Leads Forterra’s end-to-end product security program for autonomous vehicle platforms, including DoD authorization, compliance, threat modeling, vulnerability management, and incident response. Requires 7+ years of cybersecurity experience, ATO ownership, embedded or autonomous systems expertise, and strong technical and executive leadership.
175k – 200k/yr
On-site7+ YOESecurity Engineering
About the role
Responsibilities
Own the enterprise product security program across multiple autonomous vehicle platforms and business lines, including governance, policies, and roadmap.
Lead the full ATO and IATT lifecycle across concurrent DoD programs, from control selection and tailoring through evidence generation, POA&M management, and government stakeholder coordination.
Serve as Forterra’s ATO authority and participate in software release boards as the security go/no-go authority.
Set and own the 12- and 24-month security roadmap, capability maturity planning, and resource forecasting.
Brief senior leadership, government stakeholders, and commercial partners on program status, risk posture, and readiness.
Develop cybersecurity requirements for platforms operating across air-gapped, intermittently connected, and operationally constrained environments.
Lead threat modeling across autonomous, embedded, and command-and-control systems, balancing mitigations against mission requirements.
Own DISA STIG compliance strategy, evaluate and tailor applicable checklists, and translate controls into implementable engineering guidance.
Own the SBOM generation pipeline and vulnerability management program, including CVE triage, remediation prioritization, and POA&M closure.
Lead product-level security incident response and coordinate remediation with the corporate cybersecurity team.
Support contract and sales teams as the pre-sales security subject-matter expert, contributing to RFP and RFQ responses.
Build, lead, and develop the product security team; hire, onboard, mentor, and grow direct reports while fostering a security-first engineering culture.
Requirements
7+ years in product security or cybersecurity, with demonstrated depth in program leadership.
Proven experience owning an ATO end to end as the responsible authority.
Practical command of NIST 800-37, NIST 800-53, NIST 800-171, DISA STIGs and SRGs, and eMASS artifact requirements, formats, and review cycles.
Experience securing embedded, autonomous, or operationally deployed systems, including air-gapped and disconnected environments.
Experience building and leading security programs, teams, and functions.
Ability to operate strategically and tactically at the same time.
Strong executive communication skills, including the ability to brief senior leadership and stakeholders and defend decisions.
Experience with SBOM and vulnerability management in a product engineering environment.
Experience driving compliance validation against multiple concurrent frameworks, such as NIST, ISO/SAE, and CMMC.
Active U.S. security clearance or eligibility to obtain one.
Must be a U.S. Person as defined under ITAR.
Preferred Qualifications
Active CISSP or equivalent senior security certification.
Lead application and cloud security efforts as part of the DevSecOps lifecycle at Clear Street. Own CI/CD security controls, manage vulnerabilities, enforce IaC standards, perform threat modeling, and build automation tools while partnering closely with engineering teams. Requires 7+ years in security engineering, cloud and container expertise, and strong communication skills.
175k – 210k/yrHybrid7+ YOESecurity Engineering
Senior Platform Engineer, Security
DoxelSan Francisco, CA
Build and secure Doxel's internal developer platform on GCP. Own cloud security posture, embed security into CI/CD pipelines, and drive adoption of secure golden paths across engineering teams.
175k – 220k/yrHybrid6+ YOESecurity Engineering
Senior Software Engineer, Security
CrusoeSan Francisco, CA
Design, build, and deploy scalable security services, PKI, and secrets management platforms. Implement automation to eliminate manual security risk remediation across enterprise infrastructure.
175k – 210k/yrOn-site5+ YOESecurity Engineering
Senior Security Engineer
SigmaSan Francisco, CA
Senior Security Engineer building and scaling security platforms, AI/LLM security controls, detections-as-code, and automation across cloud and SaaS environments. Requires 5+ years hands-on security engineering experience and strong Python/cloud skills.
175k – 220k/yrOn-site5+ YOESecurity Engineering
Senior Security Engineer - Data Security
SigmaSan Francisco, CA
Senior Security Engineer building and scaling data protection platforms, DLP, DSPM, and AI-driven automation across SaaS, cloud, and data warehouse environments. Requires 5+ years in security engineering and strong software engineering skills.