Product Security Lead
Clarksburg, Maryland
Job Id:
174192
Job Category:
Cyber Security
Job Location:
Clarksburg, Maryland
Security Clearance:
Secret
Business Unit:
Zachary Piper LLC DBA ZP Group
Division:
Federal Staffing
Position Owner:
Madeline Remington
Zachary Piper Solutions is seeking a Product Security Lead to join a leading Defense Technology Company specializing in autonomous systems and advanced technology supporting Department of Defense programs. This is a hybrid position based in Clarksburg, MD. The Product Security Lead will oversee security efforts across autonomous vehicle platforms and mission-critical defense programs, including security strategy, DoD RMF/ATO initiatives, and product security requirements. This individual will work closely with software, hardware, DevOps, and program teams to strengthen security throughout the product lifecycle.
Responsibilities of the Product Security Lead Include:
- Lead and advance the product security program across multiple autonomous vehicle platforms, including security governance, policies, standards, and long-term planning.
- Manage DoD ATO and IATT efforts across multiple programs, including security control selection, documentation, POA&M tracking, and coordination with government stakeholders.
- Serve as a key security authority during software release reviews and evaluate products for overall security readiness.
- Develop product security roadmaps and identify future capability, staffing, and resource requirements.
- Define cybersecurity requirements for systems operating in air-gapped, disconnected, intermittently connected, and other mission-constrained environments.
- Lead threat modeling and risk assessments across autonomous, embedded, and command-and-control technologies.
- Oversee DISA STIG compliance and translate security requirements into actionable guidance for software, hardware, and DevOps engineering teams.
- Manage SBOM and vulnerability management processes, including CVE assessment, remediation prioritization, and POA&M resolution.
- Lead product-level security incident response efforts in coordination with the corporate cybersecurity team.
- Communicate security posture, program risks, authorization progress, and readiness to senior leadership, government customers, and external partners.
- Serve as a product security SME for customer engagements, proposals, RFPs, and RFQs.
- Help build and develop the product security team through hiring, mentoring, and establishing security-focused engineering practices.
Qualifications of the Product Security Lead Include:
- 7+ years of experience in Product Security or Cybersecurity, including experience leading security programs or teams.
- Proven experience managing a DoD ATO through the full authorization lifecycle.
- Strong knowledge of NIST 800-37, 800-53, 800-171, DISA STIGs/SRGs, and eMASS requirements and documentation.
- Hands-on experience securing embedded, autonomous, or operationally deployed systems, including disconnected or air-gapped environments.
- Experience with SBOM processes, vulnerability management, threat modeling, and security risk assessments within a product engineering environment.
- Ability to work effectively at both the technical engineering level and strategic leadership level.
- Experience supporting multiple cybersecurity and compliance frameworks, including NIST, CMMC, and/or ISO/SAE.
- Strong communication skills with the ability to present technical security risks and recommendations to senior leadership and government stakeholders.
- CISSP or comparable senior-level cybersecurity certification is preferred.
- Must be eligible to obtain a U.S. security clearance; an active Secret clearance is preferred but not required.
Compensation for the Product Security Lead Include:
- Salary Range: $170,000-$195,000
- Comprehensive Benefits: Cigna Medical, Dental, Vision, 401k, Sick Leave if required by law, and holidays.
This job opens for applications 9/10/26. Applications for this job will be accepted for at least 30 days from the posting date.
#LI-MR1
#LI-HYBRID
Keywords: Product Security, Product Security Lead, Product Security Engineer, Cybersecurity, Cyber Security, DoD Cybersecurity, RMF, Risk Management Framework, ATO, Authority to Operate, IATT, NIST 800-37, NIST 800-53, NIST 800-171, DISA STIG, eMASS, SBOM, Vulnerability Management, CVE, POA&M, Threat Modeling, Embedded Systems Security, Autonomous Systems, Automotive Cybersecurity, DevSecOps, CMMC, ISO/SAE 21434, IEC 62443, DoD, Defense Technology, Security Engineering, CISSP, CUI, ITAR, Secret Clearance