of experience with Development Operations (DevOps) or Development Security Operations (DevSecOps)

  • 5+ years of experience with Continuous Integration and Continuous Delivery (CI/CD), deploying to cloud environments

  • 5+ years of experience with cloud-platform technologies (AWS, Azure, GCP)

  • 5+ years of experience with Software Defined Networking and Network Function Virtualization

  • 5+ years of experience with release tools (Azure DevOps, Artifactory, Gitlab, Maven), configuration management, monitoring, virtualization and containerization

  • 3+ years of experience working with technical infrastructure configurations such as servers, databases, networks, development environments, services and software

  • Experience in Infrastructure as Code (IaC) and CI/CD environments

Preferred Qualifications (Desired Skills/Experience):

  • 5+ years of experience with Cloud Infrastructure Scripting including ARM/Cloud Formation, Terraform, Node, Python, and PowerShell

  • 5+ years of experience with security compliance tools such as AWS Inspector, AWS Security Hub, AWS Cloud Watch, Google Security Command Center, Microsoft Defender for Cloud, Microsoft Defender for Endpoint, and Azure Monitoring Agent

Drug Free Workplace:

Boeing is a Drug Free Workplace where post offer applicants and employees are subject to testing for marijuana, cocaine, opioids, amphetamines, PCP, and alcohol when criteria is met as outlined in our policies.

Pay & Benefits:

At Boeing, we strive to deliver a Total Rewards package that will attract, engage and retain the top talent. Elements of the Total Rewards package include competitive base pay and variable compensation opportunities.

The Boeing Company also provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work.

The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, and the applicability of collective bargaining agreements.

Pay is based upon candidate experience and qualifications, as well as market and business considerations.

Summary pay range: $148,750 - $215,050

Language Requirements:

Not Applicable

Education:

Not Applicable

Relocation:

Relocation assistance is not a negotiable benefit for this position.

Export Control Requirement:

This position must meet export control compliance requirements. To meet export control compliance requirements, a “U.S. Person” as defined by 22 C.F.R. §120.15 is required. “U.S. Person” includes U.S. Citizen, lawful permanent resident, refugee, or asylee.

Safety Sensitive:

This is not a Safety Sensitive Position.

Security Clearance:

This position does not require a Security Clearance.

Visa Sponsorship:

Employer will not sponsor applicants for employment visa status.

Contingent Upon Award Program

This position is not contingent upon program award

Shift:

Shift 1 (United States of America)

Stay safe from recruitment fraud! The only way to apply for a position at Boeing is via our Careers website. Learn how to protect yourself from recruitment fraud - Recruitment Fraud Warning

Boeing is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, physical or mental disability, genetic factors, military/veteran status or other characteristics protected by law.

EEO is the law

Boeing EEO Policy

Request an Accommodation

Applicant Privacy


Boeing Participates in E – Verify

Right to Work Statement

Boeing Glassdoor Company Review
3.9 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Boeing DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Boeing
Boeing CEO photo
David Calhoun
Approve of CEO

Average salary estimate

$181900 / YEARLY (est.)
min
max
$148750K
$215050K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior Cloud Application Security Lifecycle Specialist, Boeing

Are you ready to take your IT career to new heights? The Boeing Company is looking for a Senior Cloud Application Security Lifecycle Specialist to bolster our Cloud and Development Platform team! Based in vibrant locations like Seattle, WA, North Charleston, SC, Hazelwood, MO, or Mesa, AZ, you'll play a crucial role in creating a secure operating environment across top cloud service providers like AWS, Azure, and GCP. In this position, you'll collaborate with agile teams alongside product owners, technical integrators, and architects, ensuring security-first development of solution architecture. With over 5 years of experience in Development Operations or Development Security Operations, you’ll design, implement, and maintain code-based policies to ensure compliance with industry standards. Your advanced technical automation solutions will help automate policy enforcement and streamline security measures. You’ll also conduct regular audits, provide training to your teammates, and stay up-to-date with industry trends. At Boeing, we believe in rewarding our talent with a comprehensive benefits package and a dynamic work atmosphere. If you’re passionate about cloud security and eager to drive innovation while working on cutting-edge technologies, Boeing is the place for you!

Frequently Asked Questions (FAQs) for Senior Cloud Application Security Lifecycle Specialist Role at Boeing
What are the responsibilities of a Senior Cloud Application Security Lifecycle Specialist at Boeing?

At Boeing, a Senior Cloud Application Security Lifecycle Specialist is responsible for a variety of tasks, including collaborating with agile teams to implement security-first architectural solutions. You will develop and maintain code-based policies using automation tools, monitor compliance with internal and external regulations, and conduct system audits to identify opportunities for improvement. You will also play a key role in educating teams on policy management best practices, ensuring that the entire organization remains aligned with evolving security standards.

Join Rise to see the full answer
What qualifications do I need to become a Senior Cloud Application Security Lifecycle Specialist at Boeing?

To qualify as a Senior Cloud Application Security Lifecycle Specialist at Boeing, candidates should have a minimum of 5 years of experience in Development Operations or Development Security Operations, as well as expertise in cloud platforms like AWS, Azure, and GCP. Familiarity with continuous integration and delivery pipelines, infrastructure as code tools, and security compliance frameworks are also essential. A solid understanding of automation technologies and strong analytical skills will set you apart in this innovative role.

Join Rise to see the full answer
How does Boeing ensure the security of its cloud applications?

Boeing employs a comprehensive approach to cloud application security that includes collaboration among cross-functional teams to implement security policies as code. As a Senior Cloud Application Security Lifecycle Specialist, you will help automate policy enforcement and monitor compliance with security standards, conducting regular audits to identify gaps in security implementation. Using industry best practices and cutting-edge tools, we work diligently to maintain the integrity and safety of our cloud environment.

Join Rise to see the full answer
What tools and technologies will I be working with as a Senior Cloud Application Security Lifecycle Specialist at Boeing?

In this role, you'll engage with various tools including Terraform and Open Policy Agent for implementing policies as code. You will also utilize cloud security compliance tools like AWS Inspector, Microsoft Defender for Cloud, and monitoring tools to ensure we adhere to security standards. Additionally, experience with scripting languages and continuous integration tools will enhance your contributions while streamlining our automation efforts.

Join Rise to see the full answer
What ongoing learning opportunities are available for Senior Cloud Application Security Lifecycle Specialists at Boeing?

Boeing encourages continuous learning and professional development for its Senior Cloud Application Security Lifecycle Specialists. You will be supported in attending various conferences, workshops, and training sessions related to cloud security and compliance. Staying updated with industry trends and emerging technologies is vital in this role, and Boeing provides resources and a collaborative environment to help you grow and keep pace with changes in cloud security.

Join Rise to see the full answer
Common Interview Questions for Senior Cloud Application Security Lifecycle Specialist
Can you explain the concept of Infrastructure as Code and its benefits in cloud security?

Infrastructure as Code (IaC) is a key practice that involves managing and provisioning computing infrastructure through machine-readable definition files, rather than physical hardware configuration or interactive configuration tools. It enhances cloud security by ensuring consistency in configurations, automating compliance checks, and enabling rapid recovery from any security breaches, making it easier to maintain a secure cloud environment aligned with best practices.

Join Rise to see the full answer
How would you approach policy management in a cloud environment?

In a cloud environment, I would first conduct a thorough assessment of existing security requirements and compliance standards. Next, I would design and implement policies as code using automation tools to ensure consistency and enforcement across our cloud services. Regular audits and updates to these policies are essential, as is providing training to teams to enhance adoption and understanding of policy management practices.

Join Rise to see the full answer
Can you discuss a time when you identified and resolved a significant security problem?

In my previous role, I encountered a major security flaw related to misconfigured cloud storage permissions. I initiated a comprehensive audit, identified the issue, and collaborated with engineering teams to rectify the configuration. I also implemented an automated monitoring solution to prevent future misconfigurations. This proactive approach not only resolved the issue but also strengthened our overall security posture.

Join Rise to see the full answer
What cloud platforms do you have experience with and how have you used them?

I have extensive experience with AWS, Azure, and GCP. In AWS, I've utilized services like IAM for identity management and CloudWatch for monitoring. On Azure, I’ve employed Azure DevOps for CI/CD pipelines, and in GCP, I've worked with security tools like Google Security Command Center. My expertise in these platforms enables me to create secure, scalable architectures while ensuring compliance across different environments.

Join Rise to see the full answer
How do you stay updated with the latest trends in cloud security?

I actively engage in several professional communities, subscribe to industry-specific publications, and follow thought leaders on social media. Additionally, participating in webinars, seminars, and networking events has helped me to stay informed about innovations and evolving threats in cloud security. This continuous learning fuels my ability to apply new insights and tools effectively within my role.

Join Rise to see the full answer
What is the role of automation in enhancing cloud security?

