Full-Time

Procurement Manager

Updated on 8/19/2026

Veracode

Veracode

201-500 employees

Cloud-based platform for application security scanning

No salary listed

Burlington, MA, USA

In Person

Bachelor's

Category
Operations & Logistics (1)
Required Skills
NetSuite
Forecasting
Excel/Numbers/Sheets

Get referred to Veracode

See people who can refer or advise you

Requirements
  • A Bachelor's degree in Business, Supply Chain Management, Finance, or a related field.
  • At least 7 years of procurement, strategic sourcing, or purchasing experience.
  • At least 3 years of experience leading, managing, or owning a procurement function, including direct people leadership or serving as the primary procurement leader for an organization.
  • Demonstrated experience negotiating complex supplier agreements and managing vendor relationships.
  • Experience supporting technology organizations, preferably within SaaS, cybersecurity, or software companies.
  • Strong understanding of procurement best practices, contract management, supplier performance management, and spend management.
  • Hands-on experience with Concur for procurement, purchasing workflows, and expense management.
  • Strong working knowledge of NetSuite, including purchasing, vendor management, and procurement-related financial processes.
  • Advanced proficiency with Microsoft Excel and reporting tools.
  • Excellent negotiation, analytical, communication, stakeholder management, and project management skills.
  • Ability to influence cross-functional teams, drive consensus, and successfully manage competing priorities.
Responsibilities
  • Lead the organization's procurement function, ensuring efficient, cost-effective, and compliant purchasing practices.
  • Develop and execute sourcing strategies for software, SaaS, technology, professional services, and indirect spend categories.
  • Partner with Legal, Finance, IT, Security, and business stakeholders to negotiate favorable commercial terms while mitigating risk.
  • Manage the complete procurement lifecycle from vendor selection through contract execution and renewal.
  • Evaluate supplier performance and develop strategic vendor relationships.
  • Identify opportunities for cost savings, process improvements, and procurement automation.
  • Develop procurement policies, procedures, and best practices to improve operational effectiveness.
  • Analyze spend data and provide reporting, metrics, and recommendations to leadership.
  • Ensure procurement activities comply with internal controls, financial policies, and regulatory requirements.
  • Lead cross-functional procurement initiatives and provide guidance to team members and stakeholders.
  • Support budgeting, forecasting, and vendor management activities.
Desired Qualifications
  • Experience supporting technology organizations, preferably within SaaS, cybersecurity, or software companies.

Placeholder

Company Size

201-500

Company Stage

Acquired

Total Funding

$114.3M

Headquarters

New York City, New York

Founded

2006

Get referred to Veracode

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Veracode closed 2025 with 81% ACV growth and 130 new customers in Q4.
  • July 2026 product launches target AI-generated code, supply-chain risk, and remediation speed.
  • Marketplace traction with DryRun Security expands reach into intent-based and logic vulnerabilities.

What critics are saying

  • Headcount fell from 778 in 2023 to 523 in March 2026, signaling compression.
  • Private equity ownership often pushes aggressive growth targets before a 2027 exit.
  • GitHub, Wiz, and AI-native startups like DryRun squeeze Veracode's legacy scanner moat.

What makes Veracode unique

  • Veracode Marketplace, launched July 30 2026, bundles vetted AppSec integrations under one contract.
  • Thoma Bravo bought Veracode in January 2026, giving it private-equity backing and autonomy.
  • Veracode Fix for SCA and Package Firewall automate remediation and package blocking inside developer workflows.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Wellness Program

Unlimited Paid Time Off

401(k) Company Match

401(k) Retirement Plan

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

1%

2 year growth

-4%
Softprom
Aug 18th, 2026
Veracode named Overall Leader in 2026 KuppingerCole Software Supply Chain Security Leadership Compass.

Veracode named Overall Leader in 2026 KuppingerCole Software Supply Chain Security Leadership Compass. News | 18.08.2026 Software supply chain attacks are accelerating, and CISOs need proof that their vendor can not only detect risk but actively block and remediate it. Compromised build systems, malicious open-source packages, and evolving regulations such as the EU Cyber Resilience Act and US Executive Order 14028 have made software supply chain security a board-level priority. Independent analyst validation is now a critical factor when IT leaders select an application risk management platform. What was announced. Veracode announced on August 6, 2026 that it has been named the Overall Leader in the 2026 KuppingerCole Analysts Leadership Compass: Software Supply Chain Security for the second consecutive time since the report was first published. Veracode is positioned at the top of the Overall Leader, Product Leader, and Innovation Leader categories, and is also recognized as a Market Leader. The KuppingerCole Analysts Leadership Compass assesses vendors on product strength, market presence, and innovation. The report was authored by Jonathan Care, an expert in cybersecurity and fraud detection and a Fellow of the British Computer Society. Veracode earns its Overall Leadership position by evolving from application scanning into a unified application risk management platform, pairing mature application security testing with a dedicated software supply chain layer. Its Package Firewall blocks malicious open-source packages before they enter the codebase, while its first-to-market, AI-powered Fix capability gives developers remediation choices rather than just flagging problems. KuppingerCole Analysts, 2026 Leadership Compass Why this matters. For CIOs, CISOs, and procurement leaders, this recognition provides third-party validation that Veracode combines mature Application Security Testing with proactive supply chain controls. As regulatory pressure grows under the UK Cyber Security Bill, EU CRA, and NIST SSDF, organizations need consolidated ASPM visibility, automated remediation, and evidence of enterprise-grade compliance such as SOC 2 Type II. This recognition reflects what Softprom hear from customers every day: they don't just want visibility into supply chain risk, they want it stopped and fixed automatically. As supply chain attacks grow more sophisticated, security teams need a partner that closes the gap between finding a risk and fixing it. Ajay Nigam, Chief Product Officer at Veracode Technical details. * Static Analysis: Support for 130+ languages with a market-leading low false-positive rate. * Package Firewall: Blocks malicious open-source packages at the point of ingestion. * Malicious Package Detection: Analyzes new packages within seconds. * Veracode Fix: AI-powered engine that proposes and applies remediation. * Proprietary suite: Static Analysis, SCA, Dynamic Analysis, Container Security, and Veracode Risk Manager, with no OEM dependencies. * ASPM: Consolidated findings across code to cloud via Veracode Risk Manager. * Integrations: Broad CI/CD, IDE, and registry integration ecosystem. * Compliance: SOC 2 Type II certified, aligned with NIST SSDF, EU CRA, and Executive Order 14028. Softprom and Veracode. Softprom is the official distributor of Veracode. Its team helps enterprises deploy application risk management, software composition analysis, and supply chain security controls tailored to regulatory and business requirements. This content was prepared as part of the Softprom DistriFlow project - an automated system for monitoring and adapting vendor news. Original source: original article.

Softprom
Aug 4th, 2026
Veracode Marketplace 2026: curated AppSec integrations for the AI era.

