# Senior DoD Product Security Engineer

**Company:** [Forterra](https://hotfix.jobs/companies/forterra)
**Location:** Clarksburg, MD
**Role:** Security Engineering
**Experience:** 5+ years
**Skills:** rmf, ato, nist 800-53, nist 800-171, disa stigs, emass, Threat Modeling, sbom, DevSecOps, SAST, DAST, fips 140-3, secure boot, Cryptography, embedded security
**Posted:** 2026-07-22

> Senior individual contributor owning end-to-end product security for DoD autonomous systems programs. Leads RMF/ATO processes, defines security architecture and requirements for hardware/software (including air-gapped/embedded), performs threat modeling, STIG compliance, and supply-chain security.

## Job Description

## What you'll do
- Own RMF and the ATO lifecycle end-to-end for your program, from control selection and tailoring through driving implementation with engineering and managing POA&Ms.
- Serve as Forterra's security SME and point of contact to the government cyber or program office, owning the security documentation, evidence, and authorization case.
- Own the security architecture: define the controls, propose the solutions, and write the requirements that engineering builds to. Drive secure-by-design across hardware and software, including for air-gapped, offline, and disconnected operation.
- Define, write, and trace security requirements through systems-engineering processes, including requirements and design reviews and verification and validation.
- Lead threat modeling across autonomy, embedded, and command-and-control systems, and drive risk assessments that weigh mitigations against mission needs.
- Serve as the STIG subject-matter expert: communicate STIG requirements to engineering, recommend implementation and mitigation approaches, and evaluate, tailor, and defend STIG applicability.
- Own the solutioning and verify the implementation of security monitoring, logging, and detection; of secure update strategy (signed, atomic, recoverable firmware/OS updates); and of CVE and vulnerability management.
- Partner in software supply-chain security, SBOMs, and the secure SDLC (SAST/DAST, code review, CI/CD) helping move the program toward a DevSecOps pipeline.
- Audit embedded and application code for vulnerabilities, drive remediation with internal teams and vendors, and collaborate across systems, safety, test, and DevOps to meet product- and program-level security needs.

## Qualifications
- 5+ years in security engineering or a closely related field, with the depth to be the security decision-maker on a program. Equivalent demonstrated skill will be considered in lieu of exact tenure.
- Hands-on RMF/ATO experience. Knowledgeable about every step of the ATO process and ready to act as the sole SME on it, both internally with engineers and externally with a government cyber or program office.
- Practical command of NIST 800-37, 800-53, and 800-171; DISA STIGs; and familiarity with eMASS artifact requirements, formats, and review cycles.
- Able to evaluate, tailor, and defend STIG applicability both with the customer and internally, and translate STIG and control requirements into clear implementation or mitigation guidance for engineers.
- Demonstrated depth in both hardware and software security, with a track record of identifying and mitigating high-impact vulnerabilities. Deep expertise in one domain and solid working competence in the other.
- Experience with software supply-chain risk management and SBOMs, and fluency in secure-SDLC practices (SAST/DAST, code review, CI/CD).
- Systems-engineering fluency: comfortable working within requirements, design reviews, and traceability.
- Working knowledge of FIPS 140-3 and cryptographic module validation, and how validated cryptography, TPM/HSM-backed key management, secure boot, and signed firmware apply to embedded and mission systems.
- Demonstrated ability to deal with ambiguity and learn new technologies quickly.

## Preferred Qualifications
- Owned a full ATO package end-to-end as the responsible engineer.
- Familiarity with CMMC.
- Familiarity with commercial cybersecurity-engineering standards such as ISO/SAE 21434 and IEC 62443.
- Experience securing disconnected, embedded, or industrial systems.
- CISSP or similar security certification preferred.
- Offensive-security depth: disassembly and reverse engineering, fuzzing, and common exploit methodologies.
- Hands-on depth in one or more of: C, C++, Python, ARM, x86, cryptography.

## Education & Experience
- BS in Computer Science, Computer Engineering, Information Security, Electrical Engineering, or a related field, or proof of exceptional skill in lieu of a degree.
- Must be a U.S. Person (as defined under ITAR) and eligible to obtain a U.S. security clearance.

## Similar roles

- [Senior Product Security Engineer](https://hotfix.jobs/jobs/921b5b0f-c2bc-4c6f-b83d-9a6fb45c1476) - Cloudflare
- [Senior Threat Engineer](https://hotfix.jobs/jobs/f065b632-672b-4637-8669-526d5c900162) - Coalition Security - Remote - $100k – $150k/yr
- [Senior Security Compliance Specialist](https://hotfix.jobs/jobs/00a845e2-4327-4275-ada6-9b953420c37d) - Cloudflare - Remote
- [Senior IAM Engineer](https://hotfix.jobs/jobs/a54619ea-22d6-4f1e-ab0e-bf3db137b74b) - Komodo Health - Remote - $150k – $210k/yr
- [Sr. Software Engineer](https://hotfix.jobs/jobs/fd2f1913-c150-4f35-b16f-327aa66fac6a) - Illumio - Sunnyvale, CA - $170k – $196k/yr

**Apply:** https://hotfix.jobs/jobs/c5941ba2-f396-49af-a46d-263112f4a169
**Canonical:** https://hotfix.jobs/jobs/c5941ba2-f396-49af-a46d-263112f4a169