Jobs · Information Technology · Maryland

Product Security Lead

Forterra · Clarksburg, MD · 3 wk ago
Information Technology$175k–$200k/yrFull-time

At Forterra, we are unleashing autonomy at scale to transform the battlefield. Our mission is to build the foundational platforms that enable an intelligent ecosystem to coordinate, adapt, and execute with speed and precision even in the uncertainty and disruption of modern conflict. In an era marked by rapid technological change and evolving threats, we design for flexibility, survivability, and operational dominance. Forterra delivers weapons, sensors, and battlefield effects through integrated autonomous networks reaching operational areas faster, safer, and without placing human lives at risk. Our systems operate with distributed control, dynamic routing, and real-time responsiveness, enabling sustained advantage across complex mission environments.

About the Role

Forterra is seeking a Product Security Lead to own security for all Forterra platforms end-to-end. This is a hands-on, leadership role where you will set the security strategy, own the governance and compliance posture, and drive security execution across software, hardware, and devops. You will lead a small team of product security engineers while coordinating a larger cross-functional group of indirect contributors. Additionally, you will serve as Forterra's product security voice to government customers, commercial partners, and executive leadership.

Responsibilities

  • Own the enterprise product security program across multiple autonomous vehicle platforms and business lines—governance, policies, and roadmap.
  • Lead the full ATO and IATT lifecycle across concurrent DoD programs, from control selection and tailoring through evidence generation, POAM management, and government stakeholder coordination.
  • Participate in software release boards as the go/no-go authority for security.
  • Set and own the 12 and 24-month security roadmap, capability maturity planning, and resource forecasting.
  • Brief senior leadership, government stakeholders, and commercial partners on program status, risk posture, and readiness activities.
  • Develop cybersecurity requirements for platforms operating in air-gapped, intermittently connected, and operationally constrained environments.
  • Lead threat modeling across autonomous, embedded, and command and control systems, driving risk assessments that weigh mitigations against mission requirements.
  • Own DISA STIG compliance strategy, evaluating and tailoring applicable checklists into implementable guidance for engineering teams.
  • Own the SBOM generation pipeline and vulnerability management program, including CVE triage, remediation prioritization, and POAM closure.
  • Lead product-level security incident response and coordinate cross-organization remediation with the corporate cybersecurity team.
  • Support contract and sales teams as the pre-sales security SME, contributing to RFP and RFQ responses.
  • Build, lead, and develop the product security team—hire, onboard, mentor, and grow direct reports while fostering a security-first engineering culture.

Requirements

  • 7+ years in product or cybersecurity with demonstrated depth in program leadership.
  • Proven experience owning an ATO end-to-end as the responsible authority.
  • Practical command of NIST 800-37, 800-53, 800-171; DISA STIGs and SRG; eMASS artifact requirements, formats, and review cycles.
  • Demonstrated experience securing embedded, autonomous, or operationally deployed systems, including air-gapped and disconnected environments.
  • Experience building and leading security programs, teams, and functions.
  • Ability to operate at both the strategic and tactical levels simultaneously.
  • Strong executive communication skills—ability to brief senior leadership and stakeholders and defend decision-making.
  • Demonstrated experience with SBOM and vulnerability management in a product engineering environment.
  • Experience driving compliance validation against multiple concurrent frameworks (e.g., NIST, ISO/SAE, CMMC).
  • Active US Security Clearance or eligibility. Must be a US Person as defined under ITAR.

Preferred Qualifications

  • Active CISSP or equivalent senior security certification.
  • ISO/SAE 21434 automotive cybersecurity experience.
  • Experience with multiple ATOs across multiple DoD programs or branches.
  • Familiarity with IEC 62443 commercial cybersecurity engineering standard.
  • Experience managing indirect contributors and cross-functional security execution across large engineering organizations.

Pay

US Salary Range: $175,000 - $200,000

Benefits

  • Premium healthcare benefits with three plan options, including an HSA-eligible plan (Forterra covers 80% of the plan premium for you and your dependents).
  • Basic life/AD&D, short- and long-term disability insurance plans 100% covered by Forterra, with the option to purchase additional life insurance.
  • Generous company holiday calendar, including a winter break in December.
  • Competitive paid time off (PTO) offering 20 days accrued per year.
  • Minimum of 7 weeks fully paid parental leave for birth/adoption.
  • $9k annual tuition reimbursement or professional development stipend.
  • Fully stocked beverage refrigerators.
  • 401(k) retirement savings plan with company match up to 4%.

Similar jobs