Job Type
Full-time
Description
Position Details: Job Title: AI Security Engineer
Job Type: Full-time
Location: Remote, MD
Requirements
Roles & Responsibilities: Security Architecture for AI Workloads
- Design reference architectures for secure LLM/AI agent deployments across Azure, AWS, or hybrid environments.
- Establish defense-in-depth controls for model endpoints, vector databases, prompt routing, tools/plugins, and orchestration layers.
Guardrails & Policy Enforcement
- Implement runtime guardrails including prompt injection defenses, output content filtering, PII detection/redaction, jailbreak prevention, and tool use restrictions.
- Codify enterprise policies (acceptable use, data residency, retention, secrets handling) into enforceable controls through middleware, gateways, and policy engines.
Identity, Access & Data Protection
- Integrate Entra ID / Azure AD, OAuth/OIDC, and RBAC/ABAC models.
- Apply data security measures including DLP, encryption, key management/HSM, tokenization, and fine-grained data access for RAG pipelines.
Secure SDLC for AI
- Embed threat modeling, secure coding, dependency scanning, secret scanning, and SAST/DAST into AI app pipelines.
- Define AI-specific code review checklists for prompt templates, tool bindings, and agent plans.
Risk, Governance & Compliance
- Operationalize NIST AI RMF, ISO/IEC 27001 & 42001, SOC 2; align with FedRAMP, FISMA, NIST 800-53, and agency-specific controls.
- Maintain model cards, data lineage, evaluation reports, and audit trails for AI decisions and tool calls.
AI Red Teaming & Evaluation
- Design adversarial tests for jailbreaks, prompt injections, data exfiltration attempts, and toxic outputs.
- Build automated evaluation harnesses and metrics such as hallucination rates, sensitive content occurrence, and tool misuse rates.
Monitoring & Incident Response
- Establish observability for AI systems including privacy-aware logging, policy hits, model drift detection, cost governance, and anomalies.
- Define playbooks for AI incidents involving unsafe outputs, data leakage, compromised tools, or model endpoint abuse.
Stakeholder Enablement
- Partner with Product and Engineering teams to safely accelerate new AI use cases.
- Provide training and guidance on responsible AI, secure agent design, and safe prompt engineering.
Required Professional Skills: Cloud & AI Platforms
- Azure (Azure OpenAI, AI Studio, AKS, Key Vault, Entra ID, Defender), Microsoft Purview, and M365 Copilot governance.
- Experience with AWS (Bedrock, SageMaker, KMS) or GCP Vertex AI.
LLM/Agent Security
- Hands-on guardrail implementation including content filters, safety classifiers, prompt injection defenses, jailbreak prevention, and tool whitelisting.
- Securing RAG pipelines and vector databases (Cosmos DB + pgvector/FAISS, Pinecone, Weaviate).
Identity & Access
- OAuth/OIDC, SAML, SCIM, RBAC/ABAC; secrets management via Key Vault, Parameter Store, or Vault.
Data Security
- Encryption, tokenization, redaction, differential privacy basics, DLP-based PII/PHI detection.
- Experience with data classification, retention, and lineage.
Application Security & DevSecOps
- STRIDE threat modeling, secure coding, dependency scanning, secret scanning, SAST/DAST.
- CI/CD for AI apps (GitHub Actions/Azure DevOps), IaC (Bicep/Terraform), policy-as-code (OPA/Conftest/Azure Policy).
Observability & Incident Response
- Logging with Azure Monitor/Sentinel, tracing, metrics, and automated AI evaluation pipelines integrated with SIEM/SOAR.
Compliance & Governance
- Working knowledge of NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, and public sector controls.
- Experience documenting controls, audits, and risk assessments.
Programming & Frameworks
- Proficiency in Python or TypeScript/Node.js.
- Experience with agent/orchestration frameworks (LangChain, Semantic Kernel, Guidance, DSPy).
Preferred Professional Skills: - 5-8+ years in application/cloud security with 2+ years in AI/ML or LLM security.
- Experience enabling enterprise AI use cases or AI agents in regulated environments.
- Familiarity with Microsoft Copilot for M365 governance and Microsoft Purview.
- Experience with AI red teaming and building evaluation harnesses.
- Exposure to privacy regulations (HIPAA, GLBA, GDPR/CCPA) and public-sector compliance.
- Contributions to security frameworks or open-source guardrail tools
Dynanet Team Requirements and Expectations: - Possess Strong written and verbal communication skills.
- Highly organized with the ability to prioritize, balance, and effectively advance multiple competing priorities in a high-volume, fast-paced environment.
- Ability to interact in a professional and collaborative manner with fellow Dynanet Teammates and the clients, and business partners that we work with.
- Ability and desire to challenge and educate yourself to support and advance IT services delivery in the Federal agencies we serve.
- Excellent judgment and creative problem-solving skills.
- Respond to team member and client requests via email, MS teams, or other communication means during core business hours.
- Active listening skills to understand clients' needs, and collaboration skills to work with other developers and designers.
Education/Experience Requirements: - Relevant degree in Computer Science, Engineering, Cybersecurity, or equivalent experience.
Nice to Have Certs - CISSP, CCSP, Azure Security Engineer (AZ-500), GIAC (GWEB/GWAPT/GXPN), OSCP.
- Azure AI Engineer (AI-102), Azure Solutions Architect (AZ-305), AWS Security Specialty.
- CISA, ISO 27001 Lead Implementer, Responsible AI certifications
Employee Benefits Overview: - Industry Competitive Compensation
- Medical and Dental Insurance
- Paid Time Off/Holidays
- 401(k) Retirement Plans with Matching
- Remote Work*
- Paid Training
- Employee Referral Program
- Employee Development Program