Skip to content

Open nowPosted 22 hours ago

Senior Aviation Cyber Certification Engineer

Merlin Labs27 open roles

Pay
$165,000 – $220,000 a year
Where
Boston or Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Aviation Cyber Certification EngineerMerlin Labs · Boston or Remote
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Merlin Labs's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market. Merlin Labs postings stay open a median of 1 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.5%3 days
  3. 8.0%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 22 hours ago

Merlin Labs median: 1 days open

The posting

Merlin (NASDAQ: MRLN) is a publicly traded aerospace and defense company building a non-human pilot to deliver full-stack autonomy for any aircraft from takeoff to touchdown. The Merlin Pilot autonomy system powers a growing range of aircraft and mission profiles and has been proven through hundreds of autonomous flights from Merlin's global flight test facilities, including Kerikeri, New Zealand; Quonset Point, Rhode Island; and soon, Bedford, Massachusetts. Headquartered in Boston, Merlin is expanding its organization to accelerate the development and deployment of its autonomy platform, helping customers solve some of aviation's most pressing challenges, from pilot shortages to improving flight safety. Backed by some of the world's leading investors prior to its public listing, Merlin continues to advance the certification and commercialization of autonomous flight across commercial and defense aviation.

About You:

You have hands-on experience navigating airworthiness security certification on a civil aviation program. You understand how DO-326A/ED-202A, ARP4754B, and DO-356A/ED-203A apply to certification programs, and you've built or contributed to a Plan for Security Aspects of Certification (PSecAC) or equivalent artifact where no process existed before. You know how to show compliance to applicable requirements for FAA/EASA or a Designated Engineering Representative (DER) approval.

Merlin Labs builds autonomous aviation systems for demanding defense customers, and we are establishing the civil side of our aviation cyber certification capability as our program portfolio grows. This is a foundational role: you will build the processes, procedures, and documentation that carry Merlin's civil aviation cyber certification work, working with minimal supervision and closely with our Information Systems Security team on the military airworthiness side. If you have a builder's, 0-to-1 mentality and want to own how Merlin approaches aviation cybersecurity certification, this is the role.

Responsibilities:

  • Establish civil aviation cyber certification discipline: define the processes, procedures, templates, and artifact structure needed to support airworthiness security certification as civil aviation programs come online.
  • Lead airworthiness security activities aligned to DO-326A/ED-202A and ARP4754B, including threat and security risk identification, and develop the Plan for Security Aspects of Certification (PSecAC), supporting Security Development Plan, and PSecAC Summary.
  • Perform aircraft, system, and item-level security risk assessments per DO-356A/ED-203A, and develop the certification evidence — security risk assessments, verification results, and compliance data — required to support the security aspects of certification.
  • Serve as technical point of contact with the FAA (and other applicable certification authorities or their designated representatives) on cybersecurity certification deliverables and activities for civil aviation programs.
  • Partners with systems, software, and safety engineering teams to embed airworthiness security requirements into design and development early, and coordinate security certification activities with the broader certification schedule.
  • Own the security certification documentation set — security plans, risk assessments, compliance matrices, and means-of-compliance packages — and maintain configuration control as programs move through certification milestones.
  • Validate and build on the aviation cyber certification-related work already performed by the Lead Engineer, Information Systems Security — including authorization artifacts such as test reports supporting military airworthiness efforts — and serve as Merlin's dedicated subject-matter expert for aviation cyber certification across both military and civil programs.

Qualifications:

  • Bachelor's degree with 6-9 years of cybersecurity or systems security engineering experience, including direct experience on civil aviation airworthiness security or certification programs.
  • Direct experience applying DO-326A/ED-202A, ARP4754B, and DO-356A/ED-203A on an aircraft or system certification program.
  • Experience interfacing with the FAA, EASA, or other certification authorities (directly or through a DER/ODA Unit Member (UM)) on the security aspects of a type certification or supplemental type certification (STC) program.
  • Demonstrated ability to build certification processes, procedures, and documentation from the ground up in the absence of existing infrastructure.
  • Proven ability to work independently with minimal supervision while coordinating across systems, software, safety, and program management teams.

Nice to Haves:

  • Working knowledge of systems security engineering practices (e.g., RMF, vulnerability assessment, DISA STIGs), given crossover with Merlin's defense-side security engineering work.
  • Background in aerospace, avionics, autonomous systems, or another safety-critical engineering domain where security requirements intersect with airworthiness and safety certification (e.g., familiarity with ARP4761 safety assessment processes).
  • U.S. citizenship and eligibility to obtain a security clearance, given crossover with Merlin's defense programs.
  • Experience mentoring engineers on security requirements or building out a security engineering function/team as a program or company scales.
  • Familiarity with DoD cyber authorization efforts, including Interim Authorization to Test (IATT) and Authorization to Operate (ATO) processes.

Merlin Labs offers an innovative, entrepreneurial, and team-focused startup environment. We also offer a top-notch benefits package (health, dental, life, flexible paid time off, and 401k with match) and work/life integration. Being part of the Merlin team allows you to become part of a small team that supports professional development while working together to achieve our mission.

Merlin Labs is an equal opportunity employer and values diversity. We do not discriminate on the basis of race, religion, color, national origin, genetic information, sex (including pregnancy), gender, gender identity and expression, sexual orientation, age, marital status, military service or obligation or disability status, or any other characteristic protected by law. All job offers are contingent upon the candidate passing background and reference checks.

At this time, we are unable to provide visa sponsorship or consider candidates who require visa transfers. Applicants must be authorized to work in the United States without the need for visa sponsorship now or in the future.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

If you require reasonable accommodation in completing an application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please direct your inquiries to: [email protected]

Merlin Labs does not accept unsolicited resumes from any source other than directly from candidates.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Merlin Labs's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Merlin Labs's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Merlin Labs's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.