Product Security Lead

ForterraClarksburg, WV

About The Position

Forterra is seeking a Product Security Lead to own security for all Forterra platforms end-to-end. This is a hands-on, leadership role where you will set the security strategy, own the governance and compliance posture, and drive security execution across software, hardware, and devops. You will lead a small team of product security engineers while coordinating a significantly larger cross-functional group of indirect contributors. You will serve as the company's security SME in pre-sales, bids/RFPs, and customer evaluations, and as Forterra's product security voice to government customers, commercial partners, and executive leadership. This senior security role requires someone who has built security programs before, earned DoD authorizations from beginning to end, and can operate with equal credibility at the engineering level as well as in executive briefings.

Requirements

  • 7+ years in product or cybersecurity with demonstrated depth in program leadership.
  • Proven experience owning an ATO end-to-end as the responsible authority.
  • Practical command of NIST 800-37, 800-53, 800-171; DISA STIGS and SRG; eMASS artifact requirements, formats, and review cycles.
  • Demonstrated experience securing embedded, autonomous, or operationally deployed systems including air-gapped and disconnected environments.
  • Experience building and leading security programs, teams, and functions.
  • Ability to operate at both the strategic and tactical levels simultaneously.
  • Strong executive communication skills; ability to brief senior leadership and stakeholders and defend decision-making.
  • Demonstrated experience with SBOM and vulnerability management in a product engineering environment.
  • Experience driving compliance validation against multiple concurrent frameworks (e.g., NIST, ISO/SAE, CMMC, etc.).
  • Active US Security Clearance or eligibility. Must be a US Person as defined under ITAR.

Nice To Haves

  • Active CISSP or equivalent senior security certification.
  • ISO/SAE 21434 automotive cybersecurity experience.
  • Experience with multiple ATOs across multiple DoD programs or branches.
  • Familiarity with IEC 62443 commercial cybersecurity engineering standard.
  • Experience managing indirect contributors and cross-functional security execution across large engineering organizations.

Responsibilities

  • Own the enterprise product security program across multiple autonomous vehicle platforms and business lines, including governance, policies, and roadmap.
  • Lead the full ATO and IATT lifecycle across concurrent DoD programs, from control selection and tailoring through evidence generation, POAM management, and government stakeholder coordination.
  • Participate in software release boards as the go/no-go authority for security.
  • Set and own the 12 and 24-month security roadmap, capability maturity planning, and resource forecasting.
  • Brief senior leadership, government stakeholders, and commercial partners on program status, risk posture, and readiness activities.
  • Develop cyber security requirements for platforms operating in a multitude of networks, including air-gapped, intermittently connected, and operationally constrained environments.
  • Lead threat modeling across autonomous, embedded, and command and control systems, driving risk assessments that weigh mitigations against mission requirements.
  • Own DISA STIG compliance strategy, evaluating and tailoring applicable checklists, and translating required controls into implementable guidance for engineering teams.
  • Own the SBOM generation pipeline and vulnerability management program, including CVE triage, remediation prioritization, and POAM closure.
  • Lead the product-level security incident response and coordinate cross-organization remediation with the corporate cybersecurity team.
  • Support the contract and sales teams as the pre-sales security SME, contributing to RFP and RFQ responses.
  • Build, lead, and develop the product security team, including hiring, onboarding, mentoring, and growing direct reports, and fostering a security-first engineering culture across the organization.

Benefits

  • Premium Healthcare Benefits: Three plan options, including an HSA-eligible plan, with Forterra covering 80% of the plan premium for you and your dependents.
  • Basic Life/AD&D, short and long-term disability insurance plans 100% covered by Forterra, plus the option to purchase additional life insurance for you and your dependents.
  • Extremely generous company holiday calendar including a winter break in December.
  • Competitive paid time off (PTO) offering 20 days accrued per year.
  • A minimum of 7 weeks fully paid parental leave for birth/adoption.
  • A $9k annual tuition reimbursement or professional development stipend.
  • Fully stocked beverage refrigerators.
  • 401(k) retirement savings plan, including traditional, Roth 401(k), and after-tax deferral with company match up to 4%.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service