Senior DoD Product Security Engineer at Forterra
Clarksburg, MD
—
Jul 21, 2026
Clarksburg, MD
Jul 23, 2026
What this job asks for AI summary
A senior individual-contributor role responsible for end-to-end product security on Department of Defense programs involving autonomous ground vehicles. The position owns the full RMF/ATO lifecycle, sets security architecture direction, writes and traces security requirements through systems engineering, and serves as the primary security authority with both internal engineering teams and government cyber offices. It suits an experienced security engineer with hands-on RMF/ATO ownership, embedded and software security depth, and fluency in NIST and DISA STIG frameworks.
Senior level · 5+ years · Washington-Arlington-Alexandria, DC-VA-MD-WV · Secret clearance · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $152,225 (middle half $125,286–$177,673).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (10)
Location is not explicitly stated in the posting. Forterra is headquartered in the Washington DC metro area (Reston, VA); the CBSA has been set accordingly, but the actual work location should be confirmed with the recruiter.
Clearance: the posting requires the candidate to be a U.S. Person (ITAR) and 'eligible to obtain a U.S. security clearance' — it does not specify the level. Given the DoD/ATO/RMF context, Secret is the minimum plausible gate; the actual required level should be confirmed.
Degree: the posting lists a BS in CS/CE/InfoSec/EE but explicitly accepts 'proof of exceptional skill in lieu of a degree,' so no hard degree requirement is set.
Salary range is described as an estimate based on many factors but no specific figures are published in the posting.
Secure boot and signed firmware are called out as required working knowledge but name no specific product or platform tool, so they are captured under the FIPS 140-3 / TPM/HSM requirement rather than as separate skill entries.
Offensive security skills (reverse engineering, fuzzing, exploit methodologies) appear under Preferred Qualifications and are listed as preferred accordingly.
C, C++, Python, ARM, and x86 appear under Preferred Qualifications ('hands-on depth in one or more of') and are listed as preferred accordingly.
CMMC, ISO/SAE 21434, and IEC 62443 appear under Preferred Qualifications and are listed as preferred accordingly.
The alt SOC (15-1299) reflects that this role blends deep security analysis with embedded/systems security engineering in a way that doesn't fit neatly into the standard Information Security Analyst occupation.
Requires a Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.