Principal Cybersecurity Architect AI

GuideWell

Northern (KY)

Hybrid

USD 140,000 - 200,000

Full time

48 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

GuideWell is seeking a Principal Cybersecurity Architect – AI & Agentic Systems to drive enterprise security strategy for AI adoption, including generative AI, retrieval-augmented systems, and MCP servers. You will provide technical leadership across business areas and project teams, ensuring secure, compliant AI deployments.

This role emphasizes PHI protection under HIPAA, design of runtime protections, AI governance, MLSecOps, and auditability.

Qualifications

  • 8+ years related work experience as an Architect working on progressively complex IT and cybersecurity projects, including enterprise-wide initiatives with significant size, scope.
  • Experience designing security architectures for AI-enabled systems and complex data flows.
  • Strong knowledge of HIPAA, privacy, security rules, and regulatory compliance in healthcare.

Responsibilities

  • Lead enterprise security strategy for AI adoption, including generative and predictive AI, retrieval-augmented systems, and MCP servers.
  • Provide technical oversight to projects, coach engineers, and drive security governance across the organization.
  • Design runtime protections, data privacy controls, and access for AI and agentic workloads.
  • Establish observability, auditability, and asset inventories for AI systems and agents.
  • Ensure compliance with HIPAA Rules and recognized frameworks (NIST, HITRUST, SOC 2).
  • Lead risk assessment, vendor security requirements, and third-party risk management for AI solutions.

Job description

The Principal Cybersecurity Architect – