Get more replies from employers
Send a job-specific resume in minutes.
Lantern is the specialty care platform bringing high-quality care to patients and employers nationwide. We are seeking a Director of Application & AI Security to build and lead a growing security function focused on secure-by-design AI, PHI protection, and fast, safe product delivery.
The role oversees security across the software lifecycle, AI model governance, and data‑egress controls, with a plan to mature the secure-design standards and tooling used by engineering teams.
About Lantern Lantern is the specialty care platform connecting people with the best care when they need it most. By curating a Network of Excellence comprised of the nation's top specialists for surgery, cancer care, infusions and more, Lantern delivers excellent care with significant cost savings to employers and their workforces. Lantern also pairs members with a dedicated care team, including Care Advocates and nurses, for the entirety of their care journey, helping them get back to good health, back to their families and back to work. With convenient access to specialists nationwide, Lantern means quality care is within driving distance for most. Lantern is trusted by the nation's largest employers to deliver care to more than 6 million members across the country. Learn more about us at lanterncare.com.
Lantern is the specialty care platform, connecting people with high-quality, affordable specialty care close to home. We operate in a regulated healthcare environment (HIPAA, HITRUST, SOC 2), we handle protected health information at scale, and we are becoming an AI healthcare company, with AI adoption a top company priority.
The Director, Application & AI Security owns application and AI security end to end: the security of the software and the AI systems Lantern builds. It is the seat most directly tied to our AI strategy. The job is to make it safe to move fast, building the golden paths and secure defaults that let teams ship product and adopt AI without waiting in a permission queue, while keeping PHI and external-model data egress genuinely protected.
You will lead a growing function. At hire, the team includes a senior application security engineer, with several open roles to fill across security architecture, AI/ML security, DevSecOps, and product security. You will build that team and set the secure-design standards the whole engineering organization builds against.
Our security philosophy is open by default, secure by design. Security exists to help the business move fast, safely, and the default answer is "yes, safely," because guardrails are built into the platform, pipelines, and tooling rather than enforced by someone saying no. Gates exist only where risk genuinely warrants them, and even then they are automated, fast, and transparent.
Hybrid - at least 3 days/wk in our Dallas, TX office
Own application security across the development lifecycle, covering static, dynamic, and interactive analysis (SAST/DAST/SCA/IAST), code and dependency security, API security, and runtime protections such as WAF and API gateways, all delivered through engineering teams rather than filed as findings.
Own AI and ML security, including model and agent security, prompt-injection and tool-use risk, and data-egress controls for third-party model providers, plus continuous AI security posture management informed by the OWASP LLM Top 10, MITRE ATLAS, and AI risk-management standards (NIST AI RMF, ISO/IEC 42001).
Own security architecture and threat modeling, including secure-by-design review and ownership of cryptographic standards.
Own DevSecOps and pipeline security, with scanning as a default in CI/CD and MLOps/LLMOps pipelines, release gating calibrated to risk, and software supply chain and SBOM practice.
Own the security-review intake as a single front door with risk-based triage, reported against a turnaround commitment, so security accelerates the business rather than bottlenecking it.
Own the application and AI security tool stack and the secure-design standards behind it.
Much of this scope is delivered in partnership. Engineering carries remediation on application, API, and dependency findings. Platform Engineering operates the CI/CD pipelines you secure. AI Engineering builds the model integrations you govern on the security side, while the Governance, Risk & Compliance team owns AI use governance, meaning acceptable use, model inventory, and third-party model data-egress scoping, as the companion to your security accountability. Setting and holding clear service expectations across these partners is part of the role.
You use LOGIC in your decision making and understand that progress is critical to making change. You focus on the execution of your content while balancing a fast-paced environment and you take the time to celebrate both the small & big wins. INCLUSION is a core tenant of your personal beliefs. A diverse and inclusive environment is incredibly important to you. You understand and desire to be a part of a diverse team with different experiences and perspectives & you cherish the differences in each individual that you interact with. You have the GRIT , drive and ambition to tackle big problems. Big problems require big ideas and a team that supports new ideas. You care deeply for your customers are driven to keep HUMANITY in all decisions. Your customers aren’t just the individuals using your product. They are the driving factor in your motivation to make a change. Integrity guides you in life. Focusing on the TRUTH vs. giving people the answers they want to hear. You thrive in a Team Environment. Collaboration is key in innovation and creating change. These pillars of LIGHT are a reminder to our team that we are making a difference by providing guidance and support in navigating the often complex and confusing landscape of healthcare. We hope that through this LIGHT , individuals can find their way to the best care, resources, and support they need to get back to life.
Lantern does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits.