
Staff Engineer, AI Automation and Orchestration
Procore Technologies2 hours ago
Base Salary
$169k - $232k/yr
Responsibilities
- Design, implement, and maintain cloud traffic, network routing, edge controls, and service mesh architecture using Istio, Kong, and Cloudflare.
- Lead migrations to centralized, compliant infrastructure pipelines and manage the engineering lifecycle for platform transitions.
- Design and implement IAM architectures within FedRAMP boundaries, including identity federation, SSO, RBAC, privileged access management, and zero-trust patterns.
- Select, configure, and enforce FIPS 140-2/140-3 validated cryptographic modules, TLS configurations, and key-management systems.
- Advise on FedRAMP and NIST SP 800-53 compliance controls and translate regulatory requirements into automated technical implementations.
- Partner with security teams on continuous monitoring and annual assessment readiness.
- Write production-grade software and automation to close platform gaps while mentoring mid-level engineers.
- Use AI-assisted development tooling and other modern developer tools where appropriate to improve coding efficiency and platform delivery.
Requirements
- 8+ years of software or infrastructure engineering experience, including at least 3 years directly supporting or operating within a FedRAMP-authorized environment.
- Strong software engineering fundamentals and demonstrated proficiency with Golang, TypeScript, or Python for platform infrastructure and automation.
- Hands-on expertise in IAM architecture, SAML, OIDC, directory services, privileged access management, and zero-trust architecture.
- Deep practical knowledge of FIPS 140-2/140-3 validated cryptographic modules and NIST-certified algorithm and module testing.
- Production experience managing high-throughput ingress and egress, traffic routing, and container network interfaces using Istio, Kong, or Cloudflare.
- Extensive experience architecting, operating, and hardening Kubernetes clusters, including OPA/Gatekeeper or Kyverno policy enforcement and secure secrets management.
- Experience with secrets-management platforms operating in FIPS mode, such as HashiCorp Vault.
- Familiarity with FedRAMP Rev 5 transition requirements and experience applying STIGs or enforcing CIS benchmarks at scale.
- AWS GovCloud experience is a plus.
- Security certifications such as CISSP, AWS Certified Security - Specialty, or CKS are preferred.
- US citizenship and eligibility to work on federal government projects requiring FedRAMP authorization are required.
Benefits
- Hybrid work arrangement based out of Procore’s Austin, Texas office.
- Base pay range of 168,560.00 - 231,770.00 USD annually, with potential eligibility for equity compensation and/or bonus incentive compensation.