What are the responsibilities and job description for the Aircraft Security Engineer position at XFORIA Inc?
Requirements & Qualifications
Top Priority ("Must-Haves")
5 Years in Security Engineering: Demonstrated experience owning complex security projects independently (must be engineering/architecture focused, not queue-based SOC analyst experience).
PKI Engineering (Design & Operations): Hands-on expertise beyond certificate consumption, including:
Solution design, enrollment protocols (SCEP, EST), and operational trust roles.
Certificate Policy / Certification Practice Statement (CP/CPS), Levels of Assurance, and NIST SP 800-63.
Practical implementations of certificate-based authentication and software signing/validation.
Detection Engineering & Investigation:
Proficiency with Microsoft Sentinel, KQL (query & rule authoring), and custom dashboard creation.
Proven capability in end-to-end security event investigations backed by strong written documentation.
Remediation Lifecycle Engineering: Demonstrated history of owning remediation-plan reviews and vulnerability lifecycle tracking from discovery to validated closure.
Preferred Qualifications ("Nice-to-Haves")
AI / Agentic Security Tooling: Hands-on experience with LLM-assisted code/config analysis, prompt engineering for security use cases (e.g., Claude/GPT), and CISO AI alignment.
Endpoint Platform Engineering: Experience with Absolute endpoint management (SSO, policy groups, API integrations).
Scripting & Automation: Proficiency in Python or PowerShell for security automation.
Domain Exposure: Background in aviation cybersecurity, Operational Technology (OT), cyber-physical systems, or embedded systems.
Hardware & Cryptography: Experience with Hardware Security Modules (HSMs), enterprise key management, and code-signing infrastructure.
Core Competencies & Leadership Attributes
Technical Craftsmanship: Sets high quality standards and actively coaches junior team members.
Analytical Problem Solving: Conducts deep root cause analysis to solve systemic issues rather than treating symptoms.
Strategic Vision: Evaluates technical risks thoughtfully, driving practical prevention strategies and proactive architecture improvements.