Skip to content
ForterraForterraClarksburg, MD

Product Security Lead

Leads Forterra’s end-to-end product security program for autonomous vehicle platforms, including DoD authorization, compliance, threat modeling, vulnerability management, and incident response. Requires 7+ years of cybersecurity experience, ATO ownership, embedded or autonomous systems expertise, and strong technical and executive leadership.

175k – 200k/yr
On-site7+ YOESecurity Engineering

About the role

Responsibilities

  • Own the enterprise product security program across multiple autonomous vehicle platforms and business lines, including governance, policies, and roadmap.
  • Lead the full ATO and IATT lifecycle across concurrent DoD programs, from control selection and tailoring through evidence generation, POA&M management, and government stakeholder coordination.
  • Serve as Forterra’s ATO authority and participate in software release boards as the security go/no-go authority.
  • Set and own the 12- and 24-month security roadmap, capability maturity planning, and resource forecasting.
  • Brief senior leadership, government stakeholders, and commercial partners on program status, risk posture, and readiness.
  • Develop cybersecurity requirements for platforms operating across air-gapped, intermittently connected, and operationally constrained environments.
  • Lead threat modeling across autonomous, embedded, and command-and-control systems, balancing mitigations against mission requirements.
  • Own DISA STIG compliance strategy, evaluate and tailor applicable checklists, and translate controls into implementable engineering guidance.
  • Own the SBOM generation pipeline and vulnerability management program, including CVE triage, remediation prioritization, and POA&M closure.
  • Lead product-level security incident response and coordinate remediation with the corporate cybersecurity team.
  • Support contract and sales teams as the pre-sales security subject-matter expert, contributing to RFP and RFQ responses.
  • Build, lead, and develop the product security team; hire, onboard, mentor, and grow direct reports while fostering a security-first engineering culture.

Requirements

  • 7+ years in product security or cybersecurity, with demonstrated depth in program leadership.
  • Proven experience owning an ATO end to end as the responsible authority.
  • Practical command of NIST 800-37, NIST 800-53, NIST 800-171, DISA STIGs and SRGs, and eMASS artifact requirements, formats, and review cycles.
  • Experience securing embedded, autonomous, or operationally deployed systems, including air-gapped and disconnected environments.
  • Experience building and leading security programs, teams, and functions.
  • Ability to operate strategically and tactically at the same time.
  • Strong executive communication skills, including the ability to brief senior leadership and stakeholders and defend decisions.
  • Experience with SBOM and vulnerability management in a product engineering environment.
  • Experience driving compliance validation against multiple concurrent frameworks, such as NIST, ISO/SAE, and CMMC.
  • Active U.S. security clearance or eligibility to obtain one.
  • Must be a U.S. Person as defined under ITAR.

Preferred Qualifications

  • Active CISSP or equivalent senior security certification.
  • ISO/SAE 21434 automotive cybersecurity experience.
  • Experience with multiple ATOs across multiple DoD programs or branches.
  • Familiarity with IEC 62443 commercial cybersecurity engineering standards.
  • Experience managing indirect contributors and cross-functional security execution across large engineering organizations.

Compensation and Benefits

  • Salary: $175,000 - $200,000 annually.
  • Equity is included in most full-time, high-demand roles and is part of the overall compensation package.
  • Three premium healthcare plan options, including an HSA-eligible plan; Forterra covers 80% of premiums for employees and dependents.
  • Employer-paid basic life/AD&D and short- and long-term disability insurance.
  • Company holidays, including a December winter break.
  • 20 days of accrued PTO per year.
  • At least 7 weeks of fully paid parental leave.
  • $9,000 annual tuition reimbursement or professional development stipend.
  • 401(k) plan with traditional, Roth, and after-tax deferral options, plus a company match of up to 4%.

Skills

product securityCybersecurityatoiattnist 800-37nist 800-53nist 800-171disa stigsemassThreat ModelingsbomVulnerability Managementcmmciso/sae 21434cissp
Clear Street

Application Security Engineer / Architect

Clear StreetNew York, NY

Lead application and cloud security efforts as part of the DevSecOps lifecycle at Clear Street. Own CI/CD security controls, manage vulnerabilities, enforce IaC standards, perform threat modeling, and build automation tools while partnering closely with engineering teams. Requires 7+ years in security engineering, cloud and container expertise, and strong communication skills.

175k – 210k/yrHybrid7+ YOESecurity Engineering
Doxel

Senior Platform Engineer, Security

DoxelSan Francisco, CA

Build and secure Doxel's internal developer platform on GCP. Own cloud security posture, embed security into CI/CD pipelines, and drive adoption of secure golden paths across engineering teams.

175k – 220k/yrHybrid6+ YOESecurity Engineering
Crusoe

Senior Software Engineer, Security

CrusoeSan Francisco, CA

Design, build, and deploy scalable security services, PKI, and secrets management platforms. Implement automation to eliminate manual security risk remediation across enterprise infrastructure.

175k – 210k/yrOn-site5+ YOESecurity Engineering
Sigma

Senior Security Engineer

SigmaSan Francisco, CA

Senior Security Engineer building and scaling security platforms, AI/LLM security controls, detections-as-code, and automation across cloud and SaaS environments. Requires 5+ years hands-on security engineering experience and strong Python/cloud skills.

175k – 220k/yrOn-site5+ YOESecurity Engineering
Sigma

Senior Security Engineer - Data Security

SigmaSan Francisco, CA

Senior Security Engineer building and scaling data protection platforms, DLP, DSPM, and AI-driven automation across SaaS, cloud, and data warehouse environments. Requires 5+ years in security engineering and strong software engineering skills.

175k – 220k/yrOn-site5+ YOESecurity Engineering