Senior DoD Product Security Engineer

Piper Companies

Clarksburg (MD)

Hybrid

USD 145,000 - 175,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Cigna Medical, Dental, Vision
401(k)
Paid Holidays

Job summary

Zachary Piper Solutions seeks a Senior DoD Product Security Engineer to secure autonomous and embedded platforms across the lifecycle. You will lead RMF/ATO activities for mission-critical DoD programs and work across software, hardware, and DevOps teams to embed cybersecurity requirements into architecture and deployment.

Responsibilities cover threat modeling, vulnerability management, SBOM and supply-chain security, and secure SDLC practices. Hybrid work in Clarksburg, MD with 3 days onsite.

Qualifications

  • Bachelor's degree in cybersecurity, computer science, engineering, information systems, or a related technical field.
  • 5+ years of cybersecurity, product security, systems security, or security engineering experience.
  • Hands-on experience supporting DoD RMF and ATO lifecycle activities.
  • Strong knowledge of NIST 800-37, NIST 800-53, NIST 800-171, DISA STIGs, and eMASS.
  • Experience securing embedded, autonomous, disconnected, or mission-critical operational systems.
  • Ability to develop technical security requirements and communicate with engineering teams.
  • Experience with vulnerability management, SBOMs, software supply-chain security, and secure SDLC practices.
  • Familiarity with SAST, DAST, code reviews, CI/CD pipelines, and DevSecOps methodologies.
  • Knowledge of cryptographic technologies, secure boot architectures, signed firmware, and key management solutions.

Responsibilities

  • Lead RMF and ATO activities for assigned DoD programs through successful authorization.
  • Define security architectures, control implementations, and cybersecurity requirements across software and hardware systems.
  • Partner with engineering teams to incorporate security requirements throughout product design and development.
  • Develop and maintain SSPs, POA&Ms, security evidence packages, and authorization artifacts.
  • Conduct threat modeling, risk assessments, and attack surface analysis for autonomous and embedded systems.
  • Serve as a DISA STIG subject matter expert and translate security requirements into engineering solutions.
  • Oversee vulnerability management, security monitoring, logging, and remediation activities.
  • Support SBOM generation, software supply-chain security initiatives, and secure SDLC processes.
  • Review application, firmware, and embedded systems for vulnerabilities and compliance risks.
  • Act as a primary cybersecurity interface for government customers, assessors, and program leadership.

Skills

Cybersecurity
Product Security
RMF/ATO
Vulnerability Mgmt
SBOM / Supply Chain
DevSecOps
SAST & DAST
Secure SDLC
Embedded Systems
Cryptography

Education

Bachelor's degree in cybersecurity/CS/engineering

Tools

NIST 800-37/53/171
DISA STIGs
eMASS

Job description

Senior DoD Product Security Engineer

Zachary Piper Solutions is seeking a Senior DoD Product Security Engineer to join a leading Defense Technology Company specializing in autonomous systems and advanced technologies supporting Department of Defense programs. This is a hybrid position based in Clarksburg, MD, requiring 3 days onsite and 2 days remote per week.


The Senior DoD Product Security Engineer will be responsible for securing autonomous and embedded platforms across the product lifecycle while leading RMF and ATO activities for mission-critical defense programs. This role will partner closely with software, hardware, systems, and DevOps engineering teams to ensure cybersecurity requirements are integrated into product architecture, development, and deployment efforts.


Responsibilities


  • Lead RMF and ATO activities for assigned DoD programs through successful authorization.

  • Define security architectures, control implementations, and cybersecurity requirements across software and hardware systems.

  • Partner with engineering teams to incorporate security requirements throughout product design and development.

  • Develop and maintain SSPs, POA&Ms, security evidence packages, and authorization artifacts.

  • Conduct threat modeling, risk assessments, and attack surface analysis for autonomous and embedded systems.

  • Serve as a DISA STIG subject matter expert and translate security requirements into engineering solutions.

  • Oversee vulnerability management, security monitoring, logging, and remediation activities.

  • Support SBOM generation, software supply-chain security initiatives, and secure SDLC processes.

  • Review application, firmware, and embedded systems for vulnerabilities and compliance risks.

  • Act as a primary cybersecurity interface for government customers, assessors, and program leadership.


Required Qualifications


  • Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Systems, or a related technical field.

  • 5+ years of cybersecurity, product security, systems security, or security engineering experience.

  • Hands‑on experience supporting DoD RMF and ATO lifecycle activities.

