Senior individual contributor owning end-to-end product security for DoD autonomous systems programs. Leads RMF/ATO processes, defines security architecture and requirements for hardware/software (including air-gapped/embedded), performs threat modeling, STIG compliance, and supply-chain security.
Salary not listed
On-site5+ YOESecurity Engineering
About the role
What you'll do
Own RMF and the ATO lifecycle end-to-end for your program, from control selection and tailoring through driving implementation with engineering and managing POA&Ms.
Serve as Forterra's security SME and point of contact to the government cyber or program office, owning the security documentation, evidence, and authorization case.
Own the security architecture: define the controls, propose the solutions, and write the requirements that engineering builds to. Drive secure-by-design across hardware and software, including for air-gapped, offline, and disconnected operation.
Define, write, and trace security requirements through systems-engineering processes, including requirements and design reviews and verification and validation.
Lead threat modeling across autonomy, embedded, and command-and-control systems, and drive risk assessments that weigh mitigations against mission needs.
Serve as the STIG subject-matter expert: communicate STIG requirements to engineering, recommend implementation and mitigation approaches, and evaluate, tailor, and defend STIG applicability.
Own the solutioning and verify the implementation of security monitoring, logging, and detection; of secure update strategy (signed, atomic, recoverable firmware/OS updates); and of CVE and vulnerability management.
Partner in software supply-chain security, SBOMs, and the secure SDLC (SAST/DAST, code review, CI/CD) helping move the program toward a DevSecOps pipeline.
Audit embedded and application code for vulnerabilities, drive remediation with internal teams and vendors, and collaborate across systems, safety, test, and DevOps to meet product- and program-level security needs.
Qualifications
5+ years in security engineering or a closely related field, with the depth to be the security decision-maker on a program. Equivalent demonstrated skill will be considered in lieu of exact tenure.
Hands-on RMF/ATO experience. Knowledgeable about every step of the ATO process and ready to act as the sole SME on it, both internally with engineers and externally with a government cyber or program office.
Practical command of NIST 800-37, 800-53, and 800-171; DISA STIGs; and familiarity with eMASS artifact requirements, formats, and review cycles.
Able to evaluate, tailor, and defend STIG applicability both with the customer and internally, and translate STIG and control requirements into clear implementation or mitigation guidance for engineers.
Demonstrated depth in both hardware and software security, with a track record of identifying and mitigating high-impact vulnerabilities. Deep expertise in one domain and solid working competence in the other.
Experience with software supply-chain risk management and SBOMs, and fluency in secure-SDLC practices (SAST/DAST, code review, CI/CD).
Systems-engineering fluency: comfortable working within requirements, design reviews, and traceability.
Working knowledge of FIPS 140-3 and cryptographic module validation, and how validated cryptography, TPM/HSM-backed key management, secure boot, and signed firmware apply to embedded and mission systems.
Demonstrated ability to deal with ambiguity and learn new technologies quickly.
Preferred Qualifications
Owned a full ATO package end-to-end as the responsible engineer.
Familiarity with CMMC.
Familiarity with commercial cybersecurity-engineering standards such as ISO/SAE 21434 and IEC 62443.
Experience securing disconnected, embedded, or industrial systems.
CISSP or similar security certification preferred.
Offensive-security depth: disassembly and reverse engineering, fuzzing, and common exploit methodologies.
Hands-on depth in one or more of: C, C++, Python, ARM, x86, cryptography.
Education & Experience
BS in Computer Science, Computer Engineering, Information Security, Electrical Engineering, or a related field, or proof of exceptional skill in lieu of a degree.
Must be a U.S. Person (as defined under ITAR) and eligible to obtain a U.S. security clearance.
Lead security assessments, threat modeling, and vulnerability operations for Cloudflare's core products. Drive AI-powered automation for triage and workflows while mentoring teams in large-scale distributed environments.
Salary not listed
Hybrid7+ YOESecurity Engineering
Senior Threat Engineer
Coalition SecurityUnited States
Senior Threat Engineer designs, builds, and improves detection, decisioning, and response workflows for the Wirespeed Verdict Engine. Requires significant cybersecurity operations experience, strong analytical skills, and ability to translate threat research into scalable automations.
100k – 150k/yr
Remote5+ YOESecurity Engineering
Senior Security Compliance Specialist
CloudflareUnited States
Lead Cloudflare's CCCS CSP ITS assessment and maintain CCCS requirements in the Common Control Framework. Requires 5+ years in security compliance, deep CCCS knowledge, and cross-functional collaboration with engineering, legal, and product teams.
Salary not listed
Remote5+ YOESecurity Engineering
Senior IAM Engineer
Komodo HealthNew York, NY
Senior IAM Engineer building integration and orchestration infrastructure to secure AI and data systems at Komodo Health. Design automated identity lifecycle processes, RBAC/ABAC, SSO/MFA, and custom automations with Okta, Workato, and Python while ensuring SOC2/HIPAA compliance.
150k – 210k/yr
Remote5+ YOESecurity Engineering
Sr. Software Engineer
IllumioSunnyvale, CA
Develop containerized microservices in Go for a multi-tenant cloud security platform that processes real-time cloud telemetry to deliver insights and risk minimization. Own full SDLC, design, operations, and mentoring while partnering with Product on requirements.