Job Summary
The Senior AI Security Engineer will support the integration of agentic AI capabilities into a modern eCommerce platform, securing both guest-facing autonomous experiences and internal agentic services. The role sits at the intersection of agentic AI security, identity and access management, application security, and cloud/edge security. The engineer will design and operationalize runtime guardrails, identity-aware authorization, policy enforcement, and security controls across edge, API, service, and AI runtime layers. This is an onsite position requiring four days per week in Miami, FL for the duration of the contract.
Key Responsibilities
• Design and implement security control planes for agentic AI systems.
• Define runtime authorization boundaries for AI agents, including tool-level access controls and least-privilege execution.
• Establish policy enforcement points governing agent behavior before high-impact actions.
• Support human-in-the-loop workflows for sensitive or high-risk AI-initiated actions.
• Design and review identity models for guests, employees, and non-human agent/workload identities.
• Implement or advise on OAuth/OIDC-based delegation and short-lived credential strategies.
• Ensure end-to-end attribution across user, agent, and tool execution chains.
• Secure guest-facing eCommerce flows including search, personalization, cart, and booking.
• Review backend service architectures supporting AI-driven eCommerce experiences.
• Promote agent-safe API patterns including idempotency, preview/apply, rollback, and rate limiting.
• Collaborate on edge security controls including WAFs, bot mitigation, and API gateways.
• Ensure consistent security enforcement from edge to API to service to AI runtime layers.
• Support secure cloud-native, containerized, and sandboxed deployment patterns across Google Cloud, AWS, and Azure.
• Define security telemetry and audit requirements for agentic AI systems.
• Support detection and response for runaway agents and excessive autonomy.
• Align AI security implementations with enterprise security standards and governance requirements.
• Build and secure AI solutions from end to end, from initial design through production implementation.
Required Qualifications
• 8+ years of experience in security engineering, application security, or platform security.
• Hands-on experience securing large-scale, consumer-facing eCommerce platforms.
• Strong understanding of web application and API security.
• Strong understanding of security architecture and application security principles.
• Deep knowledge of OAuth 2.0/2.1, OIDC, token-based authorization, and service principals.
• Experience designing fine-grained, least-privilege access models for distributed systems.
• Experience with Non-Human Identity (NHI) lifecycle management in highly dynamic environments.
• Experience working with AI-enabled or automation-heavy systems.
• Experience building AI solutions from start to finish.
• Familiarity with security risks unique to agentic and autonomous systems.
• Ability to reason about non-deterministic AI execution and enforce deterministic security controls.
• Knowledge of MCP security standards and agent runtime authorization.
• Experience with WAFs, API gateways, and edge security controls.
• Familiarity with cloud-native architectures and service-to-service security.
• Strong DevSecOps and Application Security experience.
• Ability to ensure consistent security enforcement across edge, API, service, and AI runtime layers.
• Ability to collaborate effectively with product, platform, AI/ML, and identity teams.
• Strong written and verbal communication skills with the ability to translate complex security concepts into practical guidance.
Preferred Qualifications
• Experience with agent frameworks or AI orchestration systems.
• Familiarity with policy-as-code or runtime enforcement models.
• Background in fraud, abuse prevention, or financial transaction security.
• Experience working in regulated or high-availability environments.