Senior AI/Cybersecurity Solutions Engineer
Senior
Agent
Ai Security
Ai Security Evaluation
Artificial Intelligence Security Evaluation
Aws Cloud Security
Aws Solutions Architect
Cloud Platforms
Cybersecurity Tools
Data Analysis
Data Security
Facilities Management
Identity and Access Management
Information Security
Information Technology (IT)
InfoSec
Risk Management
Security
Security Automation
Security Compliance
Security Engineering
Security Operations
Security Standards
Security Testing
Solution Architecture
Job Description
RCG is seeking a Senior AI/Cybersecurity Solutions Engineer for a federal Security, Architecture, and Engineering (SAE) team in Suitland, MD (100% onsite). This hands-on role combines generative and agentic AI security automation on AWS with NIST 800-53 assessment support, remediation workflows, and compliance evidence generation.
What you’ll get
- Health Care Plan (Medical, Dental & Vision)
- Retirement Plan (401k, IRA) and 401(k) with company match
- Life Insurance (Basic, Voluntary & AD&D)
- Paid Time Off (Vacation, Sick & Public Holidays)
- Family Leave (Maternity, Paternity)
- Short Term & Long Term Disability
- Training & Development
- Wellness Resources
Responsibilities
- Design and implement Amazon Bedrock agent action groups, including OpenAPI schemas and Python Lambda execution layers.
- Develop Retrieval-Augmented Generation (RAG) pipelines using Bedrock Knowledge Bases, leveraging sources such as NIST 800-53, CIS Benchmarks, organizational System Security Plans (SSPs), and threat intelligence.
- Engineer prompts, guardrails, and input validation to improve accuracy, security, and resistance to prompt-injection attacks.
- Evaluate and evolve foundation-model strategies as AI capabilities and platform requirements mature.
- Develop AI-assisted capabilities for security assessment, remediation, hardening, alert triage, and compliance workflows.
- Build automated NIST 800-53 control assessments and security evidence collection capabilities.
- Develop remediation and hardening automation across AWS services, including S3, EC2, IAM, CloudTrail, ECS, and EKS.
- Integrate live data from AWS Security Hub, GuardDuty, Inspector, and Config to support environment-aware security analysis and AI-assisted decision-making.
- Support BOD 26-04 SLA logic, CISA KEV correlation, risk enrichment, and remediation SLA tracking.
- Support telemetry aggregation and integration with SIEM technologies, including Microsoft Sentinel and AWS Security Lake.
- Support ECR vulnerability scanning, EKS runtime monitoring, and container configuration hardening.
- Develop and analyze Software Bills of Materials (SBOMs) using SPDX and CycloneDX.
- Correlate vulnerabilities with CISA Known Exploited Vulnerabilities (KEV) to support risk-based prioritization.
- Perform supply-chain security checks, including detection of typosquatting and unsigned container images.
- Maintain GitLab CI/CD pipelines for linting, testing, security scanning, builds, and deployments.
- Implement secure OIDC-based AWS authentication.
- Develop and manage Infrastructure as Code using CloudFormation and/or Terraform with least-privilege IAM.
- Support deployment and rollout verification across application and Kubernetes/EKS environments.
- Maintain strong Git practices (branching, merge requests, and clean version-control history).
- Manage engineering work through Jira and maintain engineering documentation in Confluence.
- Produce technical design documentation, evidence packages, and artifacts capable of supporting federal security assessments and audits.
- Maintain traceability between requirements, engineering work, code, deployments, and security evidence.
- Take primary ownership of assigned technical workstreams and collaborate closely with cybersecurity and engineering team members.
Requirements
- Bachelor’s degree in computer science, Cybersecurity, or a related technical discipline.
- 6+ years of cloud security engineering experience.
- 2+ years of production experience with generative AI/LLM technologies.
- 4+ years of experience working with AWS security services.
- 3+ years of experience supporting federal compliance frameworks such as NIST, FedRAMP, and FISMA.
- 2+ years of active experience with Jira and Confluence in an Agile or technical delivery environment.
- Expert-level Python development (Python 3.11+, boto3, type hints, robust error handling).
- Advanced experience with Amazon Bedrock (agents, action groups, Knowledge Bases, guardrails, prompt engineering, RAG).
- Expert knowledge of AWS security technologies, including Security Hub, GuardDuty, Inspector, Config, IAM, CloudTrail, and OIDC.
- Advanced container security experience with ECR, ECS/EKS, image scanning, runtime monitoring, and hardening.
- Expert knowledge of NIST SP 800-53 Rev. 5, including control families, assessment procedures, and evidence requirements.
- Advanced experience with CI/CD and Infrastructure as Code, including GitLab CI and CloudFormation and/or Terraform.
- Advanced Git/version-control experience.
- Demonstrated experience managing technical work in Jira and maintaining team documentation in Confluence.
Preferred Qualifications
- Master’s degree in a related technical discipline.
- 3+ years of experience building production AI agents.
- Experience supporting ATO and continuous monitoring activities.
- Experience administering or configuring Jira boards and Confluence spaces.
- Experience supporting federal IT security programs.
- Familiarity with CISA Binding Operational Directives, including BOD 22-01 and BOD 26-04.
- Experience with AWS Security Lake, OCSF, OSCAL machine-readable compliance, or Microsoft Sentinel integration.
- Experience with AI red teaming or adversarial testing of LLM applications.
- Familiarity with software supply-chain technologies such as SLSA, Sigstore, and in-toto.
- Certifications such as AWS Certified Security – Specialty, CISSP, CISM, CKS, or AWS machine learning certification are preferred.
Work environment
This is a full-time, 100% onsite position in Suitland, MD supporting a federal government cybersecurity and enterprise IT environment. The technical environment includes AWS, Amazon Bedrock, EKS, GitLab, GitLab CI, AWS CodePipeline, Jira, Confluence, Python, VS Code, and Jupyter Notebook, along with related cloud and cybersecurity technologies.
Eligibility
- Must be a U.S. Citizen or Lawful Permanent Resident and must be eligible to obtain and maintain a Public Trust.
- Employment is contingent upon successful completion of all applicable government background investigation and customer onboarding requirements.