Veracode Marketplace 2026: curated AppSec integrations for the AI era. News | 04.08.2026 Application security teams face a growing challenge: AI-generated code, agentic development environments, and expanding attack surfaces demand deeper contextual analysis than traditional static scanners can provide. Enterprises need a trusted way to extend their existing AppSec platform with specialized capabilities without adding procurement friction or fragmented workflows. A single, curated destination to discover, evaluate, and deploy elite security integrations on top of Veracode. What was announced. On July 30, 2026, Veracode announced the launch of the Veracode Marketplace, a curated ecosystem that provides customers with a single, trusted destination to discover, evaluate, and deploy third-party security integrations as an extension of the Veracode platform. The marketplace debuts with DryRun Security as its inaugural partner, delivering AI-native contextual analysis and verification to Veracode customers on day one. Every partner is vetted for technical depth, product quality, and workflow fit. Integrations are anchored to Veracode findings for a unified audit trail, and every purchase runs through a single procurement path on a single contract with a personalized support experience. Additional partners are scheduled to join throughout 2026. Application security has entered a new era, and no single vendor will solve it alone. Customers tell Softprom they want the depth and rigor of the Veracode platform, combined with the freedom to choose specialized capabilities that fit their tech stack Ajay Nigam, Chief Product Officer at Veracode Why this matters. For CIOs, CISOs, IT directors, and procurement leaders, the Veracode Marketplace addresses three critical pressures: the need to secure AI-generated code, the demand for verified risk prioritization over noisy findings, and the operational cost of managing multiple security vendors. By consolidating validated integrations under a single contract anchored to Veracode findings, enterprises reduce procurement overhead and gain a unified audit trail across their AppSec program. The inaugural partnership with DryRun Security is significant: DryRun already powers more than 500,000 code reviews per month and provides native integrations with modern AI coding tools including Claude Code, Cursor, Codex, GitHub, and GitLab. Combining Veracode's deterministic scanning with DryRun's AI-reasoning delivers unified, end-to-end coverage from detection to validated remediation. Technical details. * Curated ecosystem: vetted third-party integrations extending the Veracode platform. * Inaugural partner: DryRun Security, with AI-native Contextual Security Analysis engine. * Coverage expansion: intent-based and logic vulnerabilities missed by traditional static scanners. * Native integrations: Claude Code, Cursor, Codex, GitHub, GitLab, plus repository-wide DeepScans. * Scale: DryRun powers over 500,000 code reviews per month. * Procurement: single contract, unified audit trail, personalized support. * Availability: live today for Veracode customers, with additional partners in 2026. Application security teams are not asking for more findings - they are asking for better verification of which risks actually matter James Wickett, CEO and Co-Founder of DryRun Security Softprom and Veracode. Softprom is the official distributor of Veracode. Enterprise teams looking to adopt the Veracode Marketplace, integrate DryRun Security, or expand their AppSec program can request a consultation and demo through Softprom's certified specialists. This content was prepared as part of the Softprom DistriFlow project - an automated system for monitoring and adapting vendor news. Original source: original article.

Goldin Digital Publishing Inc.
Aug 3rd, 2026
Superblocks and AWS Announce Strategic Collaboration

