Apolis logo

Senior Security Engineer Agentic AI / Application Security

Apolis

  • Miami, FL
  • 2 days ago
  • $65–$70 Per Hour

Highlights

The ideal candidate will be comfortable securing non-deterministic AI systems, tool-calling agents, AI runtimes, and identity-driven control planes , while applying strong principles across web, API, edge, cloud, and application security. The platform includes guest-facing autonomous capabilities such as search, personalization, and booking assistance , as well as internal agentic services supporting content, knowledge, and analytics.

Numbers & Facts

LocationMiami, FL
IndustryComputer/IT Services
Salary$65–$70 Per Hour
Company Size500 to 999 employees
Websitehttps://www.apolisrises.com/

Description

  • Senior Security Engineer Agentic AI / Application Security
    Client: Royal Caribbean Cruises (Apex Systems)
    Location: Miami, FL Onsite 4 days/week
    Contract: 12+ Months
    Work Arrangement: Onsite 4 days per week
    Relocation: No relocation candidates
    Engagement: SubVending / C2C and W2 options available

    SubVending C2C Pay Rate: $70 $80/hr C2C
    W2 Candidate Pay Rate: $65 $70/hr on Apolis W2
    Candidate Submission Requirements Non-Negotiable

    Every candidate submission must include:
  • Fully vetted LinkedIn profile
  • Two professional references
  • Strong and demonstrable experience with Security Architecture / AppSec / DevSecOps
  • Experience with Agentic AI / AI security / LLM security
  • Ability to work onsite 4 days per week in Miami, FL
  • Candidate must already be local or able to independently commute to Miami no relocation candidates
  • Please do not submit candidates who are primarily software developers/coders without strong security architecture, AppSec, DevSecOps, API, infrastructure, and AI security experience.

    Position Overview
    Royal Caribbean Cruises Ltd. is seeking a Senior Security Engineer to support a strategic initiative integrating Agentic AI capabilities into a modern eCommerce platform.
    The platform includes guest-facing autonomous capabilities such as search, personalization, and booking assistance, as well as internal agentic services supporting content, knowledge, and analytics.
    This role sits at the intersection of Agentic AI Security, Identity & Access Management, Application Security, API Security, and large-scale eCommerce architecture.
    The ideal candidate will be comfortable securing non-deterministic AI systems, tool-calling agents, AI runtimes, and identity-driven control planes, while applying strong principles across web, API, edge, cloud, and application security.
    This is NOT a traditional coding or application development role. The ideal candidate should have strong security architecture knowledge and understand how security controls are implemented across complex infrastructure and application environments.
    Key Responsibilities
    Agentic AI & Control Plane Security
  • Design and implement security control planes for Agentic AI systems.
  • Define runtime authorization boundaries for AI agents, including tool-level access control and least-privilege execution.
  • Establish policy enforcement points governing agent behavior before high-impact actions.
  • Support human-in-the-loop workflows for sensitive or high-risk AI-initiated actions.
  • Understand and address security risks associated with LLMs, autonomous agents, tool calling, and non-deterministic execution.
  • Implement appropriate AI guardrails and runtime security frameworks.
  • Apply MCP security standards and agent runtime authorization principles.
  • Identity & Access Management
  • Design and review identity models for guests, employees, service accounts, and non-human/agent identities.
  • Implement or advise on OAuth 2.0/2.1, OIDC, token-based authorization, and short-lived credentials.
  • Design fine-grained, least-privilege access models for distributed systems.
  • Support Non-Human Identity (NHI) lifecycle management.
  • Ensure end-to-end attribution across user agent tool/service execution chains.
  • eCommerce & Application Security
  • Secure guest-facing eCommerce flows including search, personalization, cart, and booking.
  • Review backend service architectures supporting AI-driven experiences.
  • Apply strong web application and API security principles.
  • Promote agent-safe API patterns including idempotency, preview/apply workflows, rollback mechanisms, and rate limiting.
  • Understand how data flows through complex architectures and ensure appropriate protection throughout the data lifecycle.
  • Edge, API & Platform Security
  • Collaborate on security controls including WAFs, bot mitigation, API gateways, and edge security.
  • Ensure consistent security policy enforcement from edge API service AI runtime layers.
  • Review API Gateway configurations and security controls.
  • Support secure cloud-native, containerized, and sandboxed deployment patterns across AWS, Azure, and Google Cloud.
  • Understand service-to-service security and complex distributed architectures.
  • DevSecOps & Application Security
  • Integrate security into DevSecOps and software development processes.
  • Review Git repositories and development workflows from a security perspective.
  • Support DAST scanning, vulnerability management, security testing, and remediation.
  • Identify application, API, infrastructure, and architecture-level security vulnerabilities.
  • Partner with engineering teams to implement practical security controls without requiring hands-on application coding.
  • Observability, Logging & Governance
  • Define security telemetry and audit requirements for Agentic AI systems.
  • Review and analyze security logs and telemetry, including Splunk.
  • Support detection and response for runaway agents, excessive autonomy, unauthorized tool usage, and abnormal behavior.
  • Establish appropriate monitoring and auditability across AI and application environments.
  • Align security implementations with enterprise security standards and governance requirements.
  • Required Experience & Skills
    Core Security Experience
  • 8+ years of experience in Security Engineering, Application Security, Platform Security, or Security Architecture.
  • Strong experience securing large-scale, consumer-facing eCommerce platforms.
  • Strong understanding of Web Application Security and API Security.
  • Strong DevSecOps / AppSec experience is required.
  • Experience working with complex enterprise infrastructure and distributed architectures.
  • Strong understanding of security architecture, data flows, encryption, authentication, authorization, logging, and vulnerability management.
  • Agentic AI / AI Security
  • Hands-on experience building or securing AI/Agentic AI solutions from start to finish.
  • Strong understanding of AI/LLM security concepts.
  • Experience with AI-enabled or automation-heavy systems.
  • Understanding of security risks associated with autonomous and non-deterministic systems.
  • Experience implementing or evaluating AI guardrails and runtime controls.
  • Understanding of Agent Runtime Authorization and MCP security standards.
  • Ability to establish deterministic security controls around non-deterministic AI behavior.
  • Identity & Authorization
  • Deep understanding of:
    • OAuth 2.0/2.1
    • OIDC
    • Token-based authorization
    • Service principals
    • Short-lived credentials
    • Least-privilege access
    • Non-Human Identity (NHI)
  • Experience designing identity and authorization models for distributed systems.
  • API, Edge & Infrastructure Security
  • Strong understanding of API Gateways and API security.
  • Experience with WAF and edge security controls.
  • Understanding of enterprise infrastructure and complex application architectures.
  • Experience securing cloud-native and containerized environments.
  • Knowledge of AWS, Azure, and/or Google Cloud security architectures.
  • Security Tools & Practices
  • Experience with Git/Git repositories and secure development workflows.
  • Experience with DAST and security scanning.
  • Strong understanding of vulnerability identification, assessment, and remediation.
  • Experience with security logging and monitoring tools such as Splunk.
  • Understanding of encryption, authentication, authorization, data protection, and security telemetry.
  • Familiarity with security guardrail frameworks and policy enforcement mechanisms.
  • Nice-to-Have Skills
  • Experience with Agentic AI frameworks or orchestration platforms.
  • Experience with AI agent runtime security.
  • Experience with policy-as-code or runtime enforcement models.
  • Experience with fraud, abuse prevention, or financial transaction security.
  • Experience working in regulated, high-availability, or mission-critical environments.
  • Experience with MCP/Model Context Protocol security implementations.
  • Experience securing large-scale booking, payment, commerce, or customer-facing platforms.
  • Ideal Candidate Profile
    The ideal candidate is a senior security professional and security architect not a software developer/coder.
    Candidates should be able to:
  • Understand complex enterprise security architectures.
  • Explain what data is flowing, where it is flowing, and how it is protected.
  • Understand security from the edge through API Gateway, backend services, infrastructure, and AI runtime.
  • Evaluate authentication, authorization, encryption, logging, and access-control mechanisms.
  • Understand LLM and Agentic AI security risks.
  • Design guardrails around autonomous AI behavior.
  • Review security vulnerabilities, DAST results, Git repositories, and application architectures.
  • Work effectively with AI/ML, engineering, product, platform, identity, and security teams.
  • Translate complex security concepts into practical enterprise security controls.

Benefits

Paid Sick Days, Employee Referral Program, Employee Events, Retirement / Pension Plans

About Company

Since 1996, RJT has provided successful SAP, Oracle, and IT consulting solutions and staffing services to clients around the world. The new Apolis brings you the same personalized service fortified with a greater array of IT solutions, global expertise, and cost-management strategies.

We are a global IT consultancy that seamlessly integrates experts and leading-edge solutions into your organization so you can focus on what really matters.

Similar Jobs

See more jobs