Product Security Lead
ForterraAbout the role
About Forterra
At Forterra, we are unleashing autonomy at scale to transform the battlefield. Our mission is to build the foundational platforms that enable an intelligent ecosystem to coordinate, adapt, and execute with speed and precision even in the uncertainty and disruption of modern conflict. In an era marked by rapid technological change and evolving threats, we design for flexibility, survivability, and operational dominance.
Forterra delivers weapons, sensors, and battlefield effects through integrated autonomous networks reaching operational areas faster, safer, and without placing human lives at risk. Our systems operate with distributed control, dynamic routing, and real-time responsiveness, enabling sustained advantage across complex mission environments.
About the role
Forterra is unleashing autonomy at scale to transform the battlefield, and the systems we field have to be trusted in the most contested, disconnected environments on earth. We're seeking a Product Security Lead to own security for all Forterra platforms end-to-end: someone who can own and advance the program.
This is a hands-on, leadership role, not a paper-compliance seat. You will set the security strategy, own the governance and compliance posture, and drive security execution across software, hardware, and devops. You will lead a small team of product security engineers while coordinating a significantly larger cross functional group of indirect contributors and server as the company's security SME in pre sales, bids/RFPs, and customer evaluations. Additionally you will serve as Forterra's product security voice to government customers, commercial partners, and executive leadership.
This is a senior security role. It requires someone who has built security programs before, earned DoD authorizations from beginning to end, and an operate with equal credibility in the weeds at the engineering level as well as at an executive briefing.
What you'll do
- Own the enterprise product security program across multiple autonomous vehicle platforms and business lines- governance, policies, and roadmap
- Lead the full ATO and IATT lifecycle across concurrent DoD programs, from control selection and tailoring through evidence generation. POAM management, and government stakeholder coordination. You are Forterra's ATO authority
- Participate in software release boards as the go/no go authority for security
- Set and own the 12 and 24 month security roadmap, capability maturity planning, and resource forecasting
- Brief senior leadership, government stakeholders, and commercial partners on program status, risk posture, and readiness activities
- Develop cyber security requirements for platforms operating in a multitude of networks, including air gapped, intermittently connections, and operationally constrained environments
- Lead threat modelling across autonomous, embedded, and command and control systems, driving risk assessments that weigh mitigations against mission requirements
- Own DISA STIG compliance strategy. Evaluate and tailor applicable checklists, translating required controls into implementable guidance for engineering teams
- Own the SBOM generation pipeline and vulnerability management program, including CVE triage, remediation prioritization, and POAM closure
- Lead the product level security incident response and coordinate cross organization remediation with the corporate cybersecurity team
- Support the contract and sales teams as the pre sales security SME, contributing to RFP and RFQ responses
- Build, lead, and develop the product security team. Hire, onboard, mentor, and grow direct reports and foster a security first engineering culture across the organization
Minimum Qualifications
- 7+ years in product or cybersecurity with demonstrated depth in program leadership
- Proven experience owning an ATO end to end as the responsible authority
- Practical command of NIST 800-37, 800-53, 800-171; DISA STIGS and SRG; eMASS artifact requirements, formats, and review cycles
- Demonstrated experience securing embedded, autonomous, or operationally deployed systems including air gapped and disconnected environments
- Experience building and leading security programs, teams, and functions
- Ability to operate at both the strategic and tactical levels simultaneously
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s