Senior AI/Cybersecurity Solutions Engineer

RCG, Inc.
Suitland-Silver Hill, MD, United States
3 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
2 years minimum
Compensation
$130,000.0 - $140,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Agile Methodology Artificial Intelligence Amazon Web Services Amazon Elastic Compute Cloud Amazon S3 Confluence JIRA Audit Trail Cloud Computing Cloud Computing Security Cyber Security
+31 more
Continuous Integration Data Validation Software Design Documents Identity and Access Management Python (Programming Language) OpenID Azure Machine Learning Security Information and Event Management Visual Studio Online Workflow Management Systems Openapi Jupyter Notebook Delivery Pipeline Large Language Models Prompt Engineering Boto3 Generative AI Gitlab Git Cloudformation Gitlab-ci Kubernetes Information Technology Atlassian Tools Microsoft Sentinel Code Inspection CIS Benchmarks Terraform Software Version Control Security Orchestration, Automation & Response Vulnerability Analysis

Job description

RCG is seeking a Senior AI/Cybersecurity Solutions Engineer to support a federal Security, Architecture, and Engineering (SAE) team in Suitland, MD. This is a hands-on senior engineering role for an experienced professional who combines generative and agentic AI engineering, cloud security, cybersecurity automation, and federal compliance expertise. The selected candidate will help drive an agentic AI security platform, develop and harden automation supporting NIST 800-53 security assessments and remediation workflows, and take ownership of technical workstreams from requirements and implementation through CI/CD, deployment, and evidence generation. The ideal candidate will be equally comfortable developing Python-based AI automation, working with AWS security services and IAM, implementing secure cloud solutions, and maintaining the technical documentation and project traceability required in an auditable federal environment., * Design and implement Amazon Bedrock agent action groups, including OpenAPI schemas and Python Lambda execution layers.

  • Develop Retrieval-Augmented Generation (RAG) pipelines using Bedrock Knowledge Bases with sources such as NIST 800-53, CIS Benchmarks, organizational System Security Plans (SSPs), and threat intelligence.
  • Engineer prompts, guardrails, and input validation to improve AI accuracy, security, and resistance to prompt-injection attacks.
  • Evaluate and evolve foundation-model strategies as AI capabilities and platform requirements mature.
  • Develop AI-assisted capabilities supporting security assessment, remediation, hardening, alert triage, and compliance workflows.

Cloud & Cybersecurity Engineering

  • Build automated NIST 800-53 control assessments and security evidence collection capabilities.
  • Develop remediation and hardening automation across AWS services, including S3, EC2, IAM, CloudTrail, ECS, and EKS.
  • Integrate live data from AWS Security Hub, GuardDuty, Inspector, and Config to support environment-aware security analysis and AI-assisted decision-making.
  • Support BOD 26-04 SLA logic, CISA KEV correlation, risk enrichment, and remediation SLA tracking.
  • Support security telemetry aggregation and integration with SIEM technologies, including Microsoft Sentinel and AWS Security Lake.

Container & Software Supply Chain Security

  • Support ECR vulnerability scanning, EKS runtime monitoring, and container configuration hardening.
  • Develop and analyze Software Bills of Materials (SBOMs) using formats such as SPDX and CycloneDX.
  • Correlate vulnerabilities with the CISA Known Exploited Vulnerabilities (KEV) catalog to support risk-based prioritization.
  • Perform dependency, provenance, and software supply-chain security checks, including detection of typosquatting and unsigned container images.

Platform Engineering & Delivery

  • Maintain GitLab CI/CD pipelines supporting linting, testing, security scanning, builds, and deployments.
  • Implement secure OIDC-based AWS authentication.
  • Develop and manage Infrastructure as Code using CloudFormation and/or Terraform with least-privilege IAM.
  • Support deployment and rollout verification across application and Kubernetes/EKS environments.
  • Maintain strong Git practices, including branching, merge requests, and clean version-control history.

Documentation, Compliance & Technical Leadership

  • Manage engineering work through Jira, maintaining accurate tickets, epics, sub-tasks, workflows, status, and handoffs.
  • Maintain Confluence documentation, including architecture guides, runbooks, decision records, and onboarding materials.
  • Produce technical design documentation, evidence packages, and other artifacts capable of supporting federal security assessments and audits.
  • Maintain traceability between requirements, engineering work, code, deployments, and security evidence.

Take primary ownership of assigned technical workstreams and collaborate closely with cybersecurity and engineering team members.

