Senior Aviation Cyber Certification Engineer
Merlinlabs · Boston or Remote · posted Oct 6, 2026
Open to candidates in United States
We never charge to apply.
What this role actually asks for
Extracted by RemoteHuntMust have
- •Hands-on airworthiness security certification experience
- •Experience with DO-326A/ED-202A, ARP4754B, DO-356A/ED-203A
- •Built PSecAC or equivalent artifact
- •Show compliance to FAA/EASA or DER
- •Build certification processes from scratch
- •Experience interfacing with FAA/EASA on security
Nice to have
- •Working knowledge of RMF, vulnerability assessment, DISA STIGs
- •Background in aerospace/avionics/autonomous systems
- •U.S. citizenship and security clearance eligibility
- •Experience mentoring engineers on security
- •Familiarity with DoD cyber authorization efforts
The full posting
Merlin (NASDAQ: MRLN) is a publicly traded aerospace and defense company building a non-human pilot to deliver full-stack autonomy for any aircraft from takeoff to touchdown. The Merlin Pilot autonomy system powers a growing range of aircraft and mission profiles and has been proven through hundreds of autonomous flights from Merlin's global flight test facilities, including Kerikeri, New Zealand; Quonset Point, Rhode Island; and soon, Bedford, Massachusetts. Headquartered in Boston, Merlin is expanding its organization to accelerate the development and deployment of its autonomy platform, helping customers solve some of aviation's most pressing challenges, from pilot shortages to improving flight safety. Backed by some of the world's leading investors prior to its public listing, Merlin continues to advance the certification and commercialization of autonomous flight across commercial and defense aviation.
About You:
You have hands-on experience navigating airworthiness security certification on a civil aviation program. You understand how DO-326A/ED-202A, ARP4754B, and DO-356A/ED-203A apply to certification programs, and you've built or contributed to a Plan for Security Aspects of Certification (PSecAC) or equivalent artifact where no process existed before. You know how to show compliance to applicable requirements for FAA/EASA or a Designated Engineering Representative (DER) approval.
Merlin Labs builds autonomous aviation systems for demanding defense customers, and we are establishing the civil side of our aviation cyber certification capability as our program portfolio grows. This is a foundational role: you will build the processes, procedures, and documentation that carry Merlin's civil aviation cyber certification work, working with minimal supervision and closely with our Information Systems Security team on the military airworthiness side. If you have a builder's, 0-to-1 mentality and want to own how Merlin approaches aviation cybersecurity certification, this is the role.
Responsibilities::
- Establish civil aviation cyber certification discipline: define the processes, procedures, templates, and artifact structure needed to support airworthiness security certification as civil aviation programs come online.
- Lead airworthiness security activities aligned to DO-326A/ED-202A and ARP4754B, including threat and security risk identification, and develop the Plan for Security Aspects of Certification (PSecAC), supporting Security Development Plan, and PSecAC Summary.
- Perform aircraft, system, and item-level security risk assessments per DO-356A/ED-203A, and develop the certification evidence — security risk assessments, verification results, and compliance data — required to support the security aspects of certification.
- Serve as technical point of contact with the FAA (and other applicable certification authorities or their designated representatives) on cybersecurity certification deliverables and activities for civil aviation programs.
- Partners with systems, software, and safety engineering teams to embed airworthiness security requirements into design and development early, and coordinate security certification activities with the broader certification schedule.
- Own the security certification documentation set — security plans, risk assessments, compliance matrices, and means-of-compliance packages — and maintain configuration control as programs move through certification milestones.
- Validate and build on the aviation cyber certification-related work already performed by the Lead Engineer, Information Systems Security — including authorization artifacts such as test reports supporting military airworthiness efforts — and serve as Merlin's dedicated subject-matter expert for aviation cyber certification across both military and civil programs.
Qualifications::
- Bachelor's degree with 6-9 years of cybersecurity or systems security engineering experience, including direct experience on civil aviation airworthiness security or certification programs.
- Direct experience applying DO-326A/ED-202A, ARP4754B, and DO-356A/ED-203A on an aircraft or system certification program.
- Experience interfacing with the FAA, EASA, or other certification authorities (directly or through a DER/ODA Unit Member (UM)) on the security aspects of a type certification or supplemental type certification (STC) program.
- Demonstrated ability to build certification processes, procedures, and documentation from the ground up in the absence of existing infrastructure.
- Proven ability to work independently with minimal supervision while coordinating across systems, software, safety, and program management teams.
Nice to Have::
- Working knowledge of systems security engineering practices (e.g., RMF, vulnerability assessment, DISA STIGs), given crossover with Merlin's defense-side security engineering work.
- Background in aerospace, avionics, autonomous systems, or another safety-critical engineering domain where security requirements intersect with airworthiness and safety certification (e.g., familiarity with ARP4761 safety assessment processes).
- U.S. citizenship and eligibility to obtain a security clearance, given crossover with Merlin's defense programs.
- Experience mentoring engineers on security requirements or building out a security engineering function/team as a program or company scales.
- Familiarity with DoD cyber authorization efforts, including Interim Authorization to Test (IATT) and Authorization to Operate (ATO) processes.
Logistics::
- We welcome remote applicants for this role, with a preference for candidates based in or willing to relocate to Boston, MA for a hybrid work schedule at our HQ.
Similar remote jobs
Is this one actually worth your time?
RemoteHunt scores every remote job 0–100 against your own resume, so you apply to the handful that fit instead of the hundred that don't. Free plan, no card required.