  • Strong knowledge of NIST 800-37, NIST 800-53, NIST 800-171, DISA STIGs, and eMASS.

  • Experience securing embedded, autonomous, disconnected, or mission‑critical operational systems.

  • Ability to develop technical security requirements and communicate effectively with engineering organizations.

  • Experience with vulnerability management, SBOMs, software supply‑chain security, and secure SDLC practices.

  • Familiarity with SAST, DAST, code reviews, CI/CD pipelines, and DevSecOps methodologies.

  • Knowledge of cryptographic technologies, secure boot architectures, signed firmware, and key management solutions.


Preferred Qualifications


  • Experience owning and maintaining a DoD ATO through the complete authorization lifecycle.

  • Familiarity with CMMC compliance requirements.

  • Working knowledge of ISO/SAE 21434 and/or IEC 62443 security frameworks.

  • Experience securing industrial, embedded, disconnected, or operational technology environments.

  • CISSP, Security+, CASP+, or comparable cybersecurity certifications.

  • Experience with offensive security testing, fuzzing, exploit development, reverse engineering, or vulnerability research.

  • Hands‑on programming experience with C, C++, Python, ARM, x86, and secure software development practices.


Compensation & Benefits


  • Salary Range: $145,000 - $175,000

  • Comprehensive benefits package including:

    • Cigna Medical, Dental, and Vision

    • 401(k)

    • Paid Holidays

    • Sick Leave (where required by law)

    • Additional company-sponsored benefits




Keywords

Senior Product Security Engineer, DoD Product Security Engineer, Cybersecurity Engineer, Product Security, RMF, Risk Management Framework, ATO, Authority to Operate, eMASS, NIST 800-37, NIST 800-53, NIST 800-171, DISA STIG, POA&Ms, SSP, Embedded Security, Autonomous Systems Security, Mission Systems Security, Threat Modeling, Vulnerability Management, SBOM, Supply Chain Security, Secure SDLC, DevSecOps, SAST, DAST, CI/CD, CMMC, Cryptography, Secure Boot, Firmware Security, Reverse Engineering, Fuzzing, CISSP, Defense Technology, Embedded Systems, Secret Clearance.


#LI-JL1

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior DOD Product Security Engineer
Senior DOD Product Security Engineer

Piper Companies • Clarkburg (MS)

Hybrid
USD 145,000 - 175,000
Comprehensive benefits
Hybrid work schedule
Holidays & sick leave
Product Security Engineer
Product Security Engineer

Piper Companies • Clarksburg (MD)

Hybrid
USD 170,000 - 195,000
Cigna Medical
Dental
Vision
+2
Product Security Lead
Product Security Lead

Piper Companies • Clarksburg (MA)

Hybrid
USD 170,000 - 195,000
Comprehensive benefits
Hybrid work arrangement
Product Security Lead
Product Security Lead

Piper Companies • Clarksburg (MD)

Hybrid
USD 170,000 - 195,000
Senior DoD Product Security Engineer – Hybrid (RMF/ATO)
Senior DoD Product Security Engineer – Hybrid (RMF/ATO)

Piper Companies • Clarksburg (MD)

Hybrid
USD 145,000 - 175,000
Cigna Medical, Dental, Vision
401(k)
Paid Holidays
Product Security Engineer - 174170
Product Security Engineer - 174170

Zachary Piper Solutions • Colorado Springs (CO), Northern (KY)

Hybrid
USD 95,000 - 125,000
PTO
Paid holidays
Medical insurance
+5
Senior DoD Product Security Engineer – RMF/ATO Lead
Senior DoD Product Security Engineer – RMF/ATO Lead

Piper Companies • Clarkburg (MS)

Hybrid
USD 145,000 - 175,000
Comprehensive benefits
Hybrid work schedule
Holidays & sick leave
Product Security Engineer
Product Security Engineer

Piper Companies • Colorado Springs (CO)

On-site
USD 110,000 - 130,000
Medical benefits
401k Plan
Paid time off
+1
Product Security Engineer - 174184
Product Security Engineer - 174184

Zachary Piper Solutions • Colorado Springs (CO), Northern (KY)

Hybrid
USD 110,000 - 130,000
Medical, Dental, Vision
401k Plan
PTO
+2
Product Security Engineer - 174520
Product Security Engineer - 174520

Zachary Piper Solutions • Colorado Springs (CO), Northern (KY)

Hybrid
USD 110,000 - 130,000