Superblocks and AWS announce strategic collaboration. August 03, 2026 Superblocks and Amazon Web Services (AWS) announced a multi-year collaboration to make Superblocks' generative AI platform available within customers' AWS environments, including Amazon Bedrock. Amazon Bedrock is a platform for building generative AI applications and agents at production scale, providing access to a broad selection of fully managed models from leading AI companies through a unified API. As a result, enterprise customers will be able to build, secure, and deploy AI applications while leveraging the security, privacy, and performance of AWS. As part of the collaboration, Superblocks will integrate with Amazon Aurora to spin up databases for new AI-generated applications with best-in-class price-performance and scale-to-zero capabilities within the customer's environment. Amazon Aurora is a fully managed, high-performance relational database service built for the cloud, delivering up to 6x the throughput of standard engines along with automatic scaling and enterprise-grade security at global scale. Superblocks provides both the AI coding capabilities and governance layer for enterprise-grade vibe coding, enabling business teams to deliver IT-approved applications on a self-serve basis while IT and security teams centrally control auditing and security. Bringing Superblocks to Amazon Bedrock, Amazon EC2, and Amazon Aurora gives enterprises an org-wide capability to deliver internal applications built by business teams - with all data and code secured within their trusted security perimeter in AWS through Superblocks' Cloud-Prem deployment model. Superblocks' AWS Cloud-Prem model gives enterprises the speed of a managed AI application platform while allowing IT and security teams to preserve their existing AWS network controls, governance policies, and production security requirements. Superblocks Smart Router on Amazon Bedrock delivers up to 30% cost savings by intelligently matching each task to the most cost-effective model. It reserves frontier models only when they're needed, as open-source models increasingly close the performance gap. "Customers are done being beholden to expensive frontier models. They want model choice that delivers the best price-performance for every task, and that's exactly what Superblocks Smart Router offers, with the security and performance of Amazon Bedrock behind it," said Brad Menezes, CEO of Superblocks. "Today, business users are vibe coding on their local desktops with no secure path to production on top of their private enterprise data. Our partnership with AWS provides the infrastructure for that secure path, and it lets IT teams configure policy agents that check AI-generated code against enterprise standards before it ever reaches production." "Giving AWS customers the flexibility to run Superblocks in their own virtual private cloud with model choice on Amazon Bedrock means business teams can build AI applications on enterprise data without putting security at risk," said Jason Bennett, Vice President and Global Head of Startups and Venture Capital at AWS. "Enterprises want speed and control - Superblocks delivers both, enabling self-serve automation org-wide while IT maintains governance. That's what successful AI adoption at scale looks like." As part of the collaboration, AWS will serve as Superblocks' preferred cloud provider, and both companies will co-market this new offering to customers leveraging AWS field enablement, as well as promote hands-on AI app development workshops to help enterprises move from AI prototypes to governed production applications on AWS. Customers will also be able to procure Superblocks through AWS Marketplace, simplifying contracting, budget alignment, and committed-spend utilization for AWS customers adopting Superblocks across business teams. Industry news. August 03, 2026 Superblocks and Amazon Web Services (AWS) announced a multi-year collaboration to make Superblocks' generative AI platform available within customers' AWS environments, including Amazon Bedrock. August 03, 2026 BrowserStack announced Test Companion, agentic AI for test automation built into the IDE. August 03, 2026 Veracode announced the launch of the Veracode Marketplace, a curated ecosystem that gives customers a single, trusted destination to discover, evaluate, and deploy third-party security integrations as an extension of the Veracode platform. July 30, 2026 Oracle and Google Cloud have expanded their partnership to bring Google's Gemini models to Oracle's extensive portfolio of enterprise applications. July 30, 2026 Tricentis announced the acquisition of Tabnine, the AI-coding platform purpose-built for secure, context-aware enterprise software development. July 29, 2026 Checkmarx announced Checkmarx Fusion, a new hybrid scanning approach now available in early access to Checkmarx customers. July 29, 2026 Evinced announced the launch of its suite of agentic coding tools: Autopilot, Harness, and Resolve. July 28, 2026 The Agentic AI Foundation (AAIF) announced the largest update to the Model Context Protocol (MCP) since its launch. This update removes the biggest technical roadblocks, making it easier for Fortune 500 and AI labs to use AI agents at scale. What's new: - Stateless architecture that scales on HTTP infrastructure - Enterprise-grade security that aligns with the security standards companies already use (OAuth 2.0 and OpenID Connect) - Formal governance via a predictable, 12 month deprecation policy July 28, 2026 Opsera announced the availability of Forge, an enterprise software factory, on the Cursor Marketplace. July 27, 2026 Decisions announced its latest release, Decisions Platform v10, a major update to its enterprise orchestration platform that advances how organizations build, govern, deploy, and orchestrate automation at scale. July 23, 2026 Azul announced that it will deliver monthly Critical Security Patch Updates (CSPUs) for Java Long-Term Support (LTS) versions for both Azul Core and Azul Prime, starting in August 2026. July 23, 2026 Prismatic announced native large data sync, a set of new capabilities that enables teams to move high volumes of customer data through the same integration platform they already use to build, deploy, monitor, and manage customer-facing integrations. July 23, 2026 Harness and Kong announced an expansion of their strategic partnership to address the growing security challenges posed by AI-driven architectures, autonomous agents, and Model Context Protocol (MCP) deployments. July 22, 2026 Sauce Labs introduced AURA, its AI-Unified Release Assurance platform, to close that gap.

