About This Role
About Firestorm
Firestorm Labs, based in San Diego, California, specializes in advanced additive manufacturing and modular, 3D-printed unmanned aerial systems (UAS) for defense and expeditionary operations. The company is pioneering the development of the first completely modular unmanned aerial system (MUAS) that is fully 3D printed and adaptable to various payloads. Firestorm aims to streamline the UAS manufacturing process, making it faster and more cost-effective while providing scalable and rapidly deployable solutions. Firestorm offers customizable drones that can be quickly modified for different missions, along with mobile, field-deployable 3D printing technologies for on-site manufacturing. The company holds exclusive distribution rights for HP's Multi Jet Fusion 3D printers, positioning itself as the sole provider of these advanced printers for mobile environments. Firestorm serves a range of sectors, including defense, commercial, humanitarian, and medical, focusing on urgent, on-the-ground responses where traditional supply chains may fall short.
Security at Firestorm
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
“Firestorm publicly frames security around protecting defense, classified, controlled-unclassified, cloud, factory, edge, and air-gapped systems. The Staff Platform Security Engineer scope covers identity, access control, secrets management, data protection, system boundaries, Kubernetes/Linux/cloud/edge hardening, software-supply-chain security, CI/CD security controls, threat modeling, vulnerability remediation, and accreditation evidence. The ISSM role emphasizes alert response, POA&M remediation, endpoint security, tool/vendor assessments, incident response, insider-threat participation, training, and NIST SP 800-171, DFARS, and CMMC compliance. No public evidence was found for a security-champions program, developer-first/paved-road language, formal security gates, vulnerability SLAs, or a stated AppSec mission distinct from the broader security program.”
Security Team
Firestorm's publicly documented security function spans platform/product security, IT security operations, information-systems security, facility security, and enterprise security. Publicly identified personnel include Robert Mueller Jr. (Sr DevSecOps/Product Security Manager), Noah Taul (IT & Security Operations Specialist), and Ian Reyes (formerly ISSM/FSO/ITPSO; profile indicates he left Firestorm in August 2026). Firestorm's public careers pages list Staff Platform Security Engineer, Security Engineer, ISSM, and FSO roles. A precise AppSec team size and reporting line are Information not publicly available. Active security-related postings identified as of: at least three—Staff Platform Security Engineer, ISSM, and FSO—with the separate Director of Security posting no longer accepting applications.
Key Initiatives
Documented initiatives and workflows include: building platform security across cloud, factory, edge, and air-gapped environments; implementing identity, access control, secrets management, data protection, and system boundaries; hardening Kubernetes, Linux, cloud, and edge deployments; securing software supply chains; automating CI/CD security controls; conducting threat modeling and vulnerability remediation; supporting accreditation with technical controls, evidence, and system designs; monitoring Microsoft Defender and Sentinel alerts; supporting POA&M remediation; maintaining endpoint security, patching, and Intune policies; assessing new tools, services, and vendors; coordinating incident response; participating in insider-threat monitoring; delivering security education; and maintaining NIST SP 800-171, DFARS, CMMC, NISPOM, and DCSA-related compliance. Firestorm-authored xCell material additionally states that the product uses end-to-end encryption, physical kill switches, and isolated networks. No public evidence was found for a security-champions program, bug-bounty intake, formal vulnerability-management SLA, Jira ownership rule, annual penetration-testing requirement, or AppSec initiative launched during the six months before.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.
Interested in this role?
Apply on LinkedIn