Sr. Security Engineer
Listed on 2026-07-26
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Halvik Corp delivers a wide range of services to 13 executive agencies and 15 independent agencies. Halvik is a highly successful WOB business with more than 50 prime contracts and 500+ professionals delivering Digital Services, Advanced Analytics, Artificial Intelligence/Machine Learning, Cyber Security and Cutting-Edge Technology across the US Government. Be a part of something special!
Position OverviewHalvik is seeking a Senior Security Engineer to support a customer's enterprise initiative that enables secure, compliant adoption of Artificial Intelligence (AI) across their agency's hybrid environment. This role leads the design, implementation, and operationalization of enterprise-scale data discovery and classification, AI governance and protection controls, and detection capabilities for emerging AI-native development artifacts (e.g., Markdown-based prompt files, cursor rules, Git Hub Copilot instructions, and Model Context Protocol configuration files).
The Senior Security Engineer will serve as a technical lead on the program, working closely with customer stakeholders, the COR/CO, and Halvik delivery leadership to protect sensitive agency and stakeholder information while enabling the agency's AI adoption goals.
This is a Hybrid position requiring work at the customer location in Alexandria, VA.
Core Responsibilities- Strategic Execution: Lead the architecture and phased rollout of enterprise data discovery, classification, and AI governance capabilities, prioritizing high-risk repositories and expanding coverage across cloud, on-premises, SaaS, and developer environments.
- AI Governance & Enforcement: Design and tune policy-based controls (allow, block, alert, redact, route) that monitor AI prompts, responses, and related artifacts in real time or near-real-time to prevent unauthorized disclosure of sensitive information.
- Emerging AI Artifact Security: Own detection, classification, and protection of AI-native development artifacts, including Markdown prompt files, cursor rules, Copilot instructions, and MCP configuration files, across repositories, shared drives, and developer work spaces.
- Operational Oversight: Maintain auditable enforcement records, oversee remediation workflows for policy exceptions and exposure events, and ensure timely, traceable resolution of compliance findings.
- Collaboration: Partner with customer stakeholders, the COR/CO, and cross-functional Halvik teams to align implementation with the agency's cloud migration timeline, security approvals, and AI expansion roadmap.
- Technical Performance: Architect integrations with enterprise DLP/CASB platforms, SIEM, and identity/access workflows; support early, automated detection of vulnerabilities in code, containers, and infrastructure-as-code templates, including flaws introduced by AI components or data pipelines feeding AI models.
- Mentorship & Quality: Provide technical guidance and review for mid-level engineers and contribute to deliverables including the Enterprise Architecture and Deployment Plan, Discovery and Classification Configuration, and AI Governance and Enforcement Configuration.
- Continued Proficiency: Stays current with emerging AI technologies and cybersecurity trends to ensure best-in-class practices.
- Education: Bachelor's degree in Computer Science, Information Security, or a related field (Master's Degree and 8 years of experience; equivalent experience may be considered in lieu of degree, 14+ years).
- Experience: Minimum of 10 years of professional cybersecurity engineering experience, including at least 3 years focused on data loss prevention (DLP), data classification, or cloud/enterprise security architecture, ideally within a Federal environment.
- Technical Proficiency: Advanced knowledge of data discovery/classification and DLP platforms (e.g., Microsoft Purview, Symantec DLP, Varonis), cloud security in AWS/Azure/Gov Cloud, CASB, and SIEM tooling.
- Compliance: Working knowledge of NIST SP 800-53, FISMA, and the Risk Management Framework (RMF).
- Certifications: Current CISSP certification is required.
- Must be able to obtain and maintain a Public Trust security clearance.
- Demonstrated success supporting Federal contracts.
- Hands-on experience securing generative AI and LLM-enabled workflows, including prompt engineering artifacts and Model Context Protocol implementations.
- Familiarity with Agile/Scrum delivery methodologies and enterprise IT service management practices.
- Scripting and automation experience (e.g., Python, Power Shell) to support policy tuning and reporting.
- Strong analytical, written, and verbal communication skills, with the ability to translate technical risk into terms suitable for executive and government stakeholders.
- Ability to work collaboratively with others and contribute to a team environment.
- Company-supported medical, dental, vision, life, STD, and LTD insurance
- Benefits include 11 federal holidays and PTO
- Eligible employees may receive performance-based…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).