Senior AI/Cybersecurity Solutions Engineer
Senior
Agent
Ai Security
Ai Security Evaluation
Artificial Intelligence Security Evaluation
Aws Cloud Security
Aws Solutions Architect
Cloud Platforms
Cybersecurity Tools
Data Analysis
Data Security
Engineer
Facilities Management
Identity and Access Management
Information Security
Information Technology (IT)
InfoSec
Risk Management
Security
Security Automation
Security Compliance
Security Engineering
Security Operations
Security Standards
Security Testing
Solution Architecture
Job Description
Senior AI/Cybersecurity Solutions Engineer role supporting a federal Security, Architecture, and Engineering (SAE) team in Suitland, MD.
Responsibilities
- Design and implement Amazon Bedrock agent action groups, including OpenAPI schemas and Python Lambda execution layers
- Build Retrieval-Augmented Generation (RAG) pipelines using Bedrock Knowledge Bases with sources including NIST 800-53, CIS Benchmarks, organizational SSPs, and threat intelligence
- Engineer prompts, guardrails, and input validation to improve accuracy, security, and resistance to prompt-injection attacks
- Evaluate and evolve foundation-model strategies as platform requirements and AI capabilities mature
- Develop AI-assisted workflows for security assessment, remediation, hardening, alert triage, and compliance operations
- Automate NIST 800-53 control assessments and security evidence collection capabilities
- Implement remediation and hardening automation across AWS services including S3, EC2, IAM, CloudTrail, ECS, and EKS
- Integrate live security data from AWS Security Hub, GuardDuty, Inspector, and Config to enable environment-aware analysis and AI-assisted decisions
- Support BOD 26-04 SLA logic, CISA KEV correlation, risk enrichment, and remediation SLA tracking
- Support security telemetry aggregation and SIEM integrations including Microsoft Sentinel and AWS Security Lake
- Support ECR vulnerability scanning, EKS runtime monitoring, and container configuration hardening
- Develop and analyze SBOMs using formats such as SPDX and CycloneDX
- Correlate vulnerabilities with the CISA Known Exploited Vulnerabilities (KEV) catalog for risk-based prioritization
- Perform software supply-chain security checks for dependencies, provenance, and threats including typosquatting and unsigned container images
- Maintain GitLab CI/CD pipelines for linting, testing, security scanning, builds, and deployments
- Implement secure OIDC-based AWS authentication
- Develop and manage Infrastructure as Code using CloudFormation and/or Terraform with least-privilege IAM
- Support deployment and rollout verification across application and Kubernetes/EKS environments
- Maintain strong Git practices including branching, merge requests, and clean version-control history
- Manage technical work via Jira (tickets, epics, sub-tasks, workflows, status, and handoffs)
- Maintain documentation in Confluence including architecture guides, runbooks, decision records, and onboarding materials
- Produce technical design documentation, evidence packages, and audit-ready artifacts for federal assessments
- Maintain traceability between requirements, engineering work, code, deployments, and security evidence
- Own assigned technical workstreams and collaborate with cybersecurity and engineering teams
Requirements
- Bachelor’s degree in computer science, Cybersecurity, or a related technical discipline
- 6+ years of cloud security engineering experience
- 2+ years of production experience with generative AI/LLM technologies
- 4+ years experience working with AWS security services
- 3+ years supporting federal compliance frameworks such as NIST, FedRAMP, and FISMA
- 2+ years active Jira and Confluence experience in an Agile or technical delivery environment
- Expert-level Python development experience including Python 3.11+, boto3, type hints, and robust error handling
- Advanced experience with Amazon Bedrock including agents, action groups, Knowledge Bases, guardrails, prompt engineering, and RAG
- Expert knowledge of AWS security technologies including Security Hub, GuardDuty, Inspector, Config, IAM, CloudTrail, and OIDC
- Advanced container security experience with ECR, ECS/EKS, image scanning, runtime monitoring, and hardening
- Expert knowledge of NIST SP 800-53 Rev. 5 including control families, assessment procedures, and evidence requirements
- Advanced experience with CI/CD and Infrastructure as Code including GitLab CI and CloudFormation and/or Terraform
- Advanced Git/version-control experience
- Demonstrated experience managing technical work in Jira and maintaining team documentation in Confluence
Technologies
- Amazon Bedrock, OpenAPI, Python, AWS Lambda
- Retrieval-Augmented Generation (RAG), Bedrock Knowledge Bases, Amazon Bedrock agents, guardrails
- NIST 800-53, NIST SP 800-53 Rev. 5, CIS Benchmarks, System Security Plans (SSPs)
- prompt-injection attacks
- AWS security services: AWS Security Hub, GuardDuty, Inspector, Config, IAM, CloudTrail, OIDC
- AWS services: S3, EC2, ECS, EKS, Kubernetes
- Microsoft Sentinel, AWS Security Lake
- ECR, SBOMs (SPDX, CycloneDX), CISA Known Exploited Vulnerabilities (KEV)
- GitLab CI/CD pipelines, GitLab CI, Jira, Confluence, Git, CI/CD
- Infrastructure as Code: CloudFormation, Terraform
- BOD 26-04, BOD 26-04
- FedRAMP, FISMA
Benefits
- Health Care Plan (Medical, Dental & Vision)
- Retirement Plan (401k, IRA)
- Life Insurance (Basic, Voluntary & AD&D)
- Paid Time Off (Vacation, Sick & Public Holidays)
- Family Leave (Maternity, Paternity)
- Short Term & Long Term Disability
- Training & Development
- Wellness Resources
- 401(k) with company match
Preferred Qualifications
- Master’s degree in a related technical discipline
- 3+ years of experience building production AI agents
- Experience supporting ATO and continuous monitoring activities
- Experience administering or configuring Jira boards and Confluence spaces
- Experience supporting federal IT security programs
- Familiarity with CISA Binding Operational Directives, including BOD 22-01 and BOD 26-04
- Experience with AWS Security Lake, OCSF, OSCAL machine-readable compliance, or Microsoft Sentinel integration
- Experience with AI red teaming or adversarial testing of LLM applications
- Familiarity with software supply-chain technologies and frameworks such as SLSA, Sigstore, and in-toto
- Certifications such as AWS Certified Security – Specialty, CISSP, CISM, CKS, or AWS machine learning certification are preferred
Work Environment
- Full-time, 100% on-site position in Suitland, MD supporting a federal government cybersecurity and enterprise IT environment
- Technical environment includes AWS, Amazon Bedrock, EKS, GitLab, GitLab CI, AWS CodePipeline, Jira, Confluence, Python, VS Code, Jupyter Notebook, and related cloud and cybersecurity technologies
Additional Notes
- Must be a U.S. Citizen or Lawful Permanent Resident and eligible to obtain and maintain a Public Trust
- Employment contingent upon successful completion of applicable government background investigation and customer onboarding requirements