AI Security Engineer- Hybrid/Green Cards- Local to DMV
Listed on 2026-10-04
-
IT/Tech
Cybersecurity, Information Security & Data Protection
- Hybrid (US Citizens/ Green Cards
- Local to DMV only)
About Swingtech
Swingtech delivers innovative Information Technology and Professional Support services to a diverse range of clients across the federal and intelligence communities. With over 15 years of trusted experience as a systems integrator, we apply agile methodologies and deep industry insight to help our customers achieve greater efficiency, compliance, and cost savings. At Swingtech, we're committed to excellence and long-term success for our clients and our team.
Position Summary
The AI Security Engineer designs, assesses, documents, and improves cybersecurity, privacy, and AI-specific security controls for DOL AI systems. The role ensures that AI-enabled applications, data pipelines, models, RAG systems, vector stores, agentic workflows, APIs, and cloud services are secured and supported by evidence required for Government authorization and production release.
- Develop and implement AI security architecture, threat models, control matrices, security requirements, abuse cases, test plans, and remediation plans.
- Implement and validate security controls across AI applications, LLM integrations, data pipelines, model endpoints, RAG systems, vector stores, MCP servers, APIs, orchestration services, and CI/CD pipelines.
- Conduct AI-specific security testing, including prompt injection, jailbreaks, malicious-input attacks, retrieval manipulation, data poisoning, model extraction, model inversion, credential compromise, access-control bypass, insecure output handling, and tool-abuse scenarios.
- Apply Zero Trust, least privilege, role-based access, FIPS-validated encryption, secrets management, audit logging, secure configuration, vulnerability management, and secure software-development practices.
- Support FISMA, RMF, and ATO activities, including security categorization, system boundaries, SSPs, SAPs, SARs, POA&Ms, continuous monitoring, security assessments, risk decisions, and remediation evidence.
- Support assessment and approval of AI models, third-party AI services, cloud services, model providers, APIs, tools, and data-handling practices before their integration into DOL systems.
- Validate that approved cloud AI services satisfy applicable FedRAMP requirements and DOL authorization expectations.
- Ensure PII, CUI, prompts, retrieval context, embeddings, model outputs, logs, backups, and evaluation data are protected through approved controls.
- Support AI Incident Response Plan development and maintenance, including escalation paths, evidence preservation, reporting templates, severity classification, containment procedures, and post-incident review.
- Coordinate security incident investigation, containment, mitigation, recovery, and reporting for suspected or confirmed security events.
- Support supply-chain security, Software Bill of Materials generation, dependency scanning, secure-development attestations, vulnerability remediation, and third-party risk management.
- Collaborate with engineering teams to integrate security into development, testing, deployment, and production operations.
Required Qualifications
- Bachelor's degree in cybersecurity, computer science, information assurance, engineering, information systems, or a related field.
- At least five years of experience in cybersecurity engineering, cloud security, application security, Dev Sec Ops , security architecture, RMF/ATO, or comparable technical security roles.
- Experience with Federal cybersecurity frameworks, including FISMA, NIST SP 800-53, NIST SP 800-171, FIPS 199, FIPS 200, FedRAMP, and RMF/ATO.
- Experience securing cloud applications, APIs, data platforms, CI/CD pipelines, identity services, and containerized or cloud-native systems.
- Experience with vulnerability management, security logging and monitoring, incident response, security testing, and security documentation.
- Working knowledge of AI/ML security threats, including prompt injection, jail breaking, model compromise, model extraction, data poisoning, RAG poisoning, retrieval manipulation, and AI supply-chain risks.
- Strong communication skills and ability to coordinate with engineering, privacy, governance, security, program-management, and Government stakeholders.
- Must be willing to work 3 days onsite at customer site in Washington, DC.
Preferred Qualifications
- CISSP, CCSP, CISM, Security+, AWS Security Specialty, Azure Security Engineer, GIAC, CEH, or comparable security certification.
- Experience with AI red teaming, AI threat modeling, OWASP…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).