Staff Engineer, AI Automation and Orchestration
About the role
Procore Technologies provides cloud-based construction management software that helps clients build skyscrapers, hospitals, retail centers, airports, housing complexes, and more. As a Staff Engineer, AI Automation and Orchestration, you will join Procore's Government Engineering team and serve as a senior technical contributor for our FedRAMP initiative. In this role, you will design, build, and maintain next-generation platform services that provide cloud traffic, ingress/egress, identity, and compliance capabilities within FedRAMP authorization boundaries.
This position reports to the Senior Engineering Manager of the Government Engineering team and is a hybrid role based out of our Austin, TX office. US citizenship is required to work on FedRAMP-compliant projects.
Responsibilities
- Manage Cloud Traffic & Service Mesh technologies: Design, implement, and maintain next-generation network routing, edge controls, and service mesh architecture using Istio, Kong, and Cloudflare.
- Lead Platform Migrations: Drive the engineering lifecycle and migration strategies transitioning internal teams to centralized, compliant infrastructure pipelines using Istio and Datadog.
- Manage Identity & Access: Design and implement robust Identity and Access Management (IAM) architectures within FedRAMP boundaries, leveraging Okta for identity federation (SAML/OIDC), SSO, RBAC, and zero-trust patterns.
- Enforce Cryptographic Security: Select, configure, and enforce NIST-certified FIPS 140-2/140-3 validated cryptographic modules across services, TLS configurations, and key management systems.
- Advise on FedRAMP Compliance: Serve as a technical subject matter expert on FedRAMP compliance controls (NIST SP 800-53), translating complex regulatory control language into concrete, automated technical implementations. Partner with security teams on continuous monitoring (ConMon) and annual assessment readiness.
- Develop Automations: Write production-grade software to eliminate platform gaps while mentoring mid-level engineers on compliance-aware engineering design patterns.
- Leverage AI Tools: Use modern developer tooling—including AI-assisted development assistants—to optimize coding efficiency, automate mundane tasks, and accelerate platform delivery.
Requirements
- 8+ years of software or infrastructure engineering experience, with at least 3 years directly supporting or operating within a FedRAMP-authorized environment (AWS GovCloud experience is a plus).
- Strong programming fundamentals with demonstrated proficiency in writing software (e.g., Golang, Typescript, or Python) to build robust platform infrastructure and automation tools.
- Comprehensive hands-on experience with identity management architecture, identity federation (SAML, OIDC), directory services, privileged access management, and zero-trust architecture principles.
- Deep understanding of FIPS 140-2/140-3 validated cryptographic modules, including verifying and enforcing NIST-certified algorithm/module testing in practice.
- Production experience managing high-throughput ingress/egress, traffic routing, and container network interfaces at scale using tools like Istio, Kong, and Cloudflare.
- Extensive experience architecting, operating, and hardening Kubernetes clusters, including policy enforcement (e.g., OPA/Gatekeeper, Kyverno) and secure secrets management.
- Experience with secrets management platforms operating in FIPS mode (e.g., HashiCorp Vault).
- Familiarity with FedRAMP Rev 5 transition requirements.
- Experience with STIG application or CIS benchmark enforcement at scale.
- Security certifications such as CISSP, AWS Certified Security - Specialty, or CKS (preferred).
Pay
Base Pay Range: $168,560.00 - $231,770.00 USD Annual. This role may also be eligible for Equity Compensation and/or Bonus Incentive Compensation.