Forterra logo
ForterraPosted 1 month ago

Senior DoD Product Security Engineer

On-siteClarksburg, West Virginia, United States or Clarksburg, Maryland, United States

Part TimeSenior LevelMedium

Job Summary

Own the RMF and ATO lifecycle end-to-end for your program, acting as the single security authority between engineering and the government cyber office. Define security architecture and requirements that drive secure-by-design across hardware and software, including air-gapped and offline operations. Lead threat modeling, risk assessments, and STIG negotiations while auditing code for vulnerabilities and managing CVE remediation. Verify implementation of secure updates, supply-chain security, and DevSecOps pipelines. Report to the Product Security Lead to deliver authorization cases from threat model to signed ATO.

Required Qualifications

  • 5+ years in security engineering or a closely related field, with the depth to be the security decision-maker on a program
  • Equivalent demonstrated skill will be considered in lieu of exact tenure
  • Hands-on RMF/ATO experience
  • Knowledgeable about every step of the ATO process and ready to act as the sole SME on it
  • Practical command of the standards and frameworks for this work: NIST 800-37, 800-53, and 800-171
  • Familiarity with eMASS artifact requirements, formats, and review cycles
  • Able to evaluate, tailor, and defend STIG applicability both with the customer and internally
  • Ability to translate STIG and control requirements into clear implementation or mitigation guidance for engineers
  • Demonstrated depth in both hardware and software security
  • Track record of identifying and mitigating high-impact vulnerabilities
  • Deep expertise in one domain and solid working competence in the other
  • Ability to move fluidly between the physical and the logical
  • Ability to write clear security requirements
  • Ability to communicate both the why and the how to software and systems engineers
  • Experience with software supply-chain risk management and SBOMs
  • Fluency in secure-SDLC practices (SAST/DAST, code review, CI/CD)
  • Systems-engineering fluency: comfortable working within requirements, design reviews, and traceability
  • Working knowledge of FIPS 140-3 and cryptographic module validation
  • Understanding of how validated cryptography, TPM/HSM-backed key management, secure boot, and signed firmware apply to embedded and mission systems
  • Demonstrated ability to deal with ambiguity
  • Ability to learn new technologies quickly
  • BS in Computer Science, Computer Engineering, Information Security, Electrical Engineering, or a related field
  • Proof of exceptional skill in lieu of a degree
  • Must be a U.S. Person (as defined under ITAR)
  • Eligible to obtain a U.S. security clearance

Desired Qualifications

  • Ideally you've owned a full ATO end-to-end
  • Owned a full ATO package end-to-end as the responsible engineer
  • Familiarity with CMMC
  • Familiarity with commercial cybersecurity-engineering standards such as ISO/SAE 21434 and IEC 62443
  • Judgment to apply commercial standards where DoD standards and requirements fall short
  • Experience securing disconnected, embedded, or industrial systems
  • CISSP or similar security certification
  • Offensive-security depth: disassembly and reverse engineering, fuzzing, and common exploit methodologies
  • Hands-on depth in one or more of: C, C++, Python, ARM, x86, cryptography

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce