JOBSEARCHER

Application Security Engineer

Title: Application Security Engineer – Agentic AI, Identity & eCommerce SecurityLocation: Miami, FL (Onsite 4 days/week)Engagement: Contract, 12 months (strong likelihood of extension)OverviewOur client is seeking a senior Security Engineer to support a strategic initiative embedding agentic AI into a large-scale eCommerce platform — spanning guest-facing autonomous features (search, personalization, booking) and internal agentic services (content, knowledge, analytics). This role blends agentic AI security, identity and access management, and enterprise eCommerce application security. The engineer will design and operationalize runtime guardrails, identity-aware authorization, and policy enforcement across guest-facing and internal systems.This is not a traditional AppSec role — the ideal candidate is comfortable securing non-deterministic systems, tool-calling agents, and identity-driven control planes, while applying proven web, API, and edge-security fundamentals.ResponsibilitiesDesign and implement security control planes for agentic AI systemsDefine runtime authorization boundaries for AI agents, including tool-level access control and least-privilege executionEstablish policy enforcement points governing agent behavior ahead of high-impact actionsSupport human-in-the-loop workflows for sensitive/high-risk AI-initiated actionsDesign and review identity models for guests, employees, and non-human agent/workload identitiesImplement/advise on OAuth/OIDC-based delegation and short-lived credential strategiesEnsure end-to-end attribution across user ? agent ? tool execution chainsSecure guest-facing eCommerce flows: search, personalization, cart, bookingReview backend service architectures supporting AI-driven experiencesPromote agent-safe API patterns: idempotency, preview/apply, rollback, rate limitingCollaborate on edge controls: WAFs, bot mitigation, API gatewaysEnsure consistent enforcement from edge ? API ? service ? AI runtime layersSupport secure cloud-native, containerized, and sandboxed deployments (Google, AWS, Azure)Define security telemetry and audit requirements for agentic systemsSupport detection/response for runaway agents or excessive autonomyAlign implementations with enterprise security standards and governanceRequired Experience & SkillsStrong experience in security engineering, application security, or platform securityHands-on experience securing large-scale, consumer-facing eCommerce platformsStrong foundation in web application and API securityDeep understanding of OAuth 2.0/2.1, OIDC, token-based authorization, service principalsExperience designing fine-grained least-privilege access models for distributed systemsNon-Human Identity (NHI) lifecycle management in dynamic environmentsExperience with AI-enabled or automation-heavy systems; familiarity with agentic/autonomous system risksAbility to reason about non-deterministic execution and enforce deterministic controlsMCP Security Standards and agent runtime authorizationExperience with WAFs, API gateways, edge security controlsFamiliarity with cloud-native architectures and service-to-service securityStrong written/verbal communication; able to translate complex security concepts for cross-functional teams (product, platform, AI/ML, identity)DevSecOps/AppSec experience requiredNice to HaveExperience with agent frameworks or orchestration systemsFamiliarity with policy-as-code or runtime enforcement modelsBackground in fraud, abuse prevention, or financial transaction securityExperience in regulated or high-availability environments