About Swingtech
Swingtech delivers innovative Information Technology and Professional Support services to a diverse range of clients across the federal and intelligence communities. With over 15 years of trusted experience as a systems integrator, we apply agile methodologies and deep industry insight to help our customers achieve greater efficiency, compliance, and cost savings. At Swingtech, we’re committed to excellence and long-term success for our clients and our team.
Position Summary
The AI Security Engineer designs, assesses, documents, and improves cybersecurity, privacy, and AI-specific security controls for DOL AI systems. The role ensures that AI-enabled applications, data pipelines, models, RAG systems, vector stores, agentic workflows, APIs, and cloud services are secured and supported by evidence required for Government authorization and production release.
Essential Duties
- Develop and implement AI security architecture, threat models, control matrices, security requirements, abuse cases, test plans, and remediation plans.
- Implement and validate security controls across AI applications, LLM integrations, data pipelines, model endpoints, RAG systems, vector stores, MCP servers, APIs, orchestration services, and CI/CD pipelines.
- Conduct AI-specific security testing, including prompt injection, jailbreaks, malicious-input attacks, retrieval manipulation, data poisoning, model extraction, model inversion, credential compromise, access-control bypass, insecure output handling, and tool-abuse scenarios.
- Apply Zero Trust, least privilege, role-based access, FIPS-validated encryption, secrets management, audit logging, secure configuration, vulnerability management, and secure software-development practices.
- Support FISMA, RMF, and ATO activities, including security categorization, system boundaries, SSPs, SAPs, SARs, POA&Ms, continuous monitoring, security assessments, risk decisions, and remediation evidence.
- Support assessment and approval of AI models, third-party AI services, cloud services, model providers, APIs, tools, and data-handling practices before their integration into DOL systems.
- Validate that approved cloud AI services satisfy applicable FedRAMP requirements and DOL authorization expectations.
- Ensure PII, CUI, prompts, retrieval context, embeddings, model outputs, logs, backups, and evaluation data are protected through approved controls.
- Support AI Incident Response Plan development and maintenance, including escalation paths, evidence preservation, reporting templates, severity classification, containment procedures, and post-incident review.
- Coordinate security incident investigation, containment, mitigation, recovery, and reporting for suspected or confirmed security events.
- Support supply-chain security, Software Bill of Materials generation, dependency scanning, secure-development attestations, vulnerability remediation, and third-party risk management.
- Collaborate with engineering teams to integrate security into development, testing, deployment, and production operations.
Required Qualifications
- Bachelor’s degree in cybersecurity, computer science, information assurance, engineering, information systems, or a related field.
- At least five years of experience in cybersecurity engineering, cloud security, application security, DevSecOps, security architecture, RMF/ATO, or comparable technical security roles.
- Experience with Federal cybersecurity frameworks, including FISMA, NIST SP 800-53, NIST SP 800-171, FIPS 199, FIPS 200, FedRAMP, and RMF/ATO.
- Experience securing cloud applications, APIs, data platforms, CI/CD pipelines, identity services, and containerized or cloud-native systems.
- Experience with vulnerability management, security logging and monitoring, incident response, security testing, and security documentation.
- Working knowledge of AI/ML security threats, including prompt injection, jailbreaking, model compromise, model extraction, data poisoning, RAG poisoning, retrieval manipulation, and AI supply-chain risks.
- Strong communication skills and ability to coordinate with engineering, privacy, governance, security, program-management, and Government stakeholders.
- Must be willing to work 3 days onsite at customer site in Washington, DC.
Preferred Qualifications
- CISSP, CCSP, CISM, Security+, AWS Security Specialty, Azure Security Engineer, GIAC, CEH, or comparable security certification.
- Experience with AI red teaming, AI threat modeling, OWASP Top 10 for LLM Applications, NIST AI RMF, CISA AI guidance, MITRE AI security frameworks, or adversarial ML testing.
- Experience with SIEM/SOAR, CSPM, secrets management, SAST/DAST, container security, SBOMs, software supply-chain assurance, and cloud security posture management.
- Experience with Federal civilian agencies, Government ATO packages, or FedRAMP environments.
Summary of Benefits
- 15 PTO days
- 11 paid holidays
- Medical Insurance with – 3 options (HSA with $600 Employer Contribution).
- Dental Insurance with no age limit orthodonture.
- Vision Insurance through EyeMed in and out of network coverage.
- Short Term and Long-Term Disability coverage with 100% premium support,
- Life insurance and AD&D with 100% premium support
- Supplemental Life Insurance
- Critical Care and Accident Insurance availability
- Pet Insurance through Nationwide
- Employee Assistance Program
- 401k with enrollment from day one. 4% deferral by company.
- $1500 Annual Training Budget
- $1500 Referral bonus
- Eligibility for annual merit and discretionary bonus
- Flexible work arrangements
Equal Opportunity Employer Minority/Female/Veterans/Disabled