Haystack
← Back to Jobs
Technology
SG

Senior AI Security Engineer

Saxon Global Inc.Coral Gables, FL🇺🇸United StatesPosted 4 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
On Site
Location
Coral Gables, FL, United States
Posted
19 hours ago
API GatewayAWSEncryptionOAuthSplunkAzureGitLLM

Job Description

Hello,
Greetings of the day!!
We have an excellent job opportunity with one of our clients. Please go through the below job description and if you are interested, please share your updated resume to proceed further. Thank you!
 
Position: Senior AI Security Engineer
Location: Brickell, FL - Onsite 4x a week Mon-Thurs
Duration: 12 Month Contract
Open for C2C/W2
 
Position Overview:
We are seeking a senior-level Security Engineer to support a strategic initiative integrating agentic AI capabilities into a modern eCommerce platform. This platform includes guest-facing autonomous capabilities (search, personalization, booking assistance) and internal agentic services (content, knowledge, analytics).
This role sits at the intersection of agentic AI security, identity and access management, and large-scale eCommerce application security. The engineer will help design and operationalize runtime guardrails, identity-aware authorization, and policy enforcement across both guest-facing and internal systems.
This is not a traditional application security role. The ideal candidate is comfortable securing non-deterministic systems, tool-calling agents, and identity-driven control planes, while grounding solutions in proven web, API, and edge-security principles.
 
MUST Haves:
•              All aspects of Security Architecture - What data is flowing, properly encryption, basic authentication, logs out of Splunk
•              Identity and Access management - basis authentication, where memories are stored, look at a system and ask how to get logs out of it
•              Guardrails Framework
•              Agentic AI
•              Not a coder but will need to have a software development background otherwise they would not have the ability to understand API Gateway
 
Project Details:
They don’t want a coder, they don’t want anyone to build anything – they want a security focused person who know security within the SDLC – where can they put security controls, to secure infrastructure, someone who understands complex architecture, etc.
They don’t need to code but they just need to know security as it relates to the SDLC – they don’t want to touch the code at all. They have a tool called SNEAK that checks on these things. This person needs to be security focused, and raise concerns within the security, No coder, understands Security concepts of AI, LLM understands API Gateway, entire Infra, complex architecture, git repos, dast scanning, vulnerability, Security Architecture, What data is flowing, properly encryption, basic authentication, logs out of Splunk, Guardrails Framework
 
Key Responsibilities
Agentic AI & Control Plane Security
•              Design and implement security control planes for agentic AI systems
•              Define runtime authorization boundaries for AI agents, including tool-level access control and least-privilege execution
•              Establish policy enforcement points governing agent behavior prior to high-impact actions
•              Support human-in-the-loop workflows for sensitive or high-risk AI-initiated actions
Identity & Access Management
•              Design and review identity models for guests, employees, and non-human agent/workload identities
•              Implement or advise on OAuth/OIDC-based delegation and short-lived credential strategies
•              Ensure end-to-end attribution across user → agent → tool execution chains
Ecommerce Application Security (Front & Back End)
•              Secure guest-facing eCommerce flows including search, personalization, cart, and booking
•              Review backend service architectures supporting AI-driven experiences
•              Promote agent-safe API patterns such as idempotency, preview/apply, rollback, and rate limiting
Edge, API & Platform Security - DevSecOps, AppSec experience is a must
•              Collaborate on edge security controls including WAFs, bot mitigation, and API gateways
•              Ensure consistent enforcement from edge to API to service to AI runtime layers – 
•              Support secure cloud-native, containerized, and sandboxed deployment patterns(Google, AWS, Azure)
Observability, Logging & Governance
•              Define security telemetry and audit requirements for agentic systems
•              Support detection and response for runaway agents or excessive autonomy
•              Align implementations with enterprise security standards and governance expectations
Required Experience & Skills
Core Experience
•              8+ years of experience in security engineering, application security, or platform security
•              Hands-on experience securing large-scale, consumer-facing eCommerce platforms
•              Strong foundation in web application and API security
Identity & Authorization
•              Deep understanding of OAuth 2.0/2.1, OIDC, token-based authorization, and service principals
•              Experience designing fine-grained least-privilege access models for distributed systems
•              Non-Human Identity (NHI) lifecycle management in highly dynamic environments
AI & Emerging Technology
•              Experience working with AI-enabled or automation-heavy systems
•              Familiarity with risks unique to agentic or autonomous systems
•              Ability to reason about non-deterministic execution and enforce deterministic controls
•              MCP Security Standards and agent runtime authorization
Platform & Edge Security
•              Experience with WAFs, API gateways, and edge security controls
•              Familiarity with cloud-native architectures and service-to-service security
Collaboration & Communication
•              Ability to work closely with product, platform, AI/ML, and identity teams
•              Strong written and verbal communication skills
•              Ability to translate complex security concepts into practical guidance
Nice to Have
•              Experience with agent frameworks or orchestration systems
•              Familiarity with policy-as-code or runtime enforcement models
•              Background in fraud, abuse prevention, or financial transaction security
•              Experience in regulated or high-availability environments

Prasanna | Sr. Technical Recruiter

Email:

Address:

Saxon Global, 1320 Greenway Drive,

Suite #660 Irving Texas, 75038, USA

 

  


 

 

 

Similar jobs