- Location
- Lehi, Utah, United States
- Workplace
- Remote
- Employment
- Full time
- Level
- Senior
- Posted
- 3 weeks ago
About this role
Company Overview
Procurement Sciences is at the forefront of transforming the multi-billion-dollar government contracting industry with Awarded AI, our cutting-edge platform designed to help businesses excel in government sales. We simplify complex processes, drive revenue growth, and deliver real cost savings through unmatched efficiency. As a leading venture-backed SaaS company founded by seasoned GovCon experts, we are not just participants in the AI revolution; we are shaping it by solving the industry’s toughest challenges. Our “One Team, One Fight” culture values creativity, accountability, and forward-thinking, and we invite driven builders and innovators to help us develop high-performing teams. Ranked among the top 10 percent of fastest-growing SaaS companies and on a clear path to becoming a unicorn, we are seeking top talent to join our early team and play a key role in building the next great AI software company.
At Procurement Sciences, innovation is more than a buzzword; it's in our DNA, where AI serves as a playground for challenging norms and shaping the future of GovCon. If you’re ready to join a team that’s reshaping the industry landscape, leading in AI, and on the path to becoming the next unicorn, Procurement Sciences is your new home. Join us on our mission to democratize government contracting success and shape the future of this vital sector.
About the Role
You'll be the technical backbone of our security program. This is a hands-on role owning the engineering side of security across the whole platform: vulnerability management, application security, AI/LLM security, cloud hardening, detection, and automation. You'll report to the CISO and work closely with Platform Engineering, Product, and DevOps.
We process sensitive government contracting data for defense and civilian agencies and hold FedRAMP Moderate authorization. Security is a product differentiator here, not a cost center. Your job is to keep that posture strong without slowing engineering down.
What You’ll Own
Vulnerability management end to end, including pen tests, CSPM/CWPP tooling (Wiz), MTTR, and risk reporting for leadership and customers.
Application security: SAST, DAST, SCA, secret scanning, threat modeling, secure code review, and developer training. You're the person engineers come to with security questions.
AI/LLM security across our model integrations, RAG pipelines, and LLM provider APIs (Anthropic, Google Vertex AI, OpenAI). Prompt injection, data exfiltration, model abuse, output guardrails, and evaluating new AI features before they ship.
Cloud and infrastructure security in Azure/AKS and GCP under FedRAMP and GCC High requirements: IAM, network segmentation, encryption, Kubernetes runtime protection, IaC scanning, WAF, and zero-trust design with the DevOps team.
Security automation: CI/CD security gates, detection-as-code, SOAR, custom tooling, and automated compliance evidence collection for SOC 2, FedRAMP, and CMMC.
Detection and response across endpoints (SentinelOne), cloud, and application layers. Lead or support incident response and keep the IR plan current.
Compliance and customer trust: technical controls mapped to NIST 800-53, SSPs and POA&Ms, continuous monitoring, and clear technical answers to customer security assessments.
What we're looking for
Required:
5+ years of hands-on security engineering with depth in at least three of: vulnerability management, AppSec, cloud security, security automation, detection engineering.
Strong cloud-native security experience (Azure and/or GCP preferred), including Kubernetes, container hardening, and IaC security.
Proven experience operating vulnerability scanners, SAST/DAST/SCA, CSPM/CWPP, EDR, SIEM, and secret scanning.
Enough Python, Go, TypeScript, or Bash to build automation and custom tooling.
Clear communication with developers and customers alike.
US citizenship (required for FedRAMP and defense customers).
Preferred:
Experience securing AI/ML systems and LLM applications (OWASP Top 10 for LLM, MITRE ATLAS).
SaaS security background at a B2B or GovTech company.
Working knowledge of FedRAMP, CMMC, NIST 800-53, NIST 800-171, and SOC 2, and how technical controls map to them.
FedRAMP or CMMC assessment support from the engineering side.
GCC High, Azure Government, or AWS GovCloud experience.
Familiarity with DFARS 252.204-7012, CUI handling, and ITAR/EAR.
