> Markdown version of [/jobs/ext/3401881-ai-security-engineer-hybrid-us-citizens-green-cards-local-to](https://www.wearedevelopers.com/jobs/ext/3401881-ai-security-engineer-hybrid-us-citizens-green-cards-local-to). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # AI Security Engineer- Hybrid (US Citizens/ Green Cards- Local to - **Company:** SWINGTECH, LLC - **Location:** Washington, DC, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Audit Trail, Microsoft Azure, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, Continuous Integration, Federal Information Processing Standards (FIPS), Key Management, Open Web Application Security, Role-Based Access Control, Cloud Services, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Data Logging, SARS Software Products, Large Language Models, Software Security, AI Platforms, Information Technology, Data Management, Data Pipelines, Devsecops, Static Application Security Testing, Dynamic Application Security Testing - **Published:** September 22, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9190450/ai-security-engineer-hybrid-us-citizens-green-cards-local-to ## About the Role * Bachelor's degree in cybersecurity, computer science, information assurance, engineering, information systems, or a related field. * At least five years of experience in cybersecurity engineering, cloud security, application security, DevSecOps, security architecture, RMF/ATO, or comparable technical security roles. * Experience with Federal cybersecurity frameworks, including FISMA, NIST SP 800-53, NIST SP 800-171, FIPS 199, FIPS 200, FedRAMP, and RMF/ATO. * Experience securing cloud applications, APIs, data platforms, CI/CD pipelines, identity services, and containerized or cloud-native systems. * Experience with vulnerability management, security logging and monitoring, incident response, security testing, and security documentation. * Working knowledge of AI/ML security threats, including prompt injection, jailbreaking, model compromise, model extraction, data poisoning, RAG poisoning, retrieval manipulation, and AI supply-chain risks. * Strong communication skills and ability to coordinate with engineering, privacy, governance, security, program-management, and Government stakeholders. * Must be willing to work 3 days onsite at customer site in Washington, DC., * CISSP, CCSP, CISM, Security+, AWS Security Specialty, Azure Security Engineer, GIAC, CEH, or comparable security certification. * Experience with AI red teaming, AI threat modeling, OWASP Top 10 for LLM Applications, NIST AI RMF, CISA AI guidance, MITRE AI security frameworks, or adversarial ML testing. * Experience with SIEM/SOAR, CSPM, secrets management, SAST/DAST, container security, SBOMs, software supply-chain assurance, and cloud security posture management. * Experience with Federal civilian agencies, Government ATO packages, or FedRAMP environments. ## Description The AI Security Engineer designs, assesses, documents, and improves cybersecurity, privacy, and AI-specific security controls for DOL AI systems. The role ensures that AI-enabled applications, data pipelines, models, RAG systems, vector stores, agentic workflows, APIs, and cloud services are secured and supported by evidence required for Government authorization and production release., * Develop and implement AI security architecture, threat models, control matrices, security requirements, abuse cases, test plans, and remediation plans. * Implement and validate security controls across AI applications, LLM integrations, data pipelines, model endpoints, RAG systems, vector stores, MCP servers, APIs, orchestration services, and CI/CD pipelines. * Conduct AI-specific security testing, including prompt injection, jailbreaks, malicious-input attacks, retrieval manipulation, data poisoning, model extraction, model inversion, credential compromise, access-control bypass, insecure output handling, and tool-abuse scenarios. * Apply Zero Trust, least privilege, role-based access, FIPS-validated encryption, secrets management, audit logging, secure configuration, vulnerability management, and secure software-development practices. * Support FISMA, RMF, and ATO activities, including security categorization, system boundaries, SSPs, SAPs, SARs, POA&Ms, continuous monitoring, security assessments, risk decisions, and remediation evidence. * Support assessment and approval of AI models, third-party AI services, cloud services, model providers, APIs, tools, and data-handling practices before their integration into DOL systems. * Validate that approved cloud AI services satisfy applicable FedRAMP requirements and DOL authorization expectations. * Ensure PII, CUI, prompts, retrieval context, embeddings, model outputs, logs, backups, and evaluation data are protected through approved controls. * Support AI Incident Response Plan development and maintenance, including escalation paths, evidence preservation, reporting templates, severity classification, containment procedures, and post-incident review. * Coordinate security incident investigation, containment, mitigation, recovery, and reporting for suspected or confirmed security events. * Support supply-chain security, Software Bill of Materials generation, dependency scanning, secure-development attestations, vulnerability remediation, and third-party risk management. * Collaborate with engineering teams to integrate security into development, testing, deployment, and production operations. ## Related Videos - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) - [The New AI Security Stack: Observe, Detect, Protect](https://www.wearedevelopers.com/videos/100302-the-new-ai-security-stack-observe-detect-protect) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [What Industries Outside of AI Are Hiring The Most AI Experts?](https://www.wearedevelopers.com/magazine/98-what-industries-outside-of-ai-are-hiring-the-most-ai-experts) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud)