Senior DOD Product Security Engineer
Listed on 2026-09-21
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations, Systems Engineer
Zachary Piper Solutions is seeking a Senior DoD Product Security Engineer to join a leading Defense Technology Company specializing in autonomous systems and advanced technology supporting Department of Defense programs. This is a hybrid position based in Clarksburg, MD, requiring 3 days per week onsite and 2 days remote
. The Senior DoD Product Security Engineer will support product security across autonomous and embedded systems while owning RMF and ATO activities for assigned DoD programs. This individual will work closely with software, hardware, systems, and Dev Ops teams to incorporate security throughout the product lifecycle.
- Lead RMF and ATO activities for assigned DoD programs from initial security controls through authorization.
- Define security architecture, controls, and technical requirements across hardware and software systems.
- Partner with engineering teams to incorporate security requirements throughout product design and development.
- Develop and maintain security documentation, evidence, POA&Ms, and authorization artifacts.
- Lead threat modeling and risk assessments for autonomous, embedded, and command-and-control systems.
- Serve as a DISA STIG SME and translate security requirements into actionable engineering guidance.
- Oversee security monitoring, logging, secure update strategies, and vulnerability remediation efforts.
- Support SBOM, software supply-chain security, and secure SDLC/Dev Sec Ops practices.
- Review embedded and application systems for security vulnerabilities and coordinate remediation.
- Serve as a primary security resource for government cyber and program stakeholders.
- 5+ years of security engineering or related technical cybersecurity experience.
- Strong hands-on experience with DoD RMF and the ATO lifecycle.
- Working expertise with NIST 800-37, 800-53, 800-171, DISA STIGs, and eMASS.
- Technical security experience across both hardware and software environments.
- Experience securing embedded, autonomous, disconnected, or operationally deployed systems.
- Ability to develop technical security requirements and communicate them effectively to engineering teams.
- Experience with SBOMs, software supply-chain security, vulnerability management, and secure SDLC practices.
- Familiarity with SAST/DAST, code review, CI/CD, and Dev Sec Ops environments.
- Knowledge of cryptographic security, secure boot, signed firmware, and key-management technologies.
- Must be be eligible to obtain a U.S. security clearance.
- Previous experience owning a DoD ATO through the full authorization process.
- Familiarity with CMMC requirements.
- Knowledge of ISO/SAE 21434 and/or IEC 62443 security standards.
- Experience securing embedded, disconnected, industrial, or mission-critical systems.
- CISSP or comparable cybersecurity certification.
- Experience with offensive security, reverse engineering, fuzzing, or exploit analysis.
- Hands-on experience with C, C++, Python, ARM, x86, and/or cryptography.
- Salary Range: $145,000-$175,000
depending on experience - Comprehensive Benefits:
Cigna Medical, Dental, Vision, 401k, Sick Leave if required by law, and holidays
This job opens for applications 9/10/26. Applications for this job will be accepted for at least 30 days from the posting date.
#LI-MR1
#LI-HYBRID
KeywordsSenior Product Security Engineer, DoD Product Security, Security Engineer, Cybersecurity Engineer, Product Security, RMF, Risk Management Framework, ATO, Authority to Operate, NIST 800-37, NIST 800-53, NIST 800-171, DISA STIG, eMASS, POA&M, Embedded Systems Security, Autonomous Systems, Hardware Security, Software Security, Threat Modeling, SBOM, Vulnerability Management, CVE, Secure SDLC, Dev Sec Ops , SAST, DAST, CI/CD, CMMC, Cryptography, Secure Boot, Firmware Security, C, C++, Python, ARM, x86, CISSP, DoD, Defense Technology, Secret Clearance
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).