Sr. Security Engineer

Procurement SciencesLehi, UT
$150,000 - $180,000Remote

About The Position

Procurement Sciences is seeking a Sr. Security Engineer to be the technical backbone of their security program. This is a hands-on role responsible for the engineering aspects of security across the entire platform, including vulnerability management, application security, AI/LLM security, cloud hardening, detection, and automation. The role reports to the CISO and collaborates with Platform Engineering, Product, and DevOps. The company processes sensitive government contracting data and holds FedRAMP Moderate authorization, making security a key product differentiator. The goal is to maintain a strong security posture without hindering engineering velocity.

Requirements

  • 5+ years of hands-on security engineering experience with depth in at least three of: vulnerability management, AppSec, cloud security, security automation, detection engineering.
  • Strong cloud-native security experience (Azure and/or GCP preferred), including Kubernetes, container hardening, and IaC security.
  • Proven experience operating vulnerability scanners, SAST/DAST/SCA, CSPM/CWPP, EDR, SIEM, and secret scanning.
  • Proficiency in Python, Go, TypeScript, or Bash for automation and custom tooling.
  • Clear communication skills with developers and customers.
  • US citizenship.

Nice To Haves

  • Experience securing AI/ML systems and LLM applications (OWASP Top 10 for LLM, MITRE ATLAS).
  • SaaS security background at a B2B or GovTech company.
  • Working knowledge of FedRAMP, CMMC, NIST 800-53, NIST 800-171, and SOC 2, and how technical controls map to them.
  • FedRAMP or CMMC assessment support from the engineering side.
  • GCC High, Azure Government, or AWS GovCloud experience.
  • Familiarity with DFARS 252.204-7012, CUI handling, and ITAR/EAR.
  • Certifications such as OSCP, GIAC, cloud security certs, or CISSP.
  • Prior founding or early security hire at a startup.

Responsibilities

  • End-to-end vulnerability management, including pen tests, CSPM/CWPP tooling (Wiz), MTTR, and risk reporting.
  • Application security: SAST, DAST, SCA, secret scanning, threat modeling, secure code review, and developer training.
  • AI/LLM security across model integrations, RAG pipelines, and LLM provider APIs, addressing prompt injection, data exfiltration, model abuse, and output guardrails.
  • Cloud and infrastructure security in Azure/AKS and GCP under FedRAMP and GCC High requirements, focusing on IAM, network segmentation, encryption, Kubernetes runtime protection, IaC scanning, WAF, and zero-trust design.
  • Security automation: CI/CD security gates, detection-as-code, SOAR, custom tooling, and automated compliance evidence collection.
  • Detection and response across endpoints, cloud, and application layers, including incident response leadership and plan maintenance.
  • Compliance and customer trust: mapping technical controls to NIST 800-53, managing SSPs and POA&Ms, continuous monitoring, and responding to customer security assessments.

Benefits

  • Competitive salary with performance based incentive plan
  • Stock options
  • Comprehensive health plan
  • Flexible work arrangements, including full remote work capabilities
  • Extensive professional development opportunities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service