Job Summary
The Security Harness Engineer will design and deliver production-grade AI capabilities that strengthen software security across the Software Development Lifecycle (SDLC), with a focus on secure agentic workflows, AI-generated code assurance, enterprise integration, and scalable engineering practices. The role will develop AI-enabled security capabilities, integrate enterprise platforms, apply secure architecture and systems design principles, and partner with engineering, security, product, and leadership stakeholders. This is a fully onsite position in Round Rock, Texas.
Key Responsibilities
• Design, build, and deploy AI-enabled capabilities across the software development lifecycle.
• Develop specification-driven workflows that translate well-formed specifications into secure and verifiable implementations.
• Implement guardrails, policy enforcement, and verification capabilities for AI-generated code produced by AI assistants and agents.
• Develop developer-assist and verification tooling to automate security checks, including design reviews, dependency and software supply-chain analysis, static and dynamic analysis orchestration, and release audit support.
• Integrate solutions with source control, CI/CD, ticketing, security scanning, identity, and internal platforms using APIs, webhooks, and protocols such as MCP.
• Apply architecture and systems design practices, including well-defined service boundaries, appropriate data models, secure defaults, observability, and extensibility.
• Partner with engineering, security, product, and leadership stakeholders to define requirements, evaluate trade-offs, and support solution adoption.
Required Qualifications
• Demonstrated experience developing and deploying AI-based solutions in production environments with measurable business or operational impact.
• Strong programming proficiency in Python, TypeScript/JavaScript, Go, or a similar programming language.
• Strong software engineering practices including testing, code quality, and maintainability.
• Hands-on experience with modern AI and LLM development, including context engineering, agentic system design, context-window management, token budgeting, and evaluation of AI quality, reliability, and safety.
• Experience designing model context through agentic retrieval and search, memory architectures, enterprise data grounding, and structured outputs.
• Experience engineering agent loops, multi-agent and sub-agent orchestration, and tool or function calling.
• Ability to optimize AI workloads for production cost and latency.
• Solid understanding of software architecture and systems design, including API design, event-driven patterns, and scalable data modeling.
• Experience developing or deploying applications with large-scale impact, such as broad user bases, high transaction volumes, or organization-wide adoption.
• Experience integrating multiple systems and platforms, including REST or GraphQL APIs, CI/CD pipelines, cloud services, and enterprise tooling.
• Ability to work independently across the full delivery lifecycle, including requirements analysis, solution design, implementation, deployment, stakeholder engagement, and accountability for results.
• Strong communication and collaboration skills, with the ability to communicate technical concepts to engineering and business audiences.
• Working knowledge of secure development practices and experience designing solutions that meet enterprise security and compliance requirements.
Preferred Qualifications
• Experience applying AI within security domains such as application security, DevSecOps, code analysis, threat modeling, firmware security, or software supply-chain security.
• Familiarity with secure-by-design and secure-by-default principles and frameworks including OWASP, OWASP Top 10 for LLM Applications, and NIST SSDF.
• Experience with MCP (Model Context Protocol), building agent skills and tools, or extending AI coding assistants such as Claude Code, GitHub Copilot, Cursor, or Devin.
• Experience with AI evaluation frameworks, guardrails, prompt and response caching strategies, and LLMOps in production.
• Bachelor's or master's degree in Computer Science or a related field, or equivalent practical experience.