Requirements

  • Bachelor’s degree in computer science, Cybersecurity, or a related technical discipline.
  • 6+ years of cloud security engineering experience.
  • 2+ years of production experience with generative AI/LLM technologies.
  • 4+ years of experience working with AWS security services.
  • 3+ years of experience supporting federal compliance frameworks such as NIST, FedRAMP, and FISMA.
  • 2+ years of active Jira and Confluence experience in an Agile or technical delivery environment.
  • Expert-level Python development experience, including Python 3.11+, boto3, type hints, and robust error handling.
  • Advanced experience with Amazon Bedrock, including agents, action groups, Knowledge Bases, guardrails, prompt engineering, and RAG.
  • Expert knowledge of AWS security technologies, including Security Hub, GuardDuty, Inspector, Config, IAM, CloudTrail, and OIDC.
  • Advanced container security experience with ECR, ECS/EKS, image scanning, runtime monitoring, and hardening.
  • Expert knowledge of NIST SP 800-53 Rev. 5, including control families, assessment procedures, and evidence requirements.
  • Advanced experience with CI/CD and Infrastructure as Code technologies, including GitLab CI and CloudFormation and/or Terraform.
  • Advanced Git/version-control experience.
  • Demonstrated experience managing technical work in Jira and maintaining team documentation in Confluence., * Master’s degree in a related technical discipline.
  • 3+ years of experience building production AI agents.
  • Experience supporting ATO and continuous monitoring activities.
  • Experience administering or configuring Jira boards and Confluence spaces.
  • Experience supporting federal IT security programs.
  • Familiarity with CISA Binding Operational Directives, including BOD 22-01 and BOD 26-04.
  • Experience with AWS Security Lake, OCSF, OSCAL machine-readable compliance, or Microsoft Sentinel integration.
  • Experience with AI red teaming or adversarial testing of LLM applications.
  • Familiarity with software supply-chain technologies and frameworks such as SLSA, Sigstore, and in-toto.
  • Certifications such as AWS Certified Security - Specialty, CISSP, CISM, CKS, or AWS machine learning certification are preferred.

Work Environment

This is a full-time, 100% on-site position in Suitland, MD supporting a federal government cybersecurity and enterprise IT environment. The selected candidate will work as part of a highly technical Security, Architecture, and Engineering (SAE) team supporting AI, security automation, cloud security, compliance, and related engineering initiatives. The role requires strong individual ownership as well as close collaboration with cybersecurity engineers, technical leadership, and other program personnel. The technical environment includes AWS, Amazon Bedrock, EKS, GitLab, GitLab CI, AWS CodePipeline, Jira, Confluence, Python, VS Code, Jupyter Notebook, and related cloud and cybersecurity technologies.

Please Note

Due to the requirements of this federal program, successful candidates must be a U.S. Citizen or Lawful

Permanent Resident and must be eligible to obtain and maintain a Public Trust. Employment is contingent upon successful completion of all applicable government background investigation and customer onboarding requirements.

Benefits & conditions

Employment Type: Full-Time Work Arrangement: 100% On-Site Security Requirement: Must be U.S. Citizen or Lawful Permanent Resident eligible to obtain and maintain a Public Trust Salary Range: $130,000 - $140,000, Why You’ll Love Working Here

  • Work for a company proudly Certified as a Great Place to Work® for four consecutive years.
  • Support mission-focused federal cybersecurity and technology initiatives.
  • Work directly with emerging generative AI and agentic AI technologies.
  • Solve complex challenges involving AI, cybersecurity, cloud security, automation, and federal compliance.
  • Work with modern AWS security, container, DevSecOps, and Infrastructure as Code technologies.
  • Opportunities for continued technical and professional development.
  • Comprehensive benefits including medical, dental, vision, paid time off, paid holidays, and a 401(k) with company match., * Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Family Leave (Maternity, Paternity)
  • Short Term & Long Term Disability
  • Training & Development
  • Wellness Resources

About the company

RCG, Inc. is a growing federal contracting company proudly Certified as a Great Place to Work® for four consecutive years. We provide innovative technology and cybersecurity solutions supporting complex federal government environments.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:12 min

Validating risky service requests safely via dry runs

Modood Alvi · World Congress 2025

3:05 min

Integrating an assistant application with Jira software

Felix Augenstein · LIVE

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

5:47 min

Integrating user stories and test automation via Jira tools

Christoph Ruggenthaler · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all