Kryptek LLC

Agentic and AI Engineer (Remote, US)

Herndon, VA • Posted 2 days ago • $130,000 - $155,000 per year
Remote Contract General

Remote, United States Full-time employee

Reports to: Technical Lead and Solution Architect
Engagement type: Full-time salaried employee, W-2, with benefits
Term: Permanent, with an initial twelve-month program assignment
Location: Fully remote within the United States. No travel required
Status: United States citizenship required. Offer contingent on program start

ABOUT KRYPTEK

Kryptek LLC builds governed AI systems for clients operating under regulatory obligation. The work this role supports is agentic compliance monitoring at scale: pipelines that ingest public and client-furnished data, validate it against regulatory requirements using deterministic rules, detect drift over time, and assemble evidence packages a reviewer can defend months after the fact. The agentic layer drafts narratives, clusters findings to root cause, and reconciles conflicting sources. It never renders a determination. Every finding passes a recorded human review gate before it can leave the system. The platform runs on Amazon Bedrock inside AWS GovCloud (US) and is engineered to carry a federal Authority to Operate.

Kryptek also delivers managed detection and response, cloud security, and Zero Trust engineering on Microsoft Sentinel and Palo Alto Cortex XSIAM. We are a small, senior team, and the people we hire own their scope end to end rather than executing someone else's ticket queue.

YOUR CAREER

You build the agentic layer, and the defining constraint of the role is what your agents are not allowed to do. Determinations on this platform are produced only by deterministic validators. Agents draft narratives, cluster findings to root cause, reconcile cross-source conflicts, and draft remediation materials. No agent writes a determination, and the reason it cannot is a database privilege rather than a policy document. If you are looking for a role where the model gets to decide, this is not it. If you find the engineering discipline of a governed, auditable, reproducible AI system more interesting than raw capability, this is a good fit.

YOUR IMPACT

- Build agent definitions on Amazon Bedrock, executing entirely inside an AWS GovCloud (US) authorization boundary, for narrative drafting, finding classification and clustering, cross-source conflict reconciliation, and remediation drafting
- Enforce an explicit contract per agent: the inputs it may read, the tools it may call, the output schema it must satisfy, and the fields it may write
- Implement Bedrock Guardrails on input and output, allowlisted tool policies because blocklists fail open, and bounded retry with an attempt ceiling so an agent that cannot produce schema-valid output leaves the finding in a human queue instead of degrading silently
- Build the model, prompt, and rules registry: every model identifier and version, prompt template, tool policy, guardrail configuration, and validation rule under version control with an immutable content hash, author, approval record, effective dates, and requirements traceability identifier
- Pin model versions by identifier so a provider-side update cannot silently change platform behavior, and treat model deprecation as a governed change with a full-corpus evaluation against the incumbent
- Build the evaluation corpus covering conforming inputs, every named failure mode, malformed and partially valid payloads, identifier edge cases, and each supported deployment scenario, then gate every registry change on a regression run against it
- Maintain the known limitation log from the first sprint rather than assembling it at the end, covering failure modes, edge cases, rules held advisory, incomplete sources, and observation blind spots
- Implement change control with segregation between proposer and approver for any rule capable of producing a compliance-relevant signal
- Build and demonstrate rollback to a prior known-good configuration inside eight hours, as a version pointer change plus an evaluation confirmation rather than a redeployment, then rehearse it quarterly
- Write an audit record on every invocation capturing agent identity, registry version set, inputs, tool calls, outputs, and outcome, and constrain drafted narratives so they cannot introduce a fact absent from the evidence

YOUR EXPERIENCE

- 5 or more years of software engineering, including 2 or more years shipping production applications built on large language models
- Hands-on Amazon Bedrock experience, or equivalent depth on another provider with a demonstrated ability to port the pattern
- Retrieval augmented generation, structured output enforcement, and tool use or function calling in production, not in a notebook
- You have built an evaluation harness with regression gating. Prompt iteration by feel is not the same thing, and we will ask about the difference
- Guardrails, prompt injection defense, output schema validation, and allowlisted tool policy design
- Strong Python
- Prior work on a system where the model was explicitly not the decision-maker, and a human review gate was a hard requirement, is strongly preferred
- Relevant bachelor's degree, equivalent military experience, or equivalent professional experience
- United States citizenship is required. No security clearance is required for this role at present

COMPENSATION AND ENGAGEMENT TERMS

Compensation. $130,000 to $155,000 annually plus benefits, depending on depth of production large language model and evaluation engineering experience. This is a salaried W-2 position, not a contract engagement.

Benefits. Kryptek provides an employee benefits package with this position, including paid time off and federal holidays. Plan details are reviewed during the interview process.

This position is contingent on program start. Kryptek has committed to seating every open role within 30 days of go-ahead.

This is a permanent salaried position rather than a fixed-term contract. The initial assignment is the program described above; beyond it you would carry Kryptek platform and delivery work.

Your resume will be submitted to the client for approval before you begin work, so the client sees the individual performing rather than a labor category.

Fully remote within the United States. No travel is required for this role.

United States citizenship is required. No security clearance is required at present.

Kryptek delivers services and does not operate as a staffing agency. You will own a defined scope on our side of the work, not fill a seat on someone else's team.

TO APPLY

Send a resume to with "Agentic and AI Engineer" in the subject line. Include a short note on the one item in Your Experience above that you consider your strongest claim, and how you would evidence it.

Agentic and AI Engineer (Remote, US) in Herndon at Kryptek LLC

Other openings
5

Kryptek LLC currently has 5 other roles open on LocalWork in Herndon. If this particular role is not the right fit, their other openings may be.

This position is listed as contract and able to be worked remotely. It was posted 2 days ago.

See all Kryptek LLC jobs on LocalWork →

Back to Job Search