Product Security Engineer
Job description
Role Summary
We are looking for a mission-driven Product Security Engineer to embed security into the entire lifecycle of our cutting-edge robotic systems and our command and control system. You will be responsible for hardening our autonomous ground vehicles against cyber threats in complex, contested environments. You will own compliance with our customer's contract requirements for cyber security.
You'll embed with engineering teams to drive threat modeling, define security requirements, prioritize risk, and verify that controls meet contractual and regulatory standards. You'll own our compliance posture (CSEIG v3.0, NIST 800-53/171, DISA STIGs) and prepare the evidence and documentation needed for customer authorization (ATO/ATC).
You'll be the person who translates customer security requirements and industry standards into clear, prioritized work that engineering teams can act on. This is a strategic and analytical role with technical depth. You need to understand how attacks work against embedded systems, networked robots, and C2 architectures, but your primary output is requirements, threat models, verification plans, and compliance artifacts, not production code.
Key Responsibilities
Set and own the security roadmap. Assess the current posture, identify the highest-risk gaps, and sequence the work so the most important things get done first. You won't be able to fix everything at once — knowing what matters most is the job. Threat modeling & risk analysis: Lead threat modeling and attack-tree exercises across our robotic, autonomy, and C2 systems.
Analyze operational concepts to identify security implications. Drive risk assessments that weigh mitigations against mission needs and resource constraints. Security requirements: Translate customer contracts, regulatory standards, and operational threat context into actionable security requirements for engineering teams.
Define security acceptance criteria for features and releases. When an engineer asks why a control matters, explain the threat and the mission rationale. Compliance & authorization: Own the RMF and ATO/ATC lifecycle from control selection and tailoring through evidence generation and government stakeholder coordination.
Map and implement controls aligned with CSEIG v3.0, DISA STIGs, and NIST 800-53/171. Prepare documentation and evidence packages. Manage POA&Ms. Track compliance gaps and drive closure with engineering. You are the company's ATO authority. Secure development lifecycle: Drive security across design, code review, CI/CD, and release.
Establish security gates and review checklists. Participate in software release decisions as the security authority. Partner on supply-chain security, SBOM generation, and vulnerability management. Verification & validation: Define security test plans and acceptance criteria. Audit architectures and code for vulnerabilities.
Drive remediation with engineering teams. Own the solutioning and verify the implementation, even where other teams do the building. Cross-team partnership: Work directly with firmware, platform, autonomy, and C2 teams to ensure security is addressed at the architecture level. Strong enough technically to review architectures, evaluate cryptographic choices, assess OS hardening, and have credible design-level conversations with embedded and software engineers without needing to implement each one yourself.
Customer & standards interface: Serve as the primary point of contact for customer security requirements and compliance questions. Translate feedback from customers, industry standards bodies, and regulatory agencies into engineering action.
Qualifications
5 + years in product security, cybersecurity engineering, or a closely related field, with demonstrated depth in both strategic program ownership and hands-on technical work. Proven experience leading threat modeling and risk assessment for complex systems. Proven experience owning an ATO end-to-end as the responsible authority, or deep hands-on experience across every phase of the RMF/ATO process with readiness to own it.
Practical command of NIST 800-37, 800-53, and 800-171; DISA STIGs and SRGs; and eMASS artifact requirements, formats, and review cycles. Ability to evaluate, tailor, and defend STIG applicability with both customers and internal engineers, and translate control requirements into implementable guidance.
Preferred Qualifications
Experience securing embedded, autonomous, or operationally deployed systems, including air-gapped and disconnected environments. Familiarity with CMMC, CSEIG v3.0, or FIPS 140-3 and cryptographic module validation. Experience with ISO/SAE 21434 or IEC 62443 and the judgment to apply commercial cybersecurity standards where DoD frameworks have gaps.
Active CISSP or equivalent security certification. Experience supporting pre-sales, bids, or RFP responses as a security SME. Experience writing security requirements and tracing them through systems-engineering processes (requirements reviews, design reviews, V&V). Strong communication skills across audiences: engineering teams, executive leadership, and government stakeholders.
Comfortable with ambiguity: You've built or substantially shaped a security program before, or you're ready to. You don't need an established playbook to be effective. Offensive security skills: threat emulation, fuzzing, vulnerability research.
Benefits
Overland AI believes in creating a work environment that you look forward to embracing every day. The salary range for this position is $170K to $200K annually Equity compensation Best-in-class healthcare, dental and vision plans. Unlimited PTO 401k with company match Parental leave Location: This position will be located in Seattle, WA.
Overland AI is an Equal Opportunity Employer. We do not discriminate on the basis of race, color, religion, creed, sex, sexual orientation, gender identity or expression, national origin, age, marital status, disability, genetic information, protected veteran or military status, or any other status protected by applicable law.
This position may involve access to export-controlled technology. Employment is contingent on the ability to comply with U.S. export control laws. Overland AI provides reasonable accommodations for qualified individuals with disabilities and disabled veterans during the application process. Please contact [ peopleops@overland.
ai] to request an accommodation. About Overland AI Founded in 2022 and headquartered in Seattle, Washington, Overland AI is transforming land operations for modern defense. The company leverages over a decade of advanced research in robotics and machine learning, as well as a field-test forward ethos, to deliver combined capabilities for unit commanders.
Our Over. Drive autonomy stack enables ground vehicles to navigate and operate off-road in any terrain without GPS or direct operator control. Our intuitive Over. Watch C2 interface provides commanders with precise coordination capabilities essential for mission success. Overland AI has secured funding from prominent defense tech investors including 8VC and Point 72, and built trusted partnerships with DARPA, the U.
S. Army, Marine Corps, and Special Operations Command. Backed by eight-figure contracts across the Department of Defense, we are strengthening national security by iterating closely with end users engaged in tactical operations.
More jobs at Overland AI
Technical Lead - State Estimation
Overland AI· Seattle, Washington, United States· $200k – $260kTechnical Lead - Compute Platform and Optimization
Overland AI· Seattle, Washington, United States· $200k – $260kSoftware Engineer, Platforms
Overland AI· Seattle, Washington, United States· $140k – $300kSoftware Engineer, Perception (All Levels)
Overland AI· Seattle, Washington, United States· $120k – $300kSoftware Engineer, Mission Autonomy
Overland AI· San Francisco, California, United States· $150k – $250k
More jobs in Seattle
Development Director | Seattle, WA
Arthritis Foundation· Seattle, WA, US· From $99kHeavy Duty Diesel Mechanic
Pros Mechanics· Seattle, Washington, United States· $73k – $94kProduct Manager (AI-Powered Workflow Product)
Talentry· Seattle, United States· $150k – $175kRARE Opportunity in Wallingford for an Excellent Family Assistant! 4 or 5 days/PT or FT !
aniseattle· Seattle - Wallingford, United StatesPhysical Therapist
Serene Healthcare Staffing· Seattle, United States