Skip to content

Open nowPosted 9 hours ago

AI/Cybersecurity Solutions Engineer

Workable (global search)107,933 open roles

Where
Suitland, MD, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowAI/Cybersecurity Solutions EngineerWorkable (global search) · Suitland, MD, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 3 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted 9 hours ago

Workable (global search) median: 3 days open

The posting

Location: Suitland, MD Employment Type: Full-Time Work Arrangement: 100% On-Site Security Requirement: Must be U.S. Citizen or Lawful Permanent Resident eligible to obtain and maintain a Public Trust Salary Range: $130,000 - $140,000

Who We Are

RCG, Inc. is a growing federal contracting company proudly Certified™ as a Great Place to Work® for four consecutive years. We provide innovative technology and cybersecurity solutions supporting complex federal government environments.

The Opportunity

RCG is seeking an AI/Cybersecurity Solutions Engineer to support a federal Security, Architecture, and Engineering (SAE) team in Suitland, MD. This is a hands-on senior engineering role for an experienced professional who combines generative and agentic AI engineering, cloud security, cybersecurity automation, and federal compliance expertise. The selected candidate will help drive an agentic AI security platform, develop and harden automation supporting NIST 800-53 security assessments and remediation workflows, and take ownership of technical workstreams from requirements and implementation through CI/CD, deployment, and evidence generation. The ideal candidate will be equally comfortable developing Python-based AI automation, working with AWS security services and IAM, implementing secure cloud solutions, and maintaining the technical documentation and project traceability required in an auditable federal environment.

What You’ll Do

AI & Security Automation

  • Implement Amazon Bedrock agent action groups, including OpenAPI schemas and Python Lambda execution layers.
  • Develop Retrieval-Augmented Generation (RAG) pipelines using Bedrock Knowledge Bases with sources such as NIST 800-53, CIS Benchmarks, organizational System Security Plans (SSPs), and threat intelligence.
  • Engineer prompts, guardrails, and input validation to improve AI accuracy, security, and resistance to prompt-injection attacks.
  • Evaluate and evolve foundation-model strategies as AI capabilities and platform requirements mature.
  • Develop AI-assisted capabilities supporting security assessment, remediation, hardening, alert triage, and compliance workflows.

Cloud & Cybersecurity Engineering

  • Build automated NIST 800-53 control assessments and security evidence collection capabilities.
  • Develop remediation and hardening automation across AWS services, including S3, EC2, IAM, CloudTrail, ECS, and EKS.
  • Integrate live data from AWS Security Hub, GuardDuty, Inspector, and Config to support environment-aware security analysis and AI-assisted decision-making.
  • Support BOD 26-04 SLA logic, CISA KEV correlation, risk enrichment, and remediation SLA tracking.
  • Support security telemetry aggregation and integration with SIEM technologies, including Microsoft Sentinel and AWS Security Lake.

Container & Software Supply Chain Security

  • Support ECR vulnerability scanning, EKS runtime monitoring, and container configuration hardening.
  • Develop and analyze Software Bills of Materials (SBOMs) using formats such as SPDX and CycloneDX.
  • Correlate vulnerabilities with the CISA Known Exploited Vulnerabilities (KEV) catalog to support risk-based prioritization.
  • Perform dependency, provenance, and software supply-chain security checks, including detection of typosquatting and unsigned container images.

Platform Engineering & Delivery

  • Maintain GitLab CI/CD pipelines supporting linting, testing, security scanning, builds, and deployments.
  • Implement secure OIDC-based AWS authentication.
  • Develop and manage Infrastructure as Code using CloudFormation and/or Terraform with least-privilege IAM.
  • Support deployment and rollout verification across application and Kubernetes/EKS environments.
  • Maintain strong Git practices, including branching, merge requests, and clean version-control history.

Documentation, Compliance & Technical Leadership

  • Manage engineering work through Jira, maintaining accurate tickets, epics, sub-tasks, workflows, status, and handoffs.
  • Maintain Confluence documentation, including architecture guides, runbooks, decision records, and onboarding materials.
  • Produce technical design documentation, evidence packages, and other artifacts capable of supporting federal security assessments and audits.
  • Maintain traceability between requirements, engineering work, code, deployments, and security evidence.
  • Take primary ownership of assigned technical workstreams and collaborate closely with cybersecurity and engineering team members.

