SlipstreamJobsFresh Startup & VC-Backed Jobs

Sr. Security Engineer

Procurement Sciences AI - Lehi, UT, United States - Hybrid - posted 2026-09-08

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Procurement Sciences AI is a venture-backed SaaS platform transforming government contracting with AI-powered tools. The company holds FedRAMP Moderate authorization and processes sensitive defense and civilian agency data. Security is a core product differentiator, not a cost center. As Senior Security Engineer, you'll be the technical backbone of the security program, reporting to the CISO and partnering with Platform Engineering, Product, and DevOps. This is a hands-on role spanning the full security stack. Key responsibilities include: **Vulnerability Management**: End-to-end ownership of pen testing, CSPM/CWPP tooling (Wiz), MTTR optimization, and risk reporting to leadership and customers. **Application Security**: SAST, DAST, SCA, secret scanning, threat modeling, secure code review, and developer security training. You'll be the go-to security resource for engineering teams. **AI/LLM Security**: Securing model integrations, RAG pipelines, and LLM provider APIs (Anthropic, Google Vertex AI, OpenAI). Responsibilities include prompt injection defense, data exfiltration prevention, model abuse mitigation, output guardrails, and pre-release security evaluation of AI features. **Cloud & Infrastructure Security**: Azure/AKS and GCP security under FedRAMP and GCC High requirements, including IAM, network segmentation, encryption, Kubernetes runtime protection, IaC scanning, WAF, and zero-trust architecture. **Security Automation**: CI/CD security gates, detection-as-code, SOAR, custom tooling, and automated compliance evidence collection for SOC 2, FedRAMP, and CMMC. **Detection & Response**: Lead or support incident response across endpoints (SentinelOne), cloud, and application layers. Maintain and evolve the IR plan. **Compliance**: Map technical controls to NIST 800-53, develop SSPs and POA&Ms, enable continuous monitoring, and provide technical answers to customer security assessments. Required qualifications: 5+ years hands-on security engineering with depth in at least three domains (vulnerability management, AppSec, cloud security, security automation, detection engineering). Strong cloud-native security experience (Azure/GCP preferred), including Kubernetes and IaC security. Proven experience with vulnerability scanners, SAST/DAST/SCA, CSPM/CWPP, EDR, SIEM, and secret scanning. Coding ability in Python, Go, TypeScript, or Bash for automation and tooling. Clear communication with developers and customers. US citizenship required for FedRAMP and defense customers. Preferred: AI/ML and LLM security experience (OWASP Top 10 for LLM, MITRE ATLAS). SaaS security background at B2B or GovTech companies. FedRAMP, CMMC, NIST 800-53/171, and SOC 2 knowledge. GCC High, Azure Government, or AWS GovCloud experience. DFARS 252.204-7012, CUI handling, ITAR/EAR familiarity. Certifications (OSCP, GIAC, cloud security, CISSP). Prior founding or early security hire experience. You're a builder, not just an auditor. Comfortable making judgment calls with incomplete information. An owner who identifies gaps and fixes them. Pragmatic about risk with a default of "Yes, and here's what we need to do first." You earn trust through being helpful, direct, and reliable.

Similar roles