Application Security Engineer
Listed on 2026-09-10
-
IT/Tech
AI Engineer (Applied/Software), Cybersecurity
Title: Application Security Engineer – Agentic AI, Identity & eCommerce Security
Location: Miami, FL (Onsite 4 days/week)
Engagement: Contract, 6–12 months (strong likelihood of extension)
Overview
Our client is seeking a senior Security Engineer to support a strategic initiative embedding agentic AI into a large-scale eCommerce platform — spanning guest-facing autonomous features (search, personalization, booking) and internal agentic services (content, knowledge, analytics). This role blends agentic AI security, identity and access management, and enterprise eCommerce application security. The engineer will design and operationalize runtime guardrails, identity-aware authorization, and policy enforcement across guest-facing and internal systems.
This is not a traditional App Sec role — the ideal candidate is comfortable securing non-deterministic systems, tool-calling agents, and identity-driven control planes, while applying proven web, API, and edge-security fundamentals.
Responsibilities
- Design and implement security control planes for agentic AI systems
- Define runtime authorization boundaries for AI agents, including tool-level access control and least-privilege execution
- Establish policy enforcement points governing agent behavior ahead of high-impact actions
- Support human-in-the-loop workflows for sensitive/high-risk AI-initiated actions
- Design and review identity models for guests, employees, and non-human agent/workload identities
- Implement/advise on OAuth/OIDC-based delegation and short-lived credential strategies
- Ensure end-to-end attribution across user ? agent ? tool execution chains
- Secure guest-facing eCommerce flows: search, personalization, cart, booking
- Review backend service architectures supporting AI-driven experiences
- Promote agent-safe API patterns: idempotency, preview/apply, rollback, rate limiting
- Collaborate on edge controls: WAFs, bot mitigation, API gateways
- Ensure consistent enforcement from edge ? API ? service ? AI runtime layers
- Support secure cloud-native, containerized, and sandboxed deployments (Google, AWS, Azure)
- Define security telemetry and audit requirements for agentic systems
- Support detection/response for runaway agents or excessive autonomy
- Align implementations with enterprise security standards and governance
Required Experience & Skills
- Strong experience in security engineering, application security, or platform security
- Hands-on experience securing large-scale, consumer-facing eCommerce platforms
- Strong foundation in web application and API security
- Deep understanding of OAuth 2.0/2.1, OIDC, token-based authorization, service principals
- Experience designing fine-grained least-privilege access models for distributed systems
- Non-Human Identity (NHI) lifecycle management in dynamic environments
- Experience with AI-enabled or automation-heavy systems; familiarity with agentic/autonomous system risks
- Ability to reason about non-deterministic execution and enforce deterministic controls
- MCP Security Standards and agent runtime authorization
- Experience with WAFs, API gateways, edge security controls
- Familiarity with cloud-native architectures and service-to-service security
- Strong written/verbal communication; able to translate complex security concepts for cross-functional teams (product, platform, AI/ML, identity)
- Dev Sec Ops /App Sec experience required
Nice to Have
- Experience with agent frameworks or orchestration systems
- Familiarity with policy-as-code or runtime enforcement models
- Background in fraud, abuse prevention, or financial transaction security
- Experience in regulated or high-availability environments
Equal Employment Opportunity Statement
Gravity IT Resources is an Equal Opportunity Employer. We are committed to creating an inclusive environment for all employees and applicants. We do not discriminate on the basis of race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, genetic information, veteran status, or any other legally protected characteristic. All employment decisions are based on qualifications, merit, and business needs.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).