Haystack
← Back to Jobs
Remote
Technology
GT

AI Security Engineer Remote Role with Occassional Travel

Gtech LLCSacramento, CA🇺🇸United StatesPosted Oct 7, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
Sacramento, CA, United States
Posted
20 hours ago
AWSOWASPService MeshHIPAALLM

Job Description

Area

Requirement

The resume must show

Security engineering tenure

Required

7+ years; 3+ in HIPAA, ARC-AMPE, or FedRAMP

Assessment evidence

Required

Controls implemented and evidenced for a formal assessment

AWS security

Required

IAM, KMS, VPC, CloudTrail, GuardDuty, Security Hub; boundary design

Threat modeling

Required

Method named; outputs used by engineers

Policy as code

Required

Cedar, OPA/Rego, or IAM policies authored

LLM or agent system testing

Required

Named system; findings

OpenShift on AWS security

Required

SCCs, RBAC, network policy, OSSM mTLS, Compliance Operator, ACS or Quay, KMS and IAM integration

AppSec and LLM red teaming

Required

SAST, DAST, manual testing, prompt injection, OWASP LLM or agentic

Structural fix in an agentic system

Preferred

An injection or leak path closed

ARC-AMPE or CMS assessment

Preferred

SSP, POA&M, assessment response

Certifications

Preferred

CISSP, CCSP, OSCP, GIAC

Required qualifications
  • 7 or more years in security engineering, with at least 3 in a HIPAA, ARC-AMPE (or MARS-E), or FedRAMP environment, and control evidence produced for a formal assessment.
  • AWS security depth: IAM, KMS, Security Hub; has designed a security boundary, not only reviewed one.
  • Threat modeling as a practice (STRIDE, PASTA, or equivalent) with output engineers act on.
  • Policy as code: writing and reviewing Cedar, OPA/Rego, or IAM policies.
  • Log and evidence analysis with a SIEM or equivalent.
  • Hands-on testing of at least one system with an LLM or agent in it.
  • OpenShift on AWS security: security context constraints and RBAC, network policies, OpenShift Service Mesh mTLS, the Compliance Operator, image scanning and signing with Red Hat Advanced Cluster Security or Quay, and integration with AWS KMS and IAM.
  • Application security testing (SAST, DAST, manual), LLM red teaming, prompt injection and tool-abuse testing; OWASP LLM and agentic top ten.
Preferred qualifications
  • CISSP, CCSP, OSCP, or GIAC certification.
  • Medicaid or MMIS environment experience.

Similar jobs