Associated Press
Jul 30th, 2026
Veracode launches marketplace for security integrations with DryRun Security as inaugural partner

Veracode has launched the Veracode Marketplace, a curated ecosystem allowing customers to discover and deploy third-party security integrations that extend its application risk management platform. The marketplace debuts with DryRun Security as its inaugural partner. DryRun Security brings AI-native code analysis to Veracode customers, offering contextual security analysis that identifies complex logic and intent-based vulnerabilities traditional static scanners miss. The company currently powers over 500,000 code reviews monthly. Every marketplace partner undergoes vetting for technical depth and product quality. Integrations connect to Veracode findings for unified audit trails, with purchases processed through a single contract. "Application security has entered a new era, and no single vendor will solve it alone," said Ajay Nigam, chief product officer at Veracode. Additional partners are scheduled to join throughout 2026. The marketplace is available to all Veracode customers through its platform.

Softprom
Jul 21st, 2026
Veracode unveils ai-powered innovations for software security 2025.

Veracode unveils ai-powered innovations for software security 2025. News | 21.07.2026 Advanced ai-powered solutions reduce remediation time while proactively blocking 60% of critical supply chain threats. Enterprise security teams face a paradox: they are overwhelmed by vulnerability alerts yet still miss the risks that matter most. With 70 percent of critical security debt now stemming from third-party code and regulations such as the EU Digital Operational Resilience Act (DORA) tightening expectations, organizations need proactive controls across the software development lifecycle rather than reactive firefighting. What was announced. Veracode has introduced a suite of innovations to its Application Risk Management platform that reduce vulnerability remediation time by up to 92 percent and prevent 60 percent of critical supply chain risk from entering organizations. The updates cover Veracode Risk Manager, Veracode Package Firewall, and developer productivity tools. Veracode Risk Manager now includes six new integrations with industry leaders such as Wiz, aggregating and prioritizing issues across sources so security teams can act on the Best Next Action. Veracode Package Firewall uses AI analysis to block untrusted packages before they enter development pipelines, identifying and blocking 60 percent more malicious packages than competing solutions. Security teams tell SOFTPROM Distribution Gmbh they are drowning in vulnerability alerts while missing the risks that actually matter. Its latest innovations flip the script - instead of endless firefighting, teams can now prevent threats proactively and focus remediation efforts where they will have maximum business impact Derek Maki, Head of Product at Veracode Why this matters. For CIOs, CISOs, and procurement leaders, the shift from reactive alerting to preventive control changes the economics of application security. Blocking malicious packages at the gate reduces mean time to remediate, cuts operational overhead for SOC and AppSec teams, and supports compliance with DORA and similar frameworks. According to Gartner, organizations with a high-quality developer experience are 33 percent more likely to attain their business goals - making frictionless security a strategic advantage, not just a technical improvement. Technical details. * Veracode Risk Manager: Six new ASPM integrations including Wiz; up to 92% reduction in vulnerability remediation time. * Veracode Package Firewall: AI-driven blocking of malicious open-source packages; 60% more effective than competing solutions. * SCA and Malicious Package Detection: Neutralizes libraries harboring malicious code before ingestion. * AI-Assisted Login for DAST: Automates complex authentication flows, reducing script setup time by 50%. * Container and IaC Results: Centralized findings in the Veracode Platform for streamlined vulnerability management. * IDE and Git integrations: Visual Studio, IntelliJ IDEA, Eclipse, GitHub, GitLab, Azure DevOps - with 35% faster remediation. * Veracode Fix Usage Analytics: Dashboard tracking usage and CWEs addressed by IDE, project, and source file. Softprom and Veracode. Softprom is the official distributor of Veracode. Enterprises can access the full application risk management portfolio, technical enablement, and licensing support through Softprom. Request a consultation and pricing for the updated Veracode platform via Veracode. This content was prepared as part of the Softprom DistriFlow project - an automated system for monitoring and adapting vendor news. Original source: original article.