Security Engineering Lead (AI & Cloud Security)
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
You'll be the technical backbone of our security program. This is a hands-on role owning the engineering side of security across the whole platform: vulnerability management, application security, AI/LLM security, cloud hardening, detection, and automation. You'll report to the CISO and work closely with Platform Engineering, Product, and DevOps.
We process sensitive government contracting data for defense and civilian agencies and hold FedRAMP Moderate authorization. Security is a product differentiator here, not a cost center. Your job is to keep that posture strong without slowing engineering down.
What You’ll Own
- Vulnerability management end to end, including pen tests, CSPM/CWPP tooling (Wiz), MTTR, and risk reporting for leadership and customers.
- Application security: SAST, DAST, SCA, secret scanning, threat modeling, secure code review, and developer training. You're the person engineers come to with security questions.
- AI/LLM security across our model integrations, RAG pipelines, and LLM provider APIs (Anthropic, Google Vertex AI, OpenAI). Prompt injection, data exfiltration, model abuse, output guardrails, and evaluating new AI features before they ship.
- Cloud and infrastructure security in Azure/AKS and GCP under FedRAMP and GCC High requirements: IAM, network segmentation, encryption, Kubernetes runtime protection, IaC scanning, WAF, and zero-trust design with the DevOps team.
- Security automation: CI/CD security gates, detection-as-code, SOAR, custom tooling, and automated compliance evidence collection for SOC 2, FedRAMP, and CMMC.
- Detection and response across endpoints (SentinelOne), cloud, and application layers. Lead or support incident response and keep the IR plan current.
- Compliance and customer trust: technical controls mapped to NIST 800-53, SSPs and POA&Ms, continuous monitoring, and clear technical answers to customer security assessments.
What We're Looking For
Required:
- 5+ years of hands-on security engineering with depth in at least three of: vulnerability management, AppSec, cloud security, security automation, detection engineering.
- Strong cloud-native security experience (Azure and/or GCP preferred), including Kubernetes, container hardening, and IaC security.
- Proven experience operating vulnerability scanners, SAST/DAST/SCA, CSPM/CWPP, EDR, SIEM, and secret scanning.
- Enough Python, Go, TypeScript, or Bash to build automation and custom tooling.
- Clear communication with developers and customers alike.
- US citizenship (required for FedRAMP and defense customers).
Preferred:
- Experience securing AI/ML systems and LLM applications (OWASP Top 10 for LLM, MITRE ATLAS).
- SaaS security background at a B2B or GovTech company.
- Working knowledge of FedRAMP, CMMC, NIST 800-53, NIST 800-171, and SOC 2, and how technical controls map to them.
- FedRAMP or CMMC assessment support from the engineering side.
- GCC High, Azure Government, or AWS GovCloud experience.
- Familiarity with DFARS 252.204-7012, CUI handling, and ITAR/EAR.
- Certifications such as OSCP, GIAC, cloud security certs, or CISSP.
- Prior founding or early security hire at a startup.
Who You Are
A builder, not just an auditor. Comfortable making judgment calls without perfect information. An owner who sees a gap, flags it, and fixes it. Pragmatic about risk, with a default of 'Yes, and here's what we need to do first.' Someone who earns trust by being helpful, direct, and reliable.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
Solutions Engineer (API) - Healthcare SaaS
Verifiable
United StatesHead of Venture Creation - Deep-Tech Company Builder
Roadrunner Venture Studios
United StatesSr. Database Reliability Engineer II
NinjaTrader
United StatesSenior Identity & Access Architect (Agent-Native Systems) at Keycard
Keycard
United StatesMore Openings at Procurement Sciences
Explore Top Companies in this Space
Tribe AI
Artificial Intelligence / Enterprise Software / AI Consultancy & Services / Machine Learning
BLP Digital
Enterprise Software / Artificial Intelligence / Business Process Automation / SaaS
viz.ai
Artificial Intelligence / Data Analytics / Business Intelligence / Enterprise Software
GC AI
Artificial Intelligence / Enterprise Software / Business Productivity / LegalTech
Procurement Sciences
View Company ProfileProcurement Sciences (operating at procurementsciences.com) is an AI-driven workflow platform engineered for government contractors. Founded in 2022 by military and industry veteran Christian Ferreira and headquartered in Washington, DC, Procurement Sciences transforms how businesses navigate the complex landscape of federal, state, and local government contracting. Traditional procurement processes are often fragmented, time-consuming, and prone to human error, leaving contractors struggling to identify opportunities, manage bids efficiently, or deliver proposals competitively. Under the hood, the company’s platform leverages artificial intelligence to streamline bid searches, automate proposal drafting, and optimize contract management—reducing manual workloads and minimizing risks. This allows government contractors to identify high-value opportunities faster, craft compliant and compelling proposals with AI-assisted tools, and execute contracts with greater precision. Backed by a $10 million Series A funding round and a subsequent $30 million Series B round, Procurement Sciences is supported by leading investors including Catalyst, accelerating its mission to democratize access to government contracting for businesses of all sizes.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.