Principal AI Security Engineer

SCAN Group

Long Beach (CA)

On-site

USD 125,400 - 181,419

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual bonus program
Wellness program

Job summary

SCAN Group in the United States is seeking a visionary Principal AI Security Engineer to lead the security of our AI ecosystem and act as the primary architect. You will report to the Director of Cybersecurity and own end-to-end security for enterprise AI architectures, ensuring innovation never compromises integrity.

This hands-on, player-coach role focuses on the Azure AI stack, MCP integration, and building robust guardrails, aligning with security policies and governance frameworks.

Qualifications

  • 10+ years in Cybersecurity with 3+ years in AI/ML security.
  • Proven Azure security experience with Azure OpenAI, Foundry, and Search.
  • Deep knowledge of LLM vulnerabilities and prompt injection.
  • Data security expertise for AI data workflows including vector DB security.
  • Strong AI governance knowledge and regulatory awareness (EU AI Act).

Responsibilities

  • Design secure-by-design AI architectures across lifecycle.
  • Lead security configuration for Azure OpenAI Studio, Foundry, and Search.
  • Develop and deploy security controls: prompt mitigations, rate limiting, content filtering.
  • Secure MCP integration for AI data access and interoperability.
  • Build guardrails and monitor AI security events with the SOC.

Skills

Cybersecurity
AI/ML Security
Governance

Tools

Azure OpenAI
Azure Foundry
Azure AI Search
AKS
Azure Entra ID

Job description

Founded in 1977 as the Senior Care Action Network, SCAN began with a simple but radical idea: that older adults deserve to stay healthy and independent. That belief was championed by a group of community activists we still honor today as the \"12 Angry Seniors\". Their mission continues to guide everything we do.

Today, SCAN is a nonprofit health organization serving more than 500,000 people across Arizona, California, Nevada, New Mexico, Texas, and Washington, with over $8 billion in annual revenue. With nearly five decades of experience, we have built a distinctive, values-driven platform dedicated to improving care for older adults.

Our work spans Medicare Advantage, fully integrated care models, primary care, care for the most medically and socially complex populations, and next-generation care delivery models. Across all of this, we are united by a shared commitment: combining compassion with discipline, innovation with stewardship, and growth with integrity.

At SCAN, we believe scale should strengthen-not dilute-our mission. We are building the future of care for older adults, grounded in purpose, accountability, and respect for the people and communities we serve.

The Job:

We are seeking a visionary Principal AI Security Engineer to serve as the primary architect and guardian of our Artificial Intelligence ecosystem. Reporting directly to the Director of Cybersecurity, you will be responsible for the end-to-end security of our AI architectures, ensuring that innovation never comes at the expense of integrity.

This is a high-impact, \"player-coach\" role. You will provide strategic governance and framework development while remaining deeply hands-on with enterprise AI configurations, specifically within the Azure AI stack. From securing Model Context Protocol (MCP) implementations to building robust guardrails in Azure AI Foundry, you will be the technical authority ensuring our AI identities and data workflows are impenetrable.

Key Responsibilities:
1. AI Security Architecture & Engineering
  • End-to-End Security: Design and implement secure-by-design architectures for the entire AI lifecycle, including data ingestion, model training, fine-tuning, and inference.
  • Azure AI Specialist: Lead the security configuration for Azure OpenAI Studio, Azure AI Foundry, and Azure AI Search, ensuring enterprise-grade protection.
  • Hands-on Implementation: Develop and deploy security controls, including prompt injection mitigations, rate limiting, and content filtering.
  • MCP Integration: Securely implement and oversee Model Context Protocol (MCP) to facilitate safe communication between AI models and local/remote data sources.
2. Governance & Compliance
  • Framework Ownership: Establish and maintain AI security standards based on global frameworks (e.g., NIST AI RMF, ISO/IEC 42001, OWASP Top 10 for LLMs).
  • Policy Development: Draft enterprise-wide policies for responsible AI usage, data privacy, and model risk management.
  • Identity & Data Security: Architect sophisticated identity management for AI agents (Workload Identities) and ensure data-at-rest/motion is encrypted and permissioned via Azure RBAC and Entra ID.
3. Guardrails & Monitoring
  • Control Building: Build automated guardrails to prevent data leakage and ensure model outputs remain within ethical and legal boundaries.
  • Threat Modeling: Conduct AI-specific threat modeling and red-teaming exercises to identify vulnerabilities in RAG (Retrieval-Augmented Generation) patterns.
  • Observability: Partner with the SOC to develop monitoring dashboards for AI-related anomalies and security events.
Required Qualifications:
  • Experience: 10+ years in Cybersecurity, with at least 3+ years focused specifically on AI/ML Security.
  • Azure Expertise: Proven track record securing Azure OpenAI, Azure AI Search, and Azure Foundry.
  • Technical Depth: Deep understanding of LLM vulnerabilities (Prompt Injection, Insecure Output Handling, Training Data Poisoning).
  • Data Security: Expertise in securing data workflows for AI, including vector database security and sensitive data masking.
  • Governance: Extensive knowledge of AI Governance frameworks and the regulatory landscape (EU AI Act, etc.).
Technical Skills & Tools:
  • Platforms: Azure AI Studio, Azure Machine Learning, Azure Kubernetes Service (AKS).
  • AI Protocols: Experience with Model Context Protocol (MCP) and API security (REST, gRPC).
  • Languages: Proficiency in Python and PowerShell/Bash for automation and security tooling.
  • Identity: Expert-level knowledge of Azure Entra ID (formerly Azure AD) and Managed Identities for AI workloads.
What's in it for you?
  • Base salary range: $125,400 to $181,419 annually

  • An annual employee bonus program

  • Robust Wellness Program

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal AI Security Engineer
Principal AI Security Engineer

SCAN • Long Beach (CA)

On-site
USD 125,000 - 182,000
Annual bonus
Wellness program
PTO
+4
Principal AI Security Engineer
Principal AI Security Engineer

SCAN Health Plan • Long Beach (CA)

On-site
USD 125,000 - 182,000
Bonus program
Wellness program
Generous PTO & holidays
+2
Principal AI Security Architect — Azure Security Leader
Principal AI Security Architect — Azure Security Leader

SCAN • Long Beach (CA)

On-site
USD 125,000 - 182,000
Annual bonus
Wellness program
PTO
+4
Principal AI Security Engineer
Principal AI Security Engineer

GRP SCAN Group • City of Long Beach (NY)

On-site
USD 125,000 - 182,000
Wellness Program
PTO (paid time off)
11 holidays per year
+4
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Leeds Professional Resources • Chicago (IL)

On-site
USD 110,000 - 150,000
AI Security Engineer (GRC)
AI Security Engineer (GRC)

SCAN Group • United States

On-site
USD 120,000 - 180,000
AI Architect
AI Architect

LE001 Ascent Global, Inc. dba Ascent Solutions • United States

Remote
USD 170,000 - 185,000
401(k) plan
Health insurance
Accident insurance
+3
Security Architect - AI AppSec
Security Architect - AI AppSec

Sovereign Care Services LLP • Chicago (IL)

On-site
USD 110,000 - 150,000
401(k)
Employee discounts
Opportunity for advancement
+3
Senior Security AI Engineer
Senior Security AI Engineer

Imperial PFS • Kansas City (MO)

On-site
USD 130,000 - 160,000
AI Security Engineer
AI Security Engineer

Socket.dev • Maryland

Hybrid
USD 120,000 - 190,000
Remote work
Medical and dental insurance
401(k) with matching
+4