Scroll Top
707 S Grady Way, Suite 600 Renton, WA 98057

Sr. AI Security Engineer

Seattle, Washington

Posted: 2026-08-21
Job Type: Contract

Job Description:
Location: This position requires the candidate to work onsite 2-3 days a week in Seattle, WA. Potential opening for remote candidates in PST.
Job Description:
This position will support AI workloads across our client and reduce AI risk through stronger infrastructure hygiene, in partnership with zero trust engineering.
Responsibilities
AI workload protection:
– Design, implement, and operate security controls for foundation model usage across Claude, ChatGPT, and Microsoft Copilot
– Support deployment and hardening of the enterprise AI gateway, including model allowlists, per-team keys, rate and budget limits, and centralized audit logging
– Engineer input and output guardrails covering prompt injection, sensitive data egress, credential and secret leakage, and unsafe output
– Integrate inline DLP and content inspection at the gateway so AI traffic is subject to the same data controls as other egress paths
– Establish security requirements for RAG architectures, including source grounding, index access control, and prevention of oversharing through model responses

Agentic and MCP security:
– Define and enforce governance for MCP servers and agent tooling, including registry, approval, and runtime policy enforcement
– Implement identity and authorization patterns for agents and other non-human identities: OAuth-based access, token lifecycle management, scoped tool permissions, and least privilege
– Assess and mitigate agentic risk classes including excessive agency, capability chaining, tool and memory poisoning, and unsafe autonomous action

Zero trust integration:
– Extend zero trust controls to AI workloads across identity, device, network, application, and data pillars
– Partner with identity engineering on conditional access, workload identity, and privileged access for AI systems and service principals
– Reduce AI risk through infrastructure hygiene: configuration baselines, egress control, secrets management, and dependency and supply chain integrity

Detection, testing, and assurance:
– Build monitoring and detection content for AI systems covering prompt behavior, tool invocation patterns, anomalous output, and data movement
– Conduct AI red team and adversarial testing, including direct and indirect prompt injection, jailbreak, and data extraction scenarios
– Perform shadow AI discovery and inventory of unsanctioned AI applications and browser extensions
– Conduct security reviews of AI applications, third-party AI vendors, and AI features in existing SaaS

Governance:
– Map controls to recognized frameworks including the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI Risk Management Framework
– Contribute to AI security standards, acceptable use guidance, architecture review criteria, and enablement material for engineering teams

Required Qualifications
– 7+ years in security engineering, with 2+ years securing AI, ML, or generative AI systems in production
– Hands-on experience deploying or operating an AI gateway, LLM proxy, or equivalent centralized AI control plane
– Demonstrated understanding of LLM and agent attack surface: prompt injection, data leakage through model output, insecure tool use, supply chain risk in models and dependencies
– Practical familiarity with OWASP Top 10 for LLM Applications, MITRE ATLAS, and NIST AI RMF
– Strong cloud security background, Azure preferred, including identity, network, and workload controls
– Python proficiency and comfort working with model APIs, SDKs, and evaluation tooling
– Experience partnering with engineering and data teams as an advisor rather than a gatekeeper

Preferred
– Experience with Microsoft 365 Copilot security posture, including oversharing remediation and sensitivity label enforcement
– Familiarity with AI red team tooling such as PyRIT or Garak
– Experience with MCP architecture and tool authorization patterns
– Experience with Microsoft Defender for Cloud Apps, Purview, or an equivalent DSPM platform in an AI context
– Working knowledge of ISO/IEC 42001 or the EU AI Act
– Certifications: CISSP, AZ-500, SC-100, CCSP

Pay Range: $85.00 – $95.00 per hour, depending upon experience.
Health & Medical Benefits, 401K, Employee Assistance Program, and Sick Time applicable by state.

WideNet Consultinghttps://widenet-consulting.com/https://widenet-consulting.com/wp-content/uploads/2018/02/rcs-corporation.png