Sr. Security Engineer

procurementsciences

United States

On-site

USD 180,000 - 240,000

Full time

8 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Procurement Sciences is seeking an experienced Security Engineer to own the engineering side of security across the platform. You will manage vulnerability management, application security, and AI/LLM security, reporting to the CISO and collaborating with Platform Engineering, Product, and DevOps.

You will ensure FedRAMP Moderate authorization posture and drive security as a product differentiator. The role requires hands-on expertise across vulnerability management, AppSec, cloud security, and

Qualifications

  • 5+ years of hands-on security engineering with depth in at least three areas: vulnerability management, AppSec, cloud security, security automation, or detection engineering.
  • Strong cloud-native security experience (Azure and/or GCP) including Kubernetes, container hardening, and IaC security.
  • Experience with vulnerability scanners and security testing tools (SAST/DAST/SCA, CSPM, CWPP, EDR, SIEM, secret scanning).

Responsibilities

  • Own vulnerability management end-to-end including pen tests, MTTR, and risk reporting.
  • Lead application security: SAST/DAST/secret scanning, threat modeling, secure code review.
  • Oversee AI/LLM security across models, prompts, and provider APIs.
  • Manage cloud/infrastructure security in Azure/GCP (FedRAMP/GCC High) including IAM, network segmentation, encryption, and Kubernetes security.
  • Develop security automation: CI/CD gates, detection-as-code, SOAR, and evidence collection for audits.
  • Support incident response and maintain IR plan across endpoints, cloud, and apps.
  • Ensure compliance mappings to NIST 800-53, SSPs/POA&M, and SOC 2 through technical controls.

Skills

Vulnerability management
Application security
Cloud security
Security automation
Detection engineering
Python/Go/TypeScript/Bash
US citizenship

Tools

SAST
DAST
SCA
CSPM
CWPP
EDR
SIEM
Secret scanning

Job description

Company Overview

Procurement Sciences is at the forefront of transforming the multi-billion-dollar government contracting industry with Awarded AI, our cutting-edge platform designed to help businesses excel in government sales. We simplify complex processes, drive revenue growth, and deliver real cost savings through unmatched efficiency. As a leading venture-backed SaaS company founded by seasoned GovCon experts, we are not just participants in the AI revolution; we are shaping it by solving the industry's toughest challenges. Our "One Team, One Fight" culture values creativity, accountability, and forward-thinking, and we invite driven builders and innovators to help us develop high-performing teams. Ranked among the top 10 percent of fastest-growing SaaS companies and on a clear path to becoming a unicorn, we are seeking top talent to join our early team and play a key role in building the next great AI software company.

At Procurement Sciences, innovation is more than a buzzword; it's in our DNA, where AI serves as a playground for challenging norms and shaping the future of GovCon. If you're ready to join a team that's reshaping the industry landscape, leading in AI, and on the path to becoming the next unicorn, Procurement Sciences is your new home. Join us on our mission to democratize government contracting success and shape the future of this vital sector.

About the Role

You'll be the technical backbone of our security program. This is a hands‑on role owning the engineering side of security across the whole platform: vulnerability management, application security, AI/LLM security, cloud hardening, detection, and automation. You'll report to the CISO and work closely with Platform Engineering, Product, and DevOps.

We process sensitive government contracting data for defense and civilian agencies and hold FedRAMP Moderate authorization. Security is a product differentiator here, not a cost center. Your job is to keep that posture strong without slowing engineering down.

What You'll Own

Vulnerability management end to end, including pen tests, CSPM/CWPP tooling (Wiz), MTTR, and risk reporting for leadership and customers.

Application security: SAST, DAST, SCA, secret scanning, threat modeling, secure code review, and developer training. You're the person engineers come to with security questions.

AI/LLM security across our model integrations, RAG pipelines, and LLM provider APIs (Anthropic, Google Vertex AI, OpenAI). Prompt injection, data exfiltration, model abuse, output guardrails, and evaluating new AI features before they ship.

Cloud and infrastructure security in Azure/AKS and GCP under FedRAMP and GCC High requirements: IAM, network segmentation, encryption, Kubernetes runtime protection, IaC scanning, WAF, and zero‑trust design with the DevOps team.

Security automation: CI/CD security gates, detection‑as‑code, SOAR, custom tooling, and automated compliance evidence collection for SOC 2, FedRAMP, and CMMC.

Detection and response across endpoints (SentinelOne), cloud, and application layers. Lead or support incident response and keep the IR plan current.

Compliance and customer trust: technical controls mapped to NIST 800‑53, SSPs and POA&Ms, continuous monitoring, and clear technical answers to customer security assessments.

What we're looking for

Required:

  • 5+ years of hands‑on security engineering with depth in at least three of: vulnerability management, AppSec, cloud security, security automation, detection engineering.
  • Strong cloud‑native security experience (Azure and/or GCP preferred), including Kubernetes, container hardening, and IaC security.
  • Proven experience operating vulnerability scanners, SAST/DAST/SCA, CSPM/CWPP, EDR, SIEM, and secret scanning.
  • Enough Python, Go, TypeScript, or Bash to build automation and custom tooling.
  • Clear communication with developers and customers alike.
  • US citizenship (required for FedRAMP and defense customers).

Preferred:

  • Experience securing AI/ML systems and LLM applications (OWASP Top 10 for LLM, MITRE ATLAS).
  • SaaS security background at a B2B or GovTech company.
  • Working knowledge of FedRAMP, CMMC, NIST 800‑53, NIST 800‑171, and SOC 2, and how technical controls map to them.
  • FedRAMP or CMMC assessment support from the engineering side.
  • GCC High, Azure Government, or AWS GovCloud experience.
  • Familiarity with DFARS 252.204‑7012, CUI handling, and ITAR/EAR.
  • Certifications such as OSCP, GIAC, cloud security certs, or CISSP.
  • Prior founding or early security hire at a startup.
Who you are

A builder, not just an auditor. Comfortable making judgment calls without perfect information. An owner who sees a gap, flags it, and fixes it. Pragmatic about risk, with a default of "Yes, and here's what we need to do first." Someone who earns trust by being helpful, direct, and reliable.

Compensation and Benefits:

Compensation DOE.

Competitive salary with performance based incentive plan and stock options in a rapidly growing, venture‑backed co

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Security Engineer
Sr. Security Engineer

Procurement Sciences • Lehi (UT)

Hybrid
USD 140,000 - 200,000
Remote work
Stock options
Health insurance
+1
Senior Security Engineer, Platforms & AI
Senior Security Engineer, Platforms & AI

Spinwheel Solutions Inc. • Oakland (CA)

On-site
USD 140,000 - 190,000
Remote-First
Salary & Equity
Unlimited PTO
+2
Senior Software Security Engineer
Senior Software Security Engineer

Xcede • San Francisco (CA)

On-site
USD 120,000 - 160,000
Security Engineer - Product Security (Senior)
Security Engineer - Product Security (Senior)

Cogent • All (MO)

On-site
USD 100,000 - 300,000
Security Administrator
Security Administrator

aegis-ai • United States

On-site
USD 65,000 - 90,000
Security Engineer
Security Engineer

Clera • San Francisco (CA)

On-site
USD 180,000 - 250,000
Medical, dental, vision coverage
401k
Visa sponsorship
+2
Senior Security Engineer
Senior Security Engineer

Mach7 Technologies • New Jersey

On-site
USD 120,000 - 190,000
Security Administrator
Security Administrator

Aegis AI • United States

On-site
USD 65,000 - 90,000
Security Research Engineer
Security Research Engineer

AI Security Assurance • Northern (KY)

Hybrid
USD 160,000 - 230,000
Remote‑first
Life Insurance
Disability coverage
+1
SENIOR ENGINEER, APPLICATION SECURITY
SENIOR ENGINEER, APPLICATION SECURITY

Cvent • United States

Hybrid
USD 120,000 - 160,000