# Product Security Lead

**Company:** [Forterra](https://hotfix.jobs/companies/forterra)
**Location:** Clarksburg, MD
**Role:** Security Engineering
**Salary:** $175k – $200k/yr
**Experience:** 7+ years
**Skills:** product security, Cybersecurity, ato, iatt, nist 800-37, nist 800-53, nist 800-171, disa stigs, emass, Threat Modeling, sbom, Vulnerability Management, cmmc, iso/sae 21434, cissp
**Posted:** 2026-08-04

> Leads Forterra’s end-to-end product security program for autonomous vehicle platforms, including DoD authorization, compliance, threat modeling, vulnerability management, and incident response. Requires 7+ years of cybersecurity experience, ATO ownership, embedded or autonomous systems expertise, and strong technical and executive leadership.

## Job Description

## Responsibilities
- Own the enterprise product security program across multiple autonomous vehicle platforms and business lines, including governance, policies, and roadmap.
- Lead the full ATO and IATT lifecycle across concurrent DoD programs, from control selection and tailoring through evidence generation, POA&M management, and government stakeholder coordination.
- Serve as Forterra’s ATO authority and participate in software release boards as the security go/no-go authority.
- Set and own the 12- and 24-month security roadmap, capability maturity planning, and resource forecasting.
- Brief senior leadership, government stakeholders, and commercial partners on program status, risk posture, and readiness.
- Develop cybersecurity requirements for platforms operating across air-gapped, intermittently connected, and operationally constrained environments.
- Lead threat modeling across autonomous, embedded, and command-and-control systems, balancing mitigations against mission requirements.
- Own DISA STIG compliance strategy, evaluate and tailor applicable checklists, and translate controls into implementable engineering guidance.
- Own the SBOM generation pipeline and vulnerability management program, including CVE triage, remediation prioritization, and POA&M closure.
- Lead product-level security incident response and coordinate remediation with the corporate cybersecurity team.
- Support contract and sales teams as the pre-sales security subject-matter expert, contributing to RFP and RFQ responses.
- Build, lead, and develop the product security team; hire, onboard, mentor, and grow direct reports while fostering a security-first engineering culture.

## Requirements
- 7+ years in product security or cybersecurity, with demonstrated depth in program leadership.
- Proven experience owning an ATO end to end as the responsible authority.
- Practical command of NIST 800-37, NIST 800-53, NIST 800-171, DISA STIGs and SRGs, and eMASS artifact requirements, formats, and review cycles.
- Experience securing embedded, autonomous, or operationally deployed systems, including air-gapped and disconnected environments.
- Experience building and leading security programs, teams, and functions.
- Ability to operate strategically and tactically at the same time.
- Strong executive communication skills, including the ability to brief senior leadership and stakeholders and defend decisions.
- Experience with SBOM and vulnerability management in a product engineering environment.
- Experience driving compliance validation against multiple concurrent frameworks, such as NIST, ISO/SAE, and CMMC.
- Active U.S. security clearance or eligibility to obtain one.
- Must be a U.S. Person as defined under ITAR.

## Preferred Qualifications
- Active CISSP or equivalent senior security certification.
- ISO/SAE 21434 automotive cybersecurity experience.
- Experience with multiple ATOs across multiple DoD programs or branches.
- Familiarity with IEC 62443 commercial cybersecurity engineering standards.
- Experience managing indirect contributors and cross-functional security execution across large engineering organizations.

## Compensation and Benefits
- **Salary:** $175,000 - $200,000 annually.
- Equity is included in most full-time, high-demand roles and is part of the overall compensation package.
- Three premium healthcare plan options, including an HSA-eligible plan; Forterra covers 80% of premiums for employees and dependents.
- Employer-paid basic life/AD&D and short- and long-term disability insurance.
- Company holidays, including a December winter break.
- 20 days of accrued PTO per year.
- At least 7 weeks of fully paid parental leave.
- $9,000 annual tuition reimbursement or professional development stipend.
- 401(k) plan with traditional, Roth, and after-tax deferral options, plus a company match of up to 4%.

## Similar roles

- [Application Security Engineer / Architect](https://hotfix.jobs/jobs/1b397589-ac62-48f9-95c2-b6f3f5f5e917) - Clear Street - New York, NY - $175k – $210k/yr
- [Senior Platform Engineer, Security](https://hotfix.jobs/jobs/66279d2d-a2ec-42c9-8617-3e15e999ebac) - Doxel - San Francisco, CA - $175k – $220k/yr
- [Senior Software Engineer, Security](https://hotfix.jobs/jobs/5ceaaeac-36b0-4169-9a44-fb4df6a5ceb6) - Crusoe - San Francisco, CA - $175k – $210k/yr
- [Senior Security Engineer](https://hotfix.jobs/jobs/597fe572-d370-4678-b5bb-e0e085fe5586) - Sigma - San Francisco, CA - $175k – $220k/yr
- [Senior Security Engineer - Data Security](https://hotfix.jobs/jobs/4ecc0e54-09f4-4a68-a2b7-2892ff1da3e7) - Sigma - San Francisco, CA - $175k – $220k/yr

**Apply:** https://hotfix.jobs/jobs/7b9403f9-6255-49aa-9489-3a9d385b4596
**Canonical:** https://hotfix.jobs/jobs/7b9403f9-6255-49aa-9489-3a9d385b4596