Automation plays a vital role in cloud security by ensuring that security policies are consistently enforced, monitoring compliance in real-time, and reducing human error. By automating repetitive tasks such as configuration checks and vulnerability scanning, we can focus our resources on more strategic security initiatives, thereby enhancing our overall security posture.

Join Rise to see the full answer
Describe your experience with continuous integration and delivery in relation to security.

My experience with CI/CD involves implementing secure coding practices and integrating security checks at each stage of the pipeline. This includes automated testing for vulnerabilities and compliance as part of the build process, ensuring that we detect and address security issues before they can affect production. This proactive approach to software development fundamentally enhances security while enabling rapid deployment.

Join Rise to see the full answer
How do you handle stakeholder communication regarding security policies?

Effective communication with stakeholders is critical in managing security policies. I prioritize clarity and transparency in discussions, often using tailored presentations to explain policies and their implications. Regular updates on compliance status and potential risks help build trust and ensure stakeholders are aware of their roles in maintaining security.

Join Rise to see the full answer
What strategies do you use to educate teams on security best practices?

I employ a combination of formal training sessions, hands-on workshops, and accessible documentation to educate teams on security best practices. Encouraging open dialogue and knowledge-sharing sessions fosters a culture of security awareness, empowering team members to take responsibility for their roles in maintaining cloud security.

Join Rise to see the full answer
What challenges have you faced in cloud security, and how have you overcome them?

One challenge I faced was addressing compliance requirements across multiple cloud platforms, each utilizing different tools and standards. I conducted a comparative analysis to identify commonalities amongst the platforms and developed a unified policy framework that could be applied universally. This streamlining improved our compliance posture and reduced administrative burden.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Boeing Hybrid US, Saint Louis County, MO; Missouri, Berkeley, MO
Posted yesterday
Photo of the Rise User
Boeing Hybrid US, Saint Louis County, MO; Missouri, Berkeley, MO
Posted yesterday
Photo of the Rise User
Posted 8 days ago
Photo of the Rise User
Bosch Group Hybrid No 123 Industrial Layout Hosur Road Koramangala, Bengaluru, in
Posted yesterday
Photo of the Rise User
Posted 2 days ago
Posted 2 days ago
Photo of the Rise User
Posted 6 days ago

The story of our company is woven together from thousands of individual stories of engineers and technicians. Scientists and thinkers. Innovators and dreamers. Equity, diversity and inclusion are crucial to our employees, our stakeholders, and our...

311 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
March 27, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
Photo of the Rise User
Someone from OH, Youngstown just viewed Sales and purchase internship at B&S Group
Photo of the Rise User
Someone from OH, Dayton just viewed Data Entry Specialist, Remote at ABC Legal Services
Photo of the Rise User
Someone from OH, Columbus just viewed Internship - DEI & Social Impact at Mendix
Photo of the Rise User
11 people applied to Excel Developer at Valcre
Photo of the Rise User
Someone from OH, Akron just viewed Grad Intern - No Work Experience at Walmart
Photo of the Rise User
Someone from OH, Columbus just viewed Race & Sportsbook Office Manager at Westgate Resorts
S
Someone from OH, Akron just viewed Client Service Representative at Shine Productions
Photo of the Rise User
26 people applied to IT Intern at USAA
Photo of the Rise User
Someone from OH, Columbus just viewed Technical Support Specialist at Samsara
Photo of the Rise User
Someone from OH, Canton just viewed Full Stack Web Developer at Abnormal Security
Photo of the Rise User
Someone from OH, Canton just viewed Frontend Engineer, UX at Chainlink Labs
R
Someone from OH, Toledo just viewed Global Marketing Intern at Reebok International, Ltd
Photo of the Rise User
Someone from OH, Toledo just viewed Intern, Corporate Communications at E.L.F. BEAUTY
Photo of the Rise User
Someone from OH, Cincinnati just viewed Immigration - E2 Visa at Upwork
Photo of the Rise User
Someone from OH, Dayton just viewed Senior Director - Brand & Marketing Content at Cielo
Photo of the Rise User
Someone from OH, Cleveland just viewed Scheduling Coordinator at Window Nation
T
Someone from OH, Columbus just viewed Power BI Developer - Remote at Two95 International Inc.
Photo of the Rise User
Someone from OH, Dayton just viewed Front Desk Clerk at Marriott International
Photo of the Rise User
Someone from OH, Hilliard just viewed Junior Digital Analyst at Jellyfish
Photo of the Rise User
Someone from OH, Hilliard just viewed Junior Digital Data Analyst at AECOM