Product Security Engineer - 174338

Clarksburg, Maryland

Zachary Piper Logo

Job Id:
0000174338

Job Category:

Job Location:
Clarksburg, Maryland

Security Clearance:
Secret

Business Unit:
Zachary Piper

Division:
Not Defined

Position Owner:
Jack Lively

Product Security Engineer

Zachary Piper Solutions is seeking a Product Security Engineer to support a leading Defense Technology Company focused on autonomous systems and advanced technologies supporting Department of Defense programs. This is a hybrid position based in Clarksburg, MD. The Product Security Engineer will support cybersecurity initiatives across autonomous vehicle platforms and mission-critical defense programs, helping to ensure products meet security, compliance, and operational requirements throughout the development lifecycle.


Responsibilities of the Product Security Engineer Include:

  • Support product security initiatives across autonomous vehicle platforms and defense technology programs.
  • Assist with DoD RMF, ATO, and IATT activities, including security documentation, control implementation, POA&M management, and coordination with government stakeholders.
  • Perform security assessments, vulnerability analysis, and security reviews throughout the software and hardware development lifecycle.
  • Conduct threat modeling and cybersecurity risk assessments for embedded systems, autonomous platforms, and command-and-control technologies.
  • Support DISA STIG compliance activities and collaborate with software, hardware, and DevOps teams to implement security requirements.
  • Manage vulnerability remediation efforts, including CVE analysis, SBOM validation, risk prioritization, and tracking corrective actions.
  • Assist with security testing activities, including vulnerability scanning, configuration reviews, and secure code review processes.
  • Develop and maintain security documentation, procedures, and technical guidance.
  • Support incident response and forensic investigations involving product-level cybersecurity events.
  • Collaborate with engineering teams to integrate secure development practices and DevSecOps methodologies.
  • Track authorization status, security metrics, and compliance requirements and provide updates to leadership and program stakeholders.
  • Support proposal efforts, customer engagements, and cybersecurity-related technical discussions.

Qualifications of the Product Security Engineer Include:

  • 7+ years of experience in Product Security, Cybersecurity, Information Assurance, Security Engineering, or a related field.
  • Experience supporting DoD RMF, ATO, IATT, or other federal cybersecurity compliance activities.
  • Working knowledge of NIST 800-37, NIST 800-53, NIST 800-171, DISA STIGs, SRGs, and eMASS.
  • Experience conducting vulnerability management, security assessments, threat modeling, or risk analysis activities.
  • Familiarity with embedded systems, autonomous platforms, industrial control systems, or mission-critical technologies.
  • Understanding of secure software development practices and DevSecOps principles.
  • Experience managing or reviewing SBOMs and evaluating software supply chain risks.
  • Strong written and verbal communication skills with the ability to work across technical and non-technical teams.
  • Knowledge of cybersecurity frameworks such as NIST RMF, CMMC, ISO 27001, ISO/SAE 21434, or IEC 62443.
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related field preferred.
  • Security certifications such as Security+, CySA+, CISSP, SSCP, GSEC, or equivalent are highly desirable.

Compensation for the Product Security Engineer Includes:

  • Salary Range: $170,000 - $195,000
  • Comprehensive Benefits: Cigna Medical, Dental, Vision, 401(k), Sick Leave if required by law, and Paid Holidays.

Keywords:

Product Security, Product Security Engineer, Cybersecurity Engineer, Security Engineer, Application Security, DevSecOps, RMF, Risk Management Framework, ATO, Authority to Operate, IATT, NIST 800-37, NIST 800-53, NIST 800-171, DISA STIG, eMASS, SBOM, Vulnerability Management, Threat Modeling, CVE Management, Security Compliance, Embedded Systems Security, Autonomous Systems, Defense Technology, Software Security, Security Assessments, Risk Analysis, CMMC, ISO 27001, ISO/SAE 21434, IEC 62443, Security+, CISSP, Secret Clearance, Department of Defense, DoD Cybersecurity.


#LI-JL1

Apply For This Position

Personal Information

Required
Required
Required
Required
Required
Required
Required

Additional Details

Required
Required
Required

Voluntary Self-identification Form

Required
Required
Required

Veteran Status *

Discharge Date:

Resume Upload

Please note only files with .pdf, .docx, or .doc file extensions are accepted.

Currently selected file:

Don't have a resume?