Sr. Security Engineer

Procurement Sciences

$110K — $130K *
Lehi, UT 84043In-Person
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of hands-on security engineering experience in vulnerability management, AppSec, cloud security, security automation, or detection engineering.
  • Strong knowledge of cloud-native security, specifically in Azure and GCP, including Kubernetes and container hardening.
  • Experience with security tools such as vulnerability scanners, SAST/DAST/SCA, CSPM/CWPP, EDR, SIEM, and secret scanning.
  • Proficiency in at least one programming language (Python, Go, TypeScript, or Bash) for automation and tooling.
  • Ability to communicate clearly with developers and customers.
  • US citizenship required for FedRAMP compliance.

Responsibilities

  • Manage vulnerability assessments end-to-end, including penetration testing and risk reporting.
  • Oversee application security initiatives and provide support for secure coding practices.
  • Secure AI/LLM integrations and monitor potential risks associated with them.
  • Implement cloud and infrastructure security measures in compliance with FedRAMP and GCC High.
  • Automate security processes, including detection-as-code and evidence collection for compliance audits.
  • Lead detection and response efforts across various software layers and support incident response activities.
  • Ensure compliance with technical controls and provide clear security assessments for customers.

Benefits

  • Comprehensive health plan for you and your family.
  • Flexible work arrangements, including options for remote work.
  • Extensive professional development opportunities for career growth.
  • Competitive compensation package that includes performance-based incentives and stock options.
Full Job Description
About the Role

You'll be the technical backbone of our security program. This is a hands-on role owning the engineering side of security across the whole platform: vulnerability management, application security, AI/LLM security, cloud hardening, detection, and automation. You'll report to the CISO and work closely with Platform Engineering, Product, and DevOps.

We process sensitive government contracting data for defense and civilian agencies and hold FedRAMP Moderate authorization. Security is a product differentiator here, not a cost center. Your job is to keep that posture strong without slowing engineering down.

What You'll Own
  • Vulnerability management end to end, including pen tests, CSPM/CWPP tooling (Wiz), MTTR, and risk reporting for leadership and customers.
  • Application security: SAST, DAST, SCA, secret scanning, threat modeling, secure code review, and developer training. You're the person engineers come to with security questions.
  • AI/LLM security across our model integrations, RAG pipelines, and LLM provider APIs (Anthropic, Google Vertex AI, OpenAI). Prompt injection, data exfiltration, model abuse, output guardrails, and evaluating new AI features before they ship.
  • Cloud and infrastructure security in Azure/AKS and GCP under FedRAMP and GCC High requirements: IAM, network segmentation, encryption, Kubernetes runtime protection, IaC scanning, WAF, and zero-trust design with the DevOps team.
  • Security automation: CI/CD security gates, detection-as-code, SOAR, custom tooling, and automated compliance evidence collection for SOC 2, FedRAMP, and CMMC.
  • Detection and response across endpoints (SentinelOne), cloud, and application layers. Lead or support incident response and keep the IR plan current.
  • Compliance and customer trust: technical controls mapped to NIST 800-53, SSPs and POA&Ms, continuous monitoring, and clear technical answers to customer security assessments.


What we're looking for

Required:
  • 5+ years of hands-on security engineering with depth in at least three of: vulnerability management, AppSec, cloud security, security automation, detection engineering.
  • Strong cloud-native security experience (Azure and/or GCP preferred), including Kubernetes, container hardening, and IaC security.
  • Proven experience operating vulnerability scanners, SAST/DAST/SCA, CSPM/CWPP, EDR, SIEM, and secret scanning.
  • Enough Python, Go, TypeScript, or Bash to build automation and custom tooling.
  • Clear communication with developers and customers alike.
  • US citizenship (required for FedRAMP and defense customers).

Preferred:
  • Experience securing AI/ML systems and LLM applications (OWASP Top 10 for LLM, MITRE ATLAS).
  • SaaS security background at a B2B or GovTech company.
  • Working knowledge of FedRAMP, CMMC, NIST 800-53, NIST 800-171, and SOC 2, and how technical controls map to them.
  • FedRAMP or CMMC assessment support from the engineering side.
  • GCC High, Azure Government, or AWS GovCloud experience.
  • Certifications such as OSCP, GIAC, cloud security certs, or CISSP.
  • Prior founding or early security hire at a startup.
Who you are

A builder, not just an auditor. Comfortable making judgment calls without perfect information. An owner who sees a gap, flags it, and fixes it. Pragmatic about risk, with a default of "Yes, and here's what we need to do first." Someone who earns trust by being helpful, direct, and reliable.

Compensation and Benefits:
  • Compensation DOE.
  • Competitive salary with performance based incentive plan and stock options in a rapidly growing, venture-backed company.
  • Comprehensive health plan, ensuring you and your loved ones are well taken care of.
  • Flexible work arrangements, including full remote work capabilities, to balance your professional and personal life.
  • Extensive professional development opportunities, providing a fast track for career advancement.

Similar Jobs

More Jobs at Procurement Sciences

More Information Technology Jobs

Find similar Sr. Security Engineer jobs: