Back to Jobs
Procurement Sciences
Engineering & Architecture 3h ago

Security Engineering Lead (AI & Cloud Security)

Procurement Sciences
United StatesUnited States
Full-time
DOE (Determined by Experience)
Senior-Level

Job Description

Key Skills Required

Master these to land this role

FedRAMPAI & Machine LearningCybersecuritySecurity AutomationCloud Security

Want to know if you're a match for this job?

Calculate My Match Score

You'll be the technical backbone of our security program. This is a hands-on role owning the engineering side of security across the whole platform: vulnerability management, application security, AI/LLM security, cloud hardening, detection, and automation. You'll report to the CISO and work closely with Platform Engineering, Product, and DevOps.

We process sensitive government contracting data for defense and civilian agencies and hold FedRAMP Moderate authorization. Security is a product differentiator here, not a cost center. Your job is to keep that posture strong without slowing engineering down.

What You’ll Own

  • Vulnerability management end to end, including pen tests, CSPM/CWPP tooling (Wiz), MTTR, and risk reporting for leadership and customers.
  • Application security: SAST, DAST, SCA, secret scanning, threat modeling, secure code review, and developer training. You're the person engineers come to with security questions.
  • AI/LLM security across our model integrations, RAG pipelines, and LLM provider APIs (Anthropic, Google Vertex AI, OpenAI). Prompt injection, data exfiltration, model abuse, output guardrails, and evaluating new AI features before they ship.
  • Cloud and infrastructure security in Azure/AKS and GCP under FedRAMP and GCC High requirements: IAM, network segmentation, encryption, Kubernetes runtime protection, IaC scanning, WAF, and zero-trust design with the DevOps team.
  • Security automation: CI/CD security gates, detection-as-code, SOAR, custom tooling, and automated compliance evidence collection for SOC 2, FedRAMP, and CMMC.
  • Detection and response across endpoints (SentinelOne), cloud, and application layers. Lead or support incident response and keep the IR plan current.
  • Compliance and customer trust: technical controls mapped to NIST 800-53, SSPs and POA&Ms, continuous monitoring, and clear technical answers to customer security assessments.

What We're Looking For

Required:

  • 5+ years of hands-on security engineering with depth in at least three of: vulnerability management, AppSec, cloud security, security automation, detection engineering.
  • Strong cloud-native security experience (Azure and/or GCP preferred), including Kubernetes, container hardening, and IaC security.
  • Proven experience operating vulnerability scanners, SAST/DAST/SCA, CSPM/CWPP, EDR, SIEM, and secret scanning.
  • Enough Python, Go, TypeScript, or Bash to build automation and custom tooling.
  • Clear communication with developers and customers alike.
  • US citizenship (required for FedRAMP and defense customers).

Preferred:

  • Experience securing AI/ML systems and LLM applications (OWASP Top 10 for LLM, MITRE ATLAS).
  • SaaS security background at a B2B or GovTech company.
  • Working knowledge of FedRAMP, CMMC, NIST 800-53, NIST 800-171, and SOC 2, and how technical controls map to them.
  • FedRAMP or CMMC assessment support from the engineering side.
  • GCC High, Azure Government, or AWS GovCloud experience.
  • Familiarity with DFARS 252.204-7012, CUI handling, and ITAR/EAR.
  • Certifications such as OSCP, GIAC, cloud security certs, or CISSP.
  • Prior founding or early security hire at a startup.

Who You Are

A builder, not just an auditor. Comfortable making judgment calls without perfect information. An owner who sees a gap, flags it, and fixes it. Pragmatic about risk, with a default of 'Yes, and here's what we need to do first.' Someone who earns trust by being helpful, direct, and reliable.

How would you rate this job post?

See what other professionals think about this role.

banner
logo

Procurement Sciences

View Company Profile

Procurement Sciences (operating at procurementsciences.com) is an AI-driven workflow platform engineered for government contractors. Founded in 2022 by military and industry veteran Christian Ferreira and headquartered in Washington, DC, Procurement Sciences transforms how businesses navigate the complex landscape of federal, state, and local government contracting. Traditional procurement processes are often fragmented, time-consuming, and prone to human error, leaving contractors struggling to identify opportunities, manage bids efficiently, or deliver proposals competitively. Under the hood, the company’s platform leverages artificial intelligence to streamline bid searches, automate proposal drafting, and optimize contract management—reducing manual workloads and minimizing risks. This allows government contractors to identify high-value opportunities faster, craft compliant and compelling proposals with AI-assisted tools, and execute contracts with greater precision. Backed by a $10 million Series A funding round and a subsequent $30 million Series B round, Procurement Sciences is supported by leading investors including Catalyst, accelerating its mission to democratize access to government contracting for businesses of all sizes.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More
Security Engineering Lead (AI & Cloud Security) at Procurement Sciences | HireSkys