Senior DoD Product Security Engineer

ForterraClarksburg, WV

About The Position

Forterra is seeking a Senior DoD Product Security Engineer to own product security for a DoD program end-to-end. This is a hands-on, senior individual-contributor role where you will own the RMF and ATO process for your program(s) and shape the secure architecture behind it. You will propose controls, write requirements, and drive security uplift across hardware and software. You will be responsible for explaining the threat and mission rationale behind security controls and providing implementable solutions. You will own the solutioning and verify the implementation of functions not built directly. The role requires expertise in embedded systems, CI/CD pipelines, and securing systems on air-gapped, offline, and intermittently connected networks. You will report to the Product Security Lead and own the security case from threat model to signed ATO, making critical architecture and control decisions.

Requirements

  • 5+ years in security engineering or a closely related field, with the depth to be the security decision-maker on a program. Equivalent demonstrated skill will be considered in lieu of exact tenure.
  • Hands-on RMF/ATO experience, ideally having owned a full ATO end-to-end.
  • Knowledgeable about every step of the ATO process and ready to act as the sole SME on it, both internally with engineers and externally with a government cyber or program office.
  • Practical command of NIST 800-37, 800-53, and 800-171; DISA STIGs; and familiarity with eMASS artifact requirements, formats, and review cycles.
  • Able to evaluate, tailor, and defend STIG applicability both with the customer and internally, and translate STIG and control requirements into clear implementation or mitigation guidance for engineers.
  • Demonstrated depth in both hardware and software security, with a track record of identifying and mitigating high-impact vulnerabilities.
  • Deep expertise in one domain (hardware or software security) and solid working competence in the other, with the ability to move fluidly between the physical and the logical.
  • Ability to write clear security requirements and communicate both the why and the how to software and systems engineers.
  • Experience with software supply-chain risk management and SBOMs, and fluency in secure-SDLC practices (SAST/DAST, code review, CI/CD).
  • Systems-engineering fluency: comfortable working within requirements, design reviews, and traceability.
  • Working knowledge of FIPS 140-3 and cryptographic module validation, and how validated cryptography, TPM/HSM-backed key management, secure boot, and signed firmware apply to embedded and mission systems.
  • Demonstrated ability to deal with ambiguity and learn new technologies quickly.
  • Must be a U.S. Person (as defined under ITAR) and eligible to obtain a U.S. security clearance.

Nice To Haves

  • Owned a full ATO package end-to-end as the responsible engineer.
  • Familiarity with CMMC.
  • Familiarity with commercial cybersecurity-engineering standards such as ISO/SAE 21434 and IEC 62443 and the judgment to apply them where DoD standards and requirements fall short.
  • Experience securing disconnected, embedded, or industrial systems.
  • CISSP or similar security certification preferred.
  • Offensive-security depth: disassembly and reverse engineering, fuzzing, and common exploit methodologies.
  • Hands-on depth in one or more of: C, C++, Python, ARM, x86, cryptography.

Responsibilities

  • Own RMF and the ATO lifecycle end-to-end for your program, from control selection and tailoring through driving implementation with engineering and managing POA&Ms.
  • Serve as Forterra's security SME and point of contact to the government cyber or program office, owning the security documentation, evidence, and authorization case.
  • Own the security architecture, setting the security direction for your program by defining controls, proposing solutions, and writing requirements for engineering.
  • Drive secure-by-design across hardware and software, including for air-gapped, offline, and disconnected operation.
  • Define, write, and trace security requirements through systems-engineering processes, including requirements and design reviews and verification and validation.
  • Lead threat modeling across autonomy, embedded, and command-and-control systems, and drive risk assessments.
  • Serve as the STIG subject-matter expert, communicating STIG requirements to engineering, recommending implementation and mitigation approaches, and evaluating, tailoring, and defending STIG applicability.
  • Own the solutioning and verify the implementation of security monitoring, logging, and detection; secure update strategy; and CVE and vulnerability management.
  • Partner in software supply-chain security, SBOMs, and the secure SDLC (SAST/DAST, code review, CI/CD).
  • Audit embedded and application code for vulnerabilities, drive remediation, and collaborate across systems, safety, test, and DevOps to meet product- and program-level security needs.

Benefits

  • Premium Healthcare Benefits: Three plan options, including an HSA-eligible plan, with Forterra covering 80% of the plan premium for you and your dependents.
  • Basic Life/AD&D, short and long-term disability insurance plans 100% covered by Forterra, plus the option to purchase additional life insurance for you and your dependents.
  • Extremely generous company holiday calendar including a winter break in December.
  • Competitive paid time off (PTO) offering 20 days accrued per year.
  • A minimum of 7 weeks fully paid parental leave for birth/adoption.
  • A $9k annual tuition reimbursement or professional development stipend.
  • Fully stocked beverage refrigerators with all the Celsius your little heart desires.
  • 401(k) retirement savings plan, including traditional, Roth 401(k), and after-tax deferral with company match up to 4%.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service