Sr. Security Engineer
Halvik Corp delivers a wide range of services to 13 executive agencies and 15 independent agencies. Halvik is a highly successful WOB business with more than 50 prime contracts and 500+ professionals delivering Digital Services, Advanced Analytics, Artificial Intelligence/Machine Learning, Cyber Security and Cutting-Edge Technology across the US Government.
About the role
Halvik is seeking a Senior Security Engineer to support a customer's enterprise initiative that enables secure, compliant adoption of Artificial Intelligence (AI) across their agency's hybrid environment. This role leads the design, implementation, and operationalization of enterprise-scale data discovery and classification, AI governance and protection controls, and detection capabilities for emerging AI-native development artifacts (e.g., Markdown-based prompt files, cursor rules, GitHub Copilot instructions, and Model Context Protocol configuration files). The Senior Security Engineer will serve as a technical lead on the program, working closely with customer stakeholders, the COR/CO, and Halvik delivery leadership to protect sensitive agency and stakeholder information while enabling the agency's AI adoption goals. This is a Hybrid position requiring work at the customer location in Alexandria, VA.
Responsibilities
- Lead the architecture and phased rollout of enterprise data discovery, classification, and AI governance capabilities, prioritizing high-risk repositories and expanding coverage across cloud, on-premises, SaaS, and developer environments.
- Design and tune policy-based controls (allow, block, alert, redact, route) that monitor AI prompts, responses, and related artifacts in real time or near-real-time to prevent unauthorized disclosure of sensitive information.
- Own detection, classification, and protection of AI-native development artifacts, including Markdown prompt files, cursor rules, Copilot instructions, and MCP configuration files, across repositories, shared drives, and developer workspaces.
- Maintain auditable enforcement records, oversee remediation workflows for policy exceptions and exposure events, and ensure timely, traceable resolution of compliance findings.
- Partner with customer stakeholders, the COR/CO, and cross-functional Halvik teams to align implementation with the agency's cloud migration timeline, security approvals, and AI expansion roadmap.
- Architect integrations with enterprise DLP/CASB platforms, SIEM, and identity/access workflows; support early, automated detection of vulnerabilities in code, containers, and infrastructure-as-code templates, including flaws introduced by AI components or data pipelines feeding AI models.
- Provide technical guidance and review for mid-level engineers and contribute to deliverables including the Enterprise Architecture and Deployment Plan, Discovery and Classification Configuration, and AI Governance and Enforcement Configuration.
- Stay current with emerging AI technologies and cybersecurity trends to ensure best-in-class practices.
Requirements
- Bachelor's degree in Computer Science, Information Security, or a related field (Master's Degree and 8 years of experience; equivalent experience may be considered in lieu of degree, 14+ years).
- Minimum of 10 years of professional cybersecurity engineering experience, including at least 3 years focused on data loss prevention (DLP), data classification, or cloud/enterprise security architecture, ideally within a Federal environment.
- Advanced knowledge of data discovery/classification and DLP platforms (e.g., Microsoft Purview, Symantec DLP, Varonis), cloud security in AWS/Azure/GovCloud, CASB, and SIEM tooling.
- Working knowledge of NIST SP 800-53, FISMA, and the Risk Management Framework (RMF).
- Current CISSP certification is required.
- Must be able to obtain and maintain a Public Trust security clearance.
Preferred Qualifications
- Demonstrated success supporting Federal contracts.
- Hands-on experience securing generative AI and LLM-enabled workflows, including prompt engineering artifacts and Model Context Protocol implementations.
- Familiarity with Agile/Scrum delivery methodologies and enterprise IT service management practices.
- Scripting and automation experience (e.g., Python, PowerShell) to support policy tuning and reporting.
- Strong analytical, written, and verbal communication skills, with the ability to translate technical risk into terms suitable for executive and government stakeholders.
- Ability to work collaboratively with others and contribute to a team environment.
Benefits
- Company-supported medical, dental, vision, life, STD, and LTD insurance.
- 11 federal holidays and PTO.
- Performance-based incentives for individual and/or team achievements.
- 401(k) with company matching.
- Flexible Spending Accounts for commuter, medical, and dependent care expenses.
- Tuition Assistance.
- Charitable Contribution matching.