Jobs and Careers
FO

Senior DoD Product Security Engineer

Forterra
Clarksburg, United Statesfull_timeVerifiedPosted 22 Jul 2026

About the role

About Forterra

Forterra is a leading provider of autonomous systems for ground-based movement in the working world. Amongst some of the earliest innovators in the field of driverless technology, Forterra is focused on building systems that protect front-line soldiers and enable civilian workers in our industrial base. Forterra is the go-to provider of ground autonomy solutions for the U.S. Department of Defense, which harnesses the technology for asymmetric warfare in critical conditions.

About the role

Forterra is unleashing autonomy at scale to transform the battlefield, and the systems we field have to be

trusted in the most contested, disconnected environments on earth. We're seeking a Senior DoD Product

Security Engineer to own product security for a DoD program end-to-end: someone who can walk in, take

the wheel, and be the single security authority in front of both our engineers and a government cyber or

program office.

This is a hands-on, senior individual-contributor role, not a paper-compliance seat. You'll own the RMF and

ATO process for your program(s) and shape the secure architecture behind it, proposing controls, writing

requirements, and driving security uplift across hardware and software. When an engineer asks why a

control matters, you can explain the threat and the mission rationale; when they ask how, you can give

them an implementable answer. On the functions you don't build yourself, you own the solutioning and

verify the implementation. You're as at home in the guts of an embedded system as you are reasoning

about a CI/CD pipeline, and you know how to secure systems that live on air-gapped, offline, and

intermittently connected networks. You'll report to the Product Security Lead and own the security case

from threat model to signed ATO, making the architecture and control decisions that determine whether an

autonomous platform can be trusted to operate securely in the field


What you'll do

  • Own RMF and the ATO lifecycle end-to-end for your program, from control selection and tailoring through driving implementation with engineering and managing POA&Ms. You are Forterra's security SME and point of contact to the government cyber or program office, owning the security documentation, evidence, and authorization case, and delivering it in the formats and review cycles they require.
  • Own the security architecture, don't just document it. Set the security direction for your program: define the controls, propose the solutions, and write the requirements that engineering builds to. You are the source of the security design. That means driving secure-by-design across hardware and software, including for air-gapped, offline, and disconnected operation, making the architecture calls and standing behind them with both the threat rationale and an implementable path. This is the core of the job informing and directing security uplift across the program.
  • Define, write, and trace security requirements through systems-engineering processes, including
  • requirements and design reviews and verification and validation, so security is built in and demonstrably met.
  • Lead threat modeling across autonomy, embedded, and command-and-control systems, and drive risk assessments that weigh mitigations against mission needs.
  • Serve as the STIG subject-matter expert: communicate STIG requirements to engineering, recommend implementation and mitigation approaches, and evaluate, tailor, and defend STIG applicability in negotiation with the customer.
  • Engineering owns hands-on-keyboard hardening; you own the expertise, the requirement translation, and the authorization case.
  • Own the solutioning and verify the implementation of security monitoring, logging, and detection; of secure update strategy (signed, atomic, recoverable firmware/OS updates); and of CVE and vulnerability management, even where other teams do the building.
  • Partner in software supply-chain security, SBOMs, and the secure SDLC (SAST/DAST, code review, CI/CD) helping move the program toward a DevSecOps pipeline built for security.
  • Audit embedded and application code for vulnerabilities, drive remediation with internal teams and vendors, and collaborate across systems, safety, test, and DevOps to meet product- and program-level security needs

Qualifications

  • 5+ years in security engineering o

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Forterra

View company profile →