On site 4x a week | 6-Month on going contract | 80-90/hr
Day-to-day:
In this role, you’ll partner closely with engineering, platform, and AI teams to design and enforce security controls for agentic AI–driven eCommerce experiences. Day to day, you’ll define runtime authorization and identity models for users and non‑human agents, secure guest-facing flows and backend services, and ensure consistent enforcement across edge, API, service, and AI runtime layers. You’ll embed security into the SDLC, establish observability and guardrails to prevent excessive autonomy or misuse, and provide practical, hands‑on guidance to development teams building high‑impact autonomous capabilities in a cloud‑native environment.
Additional Notes to consider:
- Senior Security Architect/Engineer with broad expertise across AI, APIs, IAM, AppSec, and distributed systems.
- Ability to quickly assess complex application environments and identify appropriate security controls.
- Strong critical thinking, problem-solving, and communication skills; able to simplify complex challenges.
- Working knowledge of Agentic AI, MCP/tool security, API security, and AppSec.
- Understands code and application architecture, but not a hands‑on development role.
- Partners with vendors, GIS, and operations teams to implement solutions and create runbooks.
- Serves as a bridge between business and GIS, driving PoVs, recommendations, and delivery with minimal oversight.
- Highly autonomous, outcome-driven, and proficient with Jira and Confluence.
- eCommerce experience preferred but not required
- Automatic disqualifier: Unable to demonstrate real-world critical thinking, problem-solving approach, and measurable outcomes.
Must-haves:
- 8+ years of experience in security engineering, application security, or platform security
- Current experience with agentic AI security and compliance support
- Deep expertise in OAuth 2.0/2.1, OIDC, token-based authorization, and service principals
- Experience with Edge, API & Platform Security
- Hands-on experience securing large-scale, consumer-facing eCommerce platforms
- Strong foundation in web application security, API security, and distributed systems
- Proven DevSecOps / AppSec experience embedded in modern SDLCs
- Experience supporting high-availability, production eCommerce environments
Pluses:
- Hands-on experience with agent frameworks or agent orchestration systems
- Experience with policy-as-code, runtime enforcement, or control plane architectures
- Background in fraud, abuse prevention, or financial/transaction security
- Experience in regulated environments or organizations with strong governance controls
Security Engineer in miami at Unknown Company
This position is listed as contract and onsite.