Procore Technologies · 1 day ago
Staff Security Engineer
Procore Technologies is looking for a Staff Security Engineer to join their Security Engineering team. This role involves designing and implementing foundational security controls to protect their platform, data, and users while driving the implementation of a secure cloud product and infrastructure.
ConstructionInternetSaaSSoftware
Responsibilities
Design and implement scalable IAM guardrails for cloud (AWS/GCP/Azure) and corporate (Okta) environments, including identity governance, PAM, and service-to-service authentication
Mentor other engineers and help scale security knowledge across the organization
Lead the evaluation and implementation of new security technologies and platforms from proof-of-concept to production
Design the long-term application security strategy and roadmap (e.g., Zero Trust architecture for apps)
Solve entire classes of vulnerabilities permanently by re-architecting frameworks or platforms
Lead critical incident response efforts for product security breaches
Design and build automated pipelines for authoritative asset inventory and Software Bill of Materials (SBOM) generation
Drive the technical roadmap for data protection, including key management (KMS), encryption-at-rest/in-transit, and tokenization
Build and implement secure-by-default configurations for our containerized (Kubernetes, EKS) and IaC (Terraform) workflows
Partner with Product & Technology teams to engineer technical resilience patterns, auto-healing systems, and verifiable disaster recovery capabilities
Act as a senior technical expert to provide authoritative context on security controls and designs to our GRC and Internal Audit teams
Provide on-call support on a rotational basis
Qualification
Required
Bachelor's degree in Computer Science or equivalent practical experience
6+ years of experience in a hands-on technical security role, with at least 3 years focused on cloud security in a large-scale SaaS environment
Deep expertise in multiple security domains including product/application security, IAM, IaaS, network, etc
Deep expertise with at least one major cloud provider (AWS preferred) and its security services (IAM, KMS, Security Hub, GuardDuty)
Strong experience with identity and access management platforms (IdP, IGA, PAM), joiner-mover-leaver (JML) mechanisms, and concepts (SAML, OAuth 2.0, OIDC, SCIM)
Proven experience building security guardrails for IaC (Terraform preferred), CI/CD pipelines, and container orchestration (Kubernetes)
Ability to influence engineering leadership and drive cultural change (shifting security left)
Experience writing custom security tooling or rules engines (e.g., CodeQL custom rules) to scale detection
Strong understanding of data protection principles, including encryption, key management, tokenization, and data loss prevention (DLP)
A 'builder' mindset with a passion for automation (Python, Go, or similar) and shipping solutions as code
Excellent communication skills with the ability to translate complex technical concepts for technical and non-technical stakeholders
Benefits
Equity Compensation
Company
Procore Technologies
Procore Technologies, Inc. (NYSE: PCOR) is a leading technology partner for every stage of construction.
H1B Sponsorship
Procore Technologies has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (37)
2024 (45)
2023 (35)
2022 (51)
2021 (43)
2020 (14)
Funding
Current Stage
Public CompanyTotal Funding
$654.02MKey Investors
12 West CapitalGlobal Secure InvestD1 Capital Partners
2023-09-21Post Ipo Secondary· $4.07M
2021-05-20IPO
2020-07-10Secondary Market
Leadership Team
Recent News
2025-12-14
Company data provided by crunchbase