AI Security Engineer- Hybrid (US Citizens/ Green Cards- Local to

SWINGTECH, LLC
Washington, DC, United States
12 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Audit Trail Microsoft Azure Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security Information Systems Continuous Integration Federal Information Processing Standards (FIPS)
+18 more
Key Management Open Web Application Security Role-Based Access Control Cloud Services Zero Trust Network Access Security Information and Event Management Software Vulnerability Management Data Logging SARS Software Products Large Language Models Software Security AI Platforms Information Technology Data Management Data Pipelines Devsecops Static Application Security Testing Dynamic Application Security Testing

Job description

The AI Security Engineer designs, assesses, documents, and improves cybersecurity, privacy, and AI-specific security controls for DOL AI systems. The role ensures that AI-enabled applications, data pipelines, models, RAG systems, vector stores, agentic workflows, APIs, and cloud services are secured and supported by evidence required for Government authorization and production release., * Develop and implement AI security architecture, threat models, control matrices, security requirements, abuse cases, test plans, and remediation plans.

  • Implement and validate security controls across AI applications, LLM integrations, data pipelines, model endpoints, RAG systems, vector stores, MCP servers, APIs, orchestration services, and CI/CD pipelines.
  • Conduct AI-specific security testing, including prompt injection, jailbreaks, malicious-input attacks, retrieval manipulation, data poisoning, model extraction, model inversion, credential compromise, access-control bypass, insecure output handling, and tool-abuse scenarios.
  • Apply Zero Trust, least privilege, role-based access, FIPS-validated encryption, secrets management, audit logging, secure configuration, vulnerability management, and secure software-development practices.
  • Support FISMA, RMF, and ATO activities, including security categorization, system boundaries, SSPs, SAPs, SARs, POA&Ms, continuous monitoring, security assessments, risk decisions, and remediation evidence.
  • Support assessment and approval of AI models, third-party AI services, cloud services, model providers, APIs, tools, and data-handling practices before their integration into DOL systems.
  • Validate that approved cloud AI services satisfy applicable FedRAMP requirements and DOL authorization expectations.
  • Ensure PII, CUI, prompts, retrieval context, embeddings, model outputs, logs, backups, and evaluation data are protected through approved controls.
  • Support AI Incident Response Plan development and maintenance, including escalation paths, evidence preservation, reporting templates, severity classification, containment procedures, and post-incident review.
  • Coordinate security incident investigation, containment, mitigation, recovery, and reporting for suspected or confirmed security events.
  • Support supply-chain security, Software Bill of Materials generation, dependency scanning, secure-development attestations, vulnerability remediation, and third-party risk management.
  • Collaborate with engineering teams to integrate security into development, testing, deployment, and production operations.

Requirements

  • Bachelor’s degree in cybersecurity, computer science, information assurance, engineering, information systems, or a related field.
  • At least five years of experience in cybersecurity engineering, cloud security, application security, DevSecOps, security architecture, RMF/ATO, or comparable technical security roles.
  • Experience with Federal cybersecurity frameworks, including FISMA, NIST SP 800-53, NIST SP 800-171, FIPS 199, FIPS 200, FedRAMP, and RMF/ATO.
  • Experience securing cloud applications, APIs, data platforms, CI/CD pipelines, identity services, and containerized or cloud-native systems.
  • Experience with vulnerability management, security logging and monitoring, incident response, security testing, and security documentation.
  • Working knowledge of AI/ML security threats, including prompt injection, jailbreaking, model compromise, model extraction, data poisoning, RAG poisoning, retrieval manipulation, and AI supply-chain risks.
  • Strong communication skills and ability to coordinate with engineering, privacy, governance, security, program-management, and Government stakeholders.
  • Must be willing to work 3 days onsite at customer site in Washington, DC., * CISSP, CCSP, CISM, Security+, AWS Security Specialty, Azure Security Engineer, GIAC, CEH, or comparable security certification.
  • Experience with AI red teaming, AI threat modeling, OWASP Top 10 for LLM Applications, NIST AI RMF, CISA AI guidance, MITRE AI security frameworks, or adversarial ML testing.
  • Experience with SIEM/SOAR, CSPM, secrets management, SAST/DAST, container security, SBOMs, software supply-chain assurance, and cloud security posture management.
  • Experience with Federal civilian agencies, Government ATO packages, or FedRAMP environments.

Benefits & conditions

  • 15 PTO days
  • 11 paid holidays
  • Medical Insurance with - 3 options (HSA with $600 Employer Contribution).
  • Dental Insurance with no age limit orthodonture.
  • Vision Insurance through EyeMed in and out of network coverage.
  • Short Term and Long-Term Disability coverage with 100% premium support,
  • Life insurance and AD&D with 100% premium support
  • Supplemental Life Insurance
  • Critical Care and Accident Insurance availability
  • Pet Insurance through Nationwide
  • Employee Assistance Program
  • 401k with enrollment from day one. 4% deferral by company.
  • $1500 Annual Training Budget
  • $1500 Referral bonus
  • Eligibility for annual merit and discretionary bonus
  • Flexible work arrangements

About the company

Swingtech delivers innovative Information Technology and Professional Support services to a diverse range of clients across the federal and intelligence communities. With over 15 years of trusted experience as a systems integrator, we apply agile methodologies and deep industry insight to help our customers achieve greater efficiency, compliance, and cost savings. At Swingtech, we’re committed to excellence and long-term success for our clients and our team.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

1:53 min

Adopting Kubernetes and GitOps for standardized deployment environments

Lian Li · World Congress 2022

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

1:45 min

Addressing active AI incident remediation and broad ecosystem support

Matthew Brady Matthew Brady · World Congress 2026 Europe

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

3:00 min

Top security vulnerabilities for AI applications

Deepu Deepu · World Congress 2025

Videos

See all

Related articles

See all