Requirements

What We’re Looking For

  • Bachelor’s degree in computer science, Cybersecurity, or a related technical discipline.
  • 4+ years of cloud security engineering experience.
  • 2+ years of production experience with generative AI/LLM technologies.
  • 2+ years of experience working with AWS security services.
  • 2+ years of experience supporting federal compliance frameworks such as NIST, FedRAMP, and FISMA.
  • 2+ years of active Jira and Confluence experience in an Agile or technical delivery environment.
  • Current DoD 8570-compliant certification required specifically Security +.
  • Solid experience with Python development experience, including Python 3.11+, boto3, type hints, and robust error handling.
  • Experience with Amazon Bedrock, including agents, action groups, Knowledge Bases, guardrails, prompt engineering, and RAG.
  • Knowledge of AWS security technologies, including Security Hub, GuardDuty, Inspector, Config, IAM, CloudTrail, and OIDC.
  • Container security experience with ECR, ECS/EKS, image scanning, runtime monitoring, and hardening.
  • Knowledge of NIST SP 800-53 Rev. 5, including control families, assessment procedures, and evidence requirements.
  • Experience with CI/CD and Infrastructure as Code technologies, including GitLab CI and CloudFormation and/or Terraform.
  • Git/version-control experience.
  • Demonstrated experience managing technical work in Jira and maintaining team documentation in Confluence.
  • Strong troubleshooting, analytical, and problem-solving skills.
  • Excellent written and verbal communication skills.

Preferred Qualifications

  • 3+ years of experience building production AI agents.
  • Experience supporting ATO and continuous monitoring activities.
  • Experience administering or configuring Jira boards and Confluence spaces.
  • Experience supporting federal IT security programs.
  • Familiarity with CISA Binding Operational Directives, including BOD 22-01 and BOD 26-04.
  • Experience with AWS Security Lake, OCSF, OSCAL machine-readable compliance, or Microsoft Sentinel integration.
  • Experience with AI red teaming or adversarial testing of LLM applications.
  • Familiarity with software supply-chain technologies and frameworks such as SLSA, Sigstore, and in-toto.
  • Certifications such as AWS Certified Security – Specialty, CISSP, CISM, CKS, or AWS machine learning certification are preferred.

Work Environment

This is a full-time, 100% on-site position in Suitland, MD supporting a federal government cybersecurity and enterprise IT environment. The selected candidate will work as part of a highly technical Security, Architecture, and Engineering (SAE) team supporting AI, security automation, cloud security, compliance, and related engineering initiatives. The role requires strong individual ownership as well as close collaboration with cybersecurity engineers, technical leadership, and other program personnel. The technical environment includes AWS, Amazon Bedrock, EKS, GitLab, GitLab CI, AWS CodePipeline, Jira, Confluence, Python, VS Code, Jupyter Notebook, and related cloud and cybersecurity technologies.

Please Note

Due to the requirements of this federal program, successful candidates must be a U.S. Citizen or Lawful Permanent Resident and must be eligible to obtain and maintain a Public Trust. Employment is contingent upon successful completion of all applicable government background investigation and customer onboarding requirements.

Why You’ll Love Working Here

  • Work for a company proudly Certified™ as a Great Place to Work® for four consecutive years.
  • Support mission-focused federal cybersecurity and technology initiatives.
  • Work directly with emerging generative AI and agentic AI technologies.
  • Solve complex challenges involving AI, cybersecurity, cloud security, automation, and federal compliance.
  • Work with modern AWS security, container, DevSecOps, and Infrastructure as Code technologies.
  • Opportunities for continued technical and professional development.
  • Comprehensive benefits including medical, dental, vision, paid time off, paid holidays, and a 401(k) with company match.

Equal Opportunity Employer

RCG, Inc. is an Equal Opportunity Employer. We provide equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable law.

Benefits

  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Family Leave (Maternity, Paternity)
  • Short Term & Long Term Disability
  • Training & Development
  • Wellness Resources
From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.