Senior DoD Product Security Engineer
On-siteClarksburg, West Virginia, United States or Clarksburg, Maryland, United States
Job Summary
Own the RMF and ATO lifecycle end-to-end for your program, acting as the single security authority between engineering and the government cyber office. Define security architecture and requirements that drive secure-by-design across hardware and software, including air-gapped and offline operations. Lead threat modeling, risk assessments, and STIG negotiations while auditing code for vulnerabilities and managing CVE remediation. Verify implementation of secure updates, supply-chain security, and DevSecOps pipelines. Report to the Product Security Lead to deliver authorization cases from threat model to signed ATO.
Required Qualifications
- 5+ years in security engineering or a closely related field, with the depth to be the security decision-maker on a program
- Equivalent demonstrated skill will be considered in lieu of exact tenure
- Hands-on RMF/ATO experience
- Knowledgeable about every step of the ATO process and ready to act as the sole SME on it
- Practical command of the standards and frameworks for this work: NIST 800-37, 800-53, and 800-171
- Familiarity with eMASS artifact requirements, formats, and review cycles
- Able to evaluate, tailor, and defend STIG applicability both with the customer and internally
- Ability to translate STIG and control requirements into clear implementation or mitigation guidance for engineers
- Demonstrated depth in both hardware and software security
- Track record of identifying and mitigating high-impact vulnerabilities
- Deep expertise in one domain and solid working competence in the other
- Ability to move fluidly between the physical and the logical
- Ability to write clear security requirements
- Ability to communicate both the why and the how to software and systems engineers
- Experience with software supply-chain risk management and SBOMs
- Fluency in secure-SDLC practices (SAST/DAST, code review, CI/CD)
- Systems-engineering fluency: comfortable working within requirements, design reviews, and traceability
- Working knowledge of FIPS 140-3 and cryptographic module validation
- Understanding of how validated cryptography, TPM/HSM-backed key management, secure boot, and signed firmware apply to embedded and mission systems
- Demonstrated ability to deal with ambiguity
- Ability to learn new technologies quickly
- BS in Computer Science, Computer Engineering, Information Security, Electrical Engineering, or a related field
- Proof of exceptional skill in lieu of a degree
- Must be a U.S. Person (as defined under ITAR)
- Eligible to obtain a U.S. security clearance
Desired Qualifications
- Ideally you've owned a full ATO end-to-end
- Owned a full ATO package end-to-end as the responsible engineer
- Familiarity with CMMC
- Familiarity with commercial cybersecurity-engineering standards such as ISO/SAE 21434 and IEC 62443
- Judgment to apply commercial standards where DoD standards and requirements fall short
- Experience securing disconnected, embedded, or industrial systems
- CISSP or similar security certification
- Offensive-security depth: disassembly and reverse engineering, fuzzing, and common exploit methodologies
- Hands-on depth in one or more of: C, C++, Python, ARM, x86, cryptography
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.