Certifications such as OSCP, GIAC, cloud security certs, or CISSP.
Prior founding or early security hire at a startup.
Who you are
A builder, not just an auditor. Comfortable making judgment calls without perfect information. An owner who sees a gap, flags it, and fixes it. Pragmatic about risk, with a default of "Yes, and here's what we need to do first." Someone who earns trust by being helpful, direct, and reliable.
Compensation and Benefits:
Compensation DOE.
Competitive salary with performance based incentive plan and stock options in a rapidly growing, venture-backed company.
Comprehensive health plan, ensuring you and your loved ones are well taken care of.
Flexible work arrangements, including full remote work capabilities, to balance your professional and personal life.
Extensive professional development opportunities, providing a fast track for career advancement.
Notice: Background Check Required
As part of our employment process, a background check is required. The background check may include a review of your credit history, criminal records, and employment verification, among other items. This check is conducted in compliance with the Fair Credit Reporting Act (FCRA). By applying for this position, you acknowledge and consent to this process.
Procurement Sciences is an equal opportunity employer and is committed to a diverse and inclusive workplace. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or protected veteran status. We encourage candidates from all backgrounds to apply
As published by Procurement Sciences AI. Applications are handled on their site.
Skills this posting mentions
About Procurement Sciences AI
Procurement Sciences is redefining how government contractors find, win, and deliver with AI at their side. Built for GovCon, by former GovCon professionals, our mission is simple: to help businesses win more, work smarter, and stay ahead in an increasingly competitive federal market. Our flagship platform, Awarded AI, is the first AI-native operating system purpose-built for government contracting. It streamlines the entire lifecycle - from opportunity discovery and bid/no-bid analysis to proposal automation, compliance reviews, and post-award delivery - all within one secure, integrated platform. Trusted by hundreds of leading contractors, including nearly 25% of the Top 100, Awarded AI has already supported over $3 billion in AI-assisted contract wins. 💡 AI that works the way GovCon does: ✅ Automates manual proposal and capture tasks 📊 Improves decision-making through real-time intelligence 🛡️ Ensures full compliance with federal requirements 🚀 Empowers teams with unlimited training and AI upskilling With secure U.S.-based infrastructure, FedRAMP-aligned architecture, and support from a team of seasoned GovCon experts, Procurement Sciences enables every organization to confidently adopt AI without compromising trust or compliance. Join the next generation of government contractors using AI to work faster, smarter, and more strategically. Procurement Sciences - Built for GovCon. By GovCon.
All 4 openings at Procurement Sciences AIOne click, then it is written
Apply to Procurement Sciences AI with a resume written for this role.
Queue Sr. Security Engineer and I read the posting, rewrite your resume against it, draft the cover letter, and score the fit. Then you press send, or press one button and I fill in Procurement Sciences AI’s form for you.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- 25 sent a week, free
- No card
- Nothing sent until you say so
More roles at Procurement Sciences AI
See all- Yesterday
- Last week
- Last week
Similar roles elsewhere
See morePut this to work
Paste your career in once. Every application after that is written for you.
Drop a resume or a LinkedIn URL. I rank the live openings against it, rewrite the resume and write a cover letter for the best of them, and fill in the employer's form when you press the button. You read, you decide what goes out.
01Drop your resume
A PDF or a LinkedIn URL. About a minute, once.
02I rank the openings
Every weekday morning, the live catalog scored against your history. Up to 20 worth your time, not two hundred links.
03Each one is written up
Resume rewritten for the posting, a cover letter, a fit score. Press send, or let me fill in the form.
- New matches ranked and written before you are up.
- Every bullet stays inside what your history supports. Nothing invented.
- Queued, submitted, interviewing, offer: one screen, not a spreadsheet.
500 free credits on sign-up. No card. Nothing is sent until you say so.
Listed from the job board Procurement Sciences AI publishes. Refolk is not the employer and does not handle their hiring. Applications go to Procurement Sciences AI directly.