> Markdown version of [/jobs/ext/1772361-sr-security-engineer](https://www.wearedevelopers.com/jobs/ext/1772361-sr-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Security Engineer - **Company:** HALL, VICKIE L - **Location:** Alexandria, VA, United States - **Experience:** Expert - **Salary:** $155,000.0 - $165,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Mobile Application Development, Software as a Service, Cloud Computing Security, Cyber Security, Data Discovery, Information Leak Prevention, Cursor (Graphical User Interface Elements), Intrusion Detection and Prevention, Python (Programming Language), Windows PowerShell, Markdown, Security Information and Event Management, Symantec, Data Classification, GitHub Copilot, Large Language Models, Prompt Engineering, Information Technology, Data Pipelines - **Published:** July 27, 2026 - **Apply:** https://www.careerjet.com/jobad/usb492b32c78ff438e100baaadb84c9b0e ## About the Role * Education: Bachelor's degree in Computer Science, Information Security, or a related field (Master's Degree and 8 years of experience; equivalent experience may be considered in lieu of degree, 14+ years). * Experience: Minimum of 10 years of professional cybersecurity engineering experience, including at least 3 years focused on data loss prevention (DLP), data classification, or cloud/enterprise security architecture, ideally within a Federal environment. * Technical Proficiency: Advanced knowledge of data discovery/classification and DLP platforms (e.g., Microsoft Purview, Symantec DLP, Varonis), cloud security in AWS/Azure/GovCloud, CASB, and SIEM tooling. * Compliance: Working knowledge of NIST SP 800-53, FISMA, and the Risk Management Framework (RMF). * Certifications: Current CISSP certification is required. * Must be able to obtain and maintain a Public Trust security clearance. Preferred Expertise * Demonstrated success supporting Federal contracts. * Hands-on experience securing generative AI and LLM-enabled workflows, including prompt engineering artifacts and Model Context Protocol implementations. * Familiarity with Agile/Scrum delivery methodologies and enterprise IT service management practices. * Scripting and automation experience (e.g., Python, PowerShell) to support policy tuning and reporting. * Strong analytical, written, and verbal communication skills, with the ability to translate technical risk into terms suitable for executive and government stakeholders. * Ability to work collaboratively with others and contribute to a team environment. ## Description Halvik is seeking a Senior Security Engineer to support a customer's enterprise initiative that enables secure, compliant adoption of Artificial Intelligence (AI) across their agency's hybrid environment. This role leads the design, implementation, and operationalization of enterprise-scale data discovery and classification, AI governance and protection controls, and detection capabilities for emerging AI-native development artifacts (e.g., Markdown-based prompt files, cursor rules, GitHub Copilot instructions, and Model Context Protocol configuration files). The Senior Security Engineer will serve as a technical lead on the program, working closely with customer stakeholders, the COR/CO, and Halvik delivery leadership to protect sensitive agency and stakeholder information while enabling the agency's AI adoption goals. This is a Hybrid position requiring work at the customer location in Alexandria, VA. Core Responsibilities * Strategic Execution: Lead the architecture and phased rollout of enterprise data discovery, classification, and AI governance capabilities, prioritizing high-risk repositories and expanding coverage across cloud, on-premises, SaaS, and developer environments. * AI Governance & Enforcement: Design and tune policy-based controls (allow, block, alert, redact, route) that monitor AI prompts, responses, and related artifacts in real time or near-real-time to prevent unauthorized disclosure of sensitive information. * Emerging AI Artifact Security: Own detection, classification, and protection of AI-native development artifacts, including Markdown prompt files, cursor rules, Copilot instructions, and MCP configuration files, across repositories, shared drives, and developer workspaces. * Operational Oversight: Maintain auditable enforcement records, oversee remediation workflows for policy exceptions and exposure events, and ensure timely, traceable resolution of compliance findings. * Collaboration: Partner with customer stakeholders, the COR/CO, and cross-functional Halvik teams to align implementation with the agency's cloud migration timeline, security approvals, and AI expansion roadmap. * Technical Performance: Architect integrations with enterprise DLP/CASB platforms, SIEM, and identity/access workflows; support early, automated detection of vulnerabilities in code, containers, and infrastructure-as-code templates, including flaws introduced by AI components or data pipelines feeding AI models. * Mentorship & Quality: Provide technical guidance and review for mid-level engineers and contribute to deliverables including the Enterprise Architecture and Deployment Plan, Discovery and Classification Configuration, and AI Governance and Enforcement Configuration. * Continued Proficiency: Stays current with emerging AI technologies and cybersecurity trends to ensure best-in-class practices. ## Related Videos - [Why and when should we consider Stream Processing frameworks in our solutions](https://www.wearedevelopers.com/videos/1085-why-and-when-should-we-consider-stream-processing-frameworks-in-our-solutions) - [Why Is Software Documentation Still Static – And Why Modern Browsers Deserve Better](https://www.wearedevelopers.com/videos/2054-why-is-software-documentation-still-static-and-why-modern-browsers-deserve-better) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Python-Based Data Streaming Pipelines Within Minutes](https://www.wearedevelopers.com/videos/1233-python-based-data-streaming-pipelines-within-minutes) - [WeAreDevelopers LIVE - 11ty and a11y](https://www.wearedevelopers.com/videos/1822-wearedevelopers-live-11ty-and-a11y) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 196: AI Killed DevOps, LLM Political Bias & AI Security](https://www.wearedevelopers.com/magazine/659-dev-digest-196-ai-killed-devops-llm-political-bias-ai-security) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)