2 months ago
Clarksburg, MD, USASenior
Base Salary
$145k - $175k/yr
Responsibilities
- Own the RMF and ATO lifecycle from control selection and tailoring through implementation, POA&M management, evidence, reviews, and authorization.
- Serve as the security SME and primary point of contact for engineering teams and government cyber or program offices.
- Own secure architecture and define security controls, requirements, mitigations, and implementation direction across hardware and software.
- Drive secure-by-design architecture for air-gapped, offline, disconnected, embedded, autonomy, and command-and-control systems.
- Write and trace security requirements through systems-engineering processes, design reviews, verification, and validation.
- Lead threat modeling and risk assessments, balancing security mitigations with mission needs.
- Evaluate, tailor, communicate, and defend DISA STIG applicability and implementation approaches.
- Own solutioning and verify implementation of security monitoring, logging, detection, secure updates, and vulnerability management.
- Partner on software supply-chain security, SBOMs, SAST/DAST, code review, CI/CD, and DevSecOps improvements.
- Audit embedded and application code for vulnerabilities and drive remediation with internal teams and vendors.
- Collaborate with systems, safety, test, and DevOps teams to meet product- and program-level security requirements.
Requirements
- 5+ years of experience in security engineering or a closely related field; equivalent demonstrated skill may substitute for exact tenure.
- Hands-on RMF and ATO experience, preferably ownership of a complete ATO package end-to-end.
- Practical command of NIST 800-37, NIST 800-53, NIST 800-171, DISA STIGs, and eMASS artifact requirements and review cycles.
- Demonstrated depth in both hardware and software security, including identifying and mitigating high-impact vulnerabilities.
- Ability to write clear security requirements and explain security rationale and implementation guidance to software and systems engineers.
- Experience with software supply-chain risk management, SBOMs, secure-SDLC practices, SAST/DAST, code review, and CI/CD.
- Systems-engineering fluency involving requirements, design reviews, and traceability.
- Working knowledge of FIPS 140-3, cryptographic module validation, TPM/HSM-backed key management, secure boot, and signed firmware.
- Preferred familiarity with CMMC, ISO/SAE 21434, IEC 62443, disconnected or industrial systems, and CISSP or a similar certification.
- Preferred offensive-security experience with disassembly, reverse engineering, fuzzing, and common exploit methodologies.
- Hands-on experience in one or more of C, C++, Python, ARM, x86, and cryptography.
- Must be a U.S. Person as defined under ITAR and eligible to obtain a U.S. security clearance.
- Bachelor's degree in Computer Science, Computer Engineering, Information Security, Electrical Engineering, or a related field, or proof of exceptional skill in lieu of a degree.
Benefits
- U.S. salary range is $145,000-$175,000 annually, excluding this benefits list's non-base compensation details.
- Hybrid schedule in Clarksburg, MD: three days per week onsite and two days remote.
- Three premium healthcare plan options, including an HSA-eligible plan, with Forterra covering 80% of premiums for the employee and dependents.
- Company-paid basic life/AD&D and short- and long-term disability insurance, with additional life insurance available for purchase.
- Company holiday calendar including a December winter break.
- 20 accrued paid-time-off days per year.
- At least seven weeks of fully paid parental leave for birth or adoption.
- $9,000 annual tuition reimbursement or professional development stipend.
- 401(k) plan with traditional, Roth, and after-tax deferral options and company matching up to 4%.
- Stock equity is included in most full-time, high-demand roles.
About Forterra
Forterra builds autonomous mission systems for defense and industrial ground operations, including self-driving kits for land vehicles and coordinated robotic swarms. It develops mission-critical hardware and software for autonomy in GPS-denied and contested environments, supporting military logistics, convoying, and yard/drayage use cases. Founded in 2002 and headquartered in Clarksburg, Maryland, the privately held company serves U.S. and allied government programs alongside commercial fleet operators.
