The Prompt Engineer (Vulnerability & Risk Analytics) designs and governs AI-assisted workflows that accelerate the analysis of software vulnerability and risk data for the TESS program. Operating on-site in Arlington, VA, the engineer will utilize CISA-approved enterprise AI tools (primarily Microsoft Copilot) to transform complex security datasets into actionable intelligence. The position requires disciplined testing, structured framework design, and detailed documentation to ensure all AI outputs are reliable, secure, and reproducible in a federal cybersecurity environment.
Key Responsibilities- Structured Prompt Design: Craft, deploy, and refine structured system and user prompts utilizing advanced role-play and constraint strategies to support software vulnerability analysis, CVE/CWE parsing, and threat risk summaries.
- Model Optimization & Parametric Testing: Systematically test model outputs across varied enterprise temperature and grounding parameters to eliminate hallucinations in risk scoring and threat summarization.
- Governance & Prompt Library Management: Document prompt patterns, maintain a centralized, version-controlled repository of reusable prompts, and establish clear guidelines for when to apply specific techniques.
- Quality Gates & Reproducibility: Enforce rigorous validation and reproducibility rubrics to benchmark prompt accuracy, consistency, and repeatability across software supply chain and vulnerability data feeds.
- Operational Alignment: Translate manual CISA cybersecurity workflows into standardized AI-assisted templates to assist technical delivery teams and capability leadership.
Salary Range: $120,000 - $140,000
General Description of Benefits
- Active Top Secret (TS) clearance with the ability to obtain DHS/CISA Suitability.
- 3+ years of professional experience working with AI/ML tools or large language models, with a strong preference for candidates supporting federal, defense, or intelligence organizations.
- Experience with Primary Tooling: CISA-approved AI toolsets (Enterprise Microsoft Copilot / M365 Copilot / GovCloud AI Environment)
- CompTIA Security+ or an equivalent CompTIA certification meeting DoD 8140/8570 IAT Level II requirements.
- Demonstrated expertise in generative AI prompt engineering techniques (such as chain-of-thought, few-shot framing, and system instructions) and prompt evaluation/testing methodologies.
- Proven capability to document, standardize, and scale repeatable technical practices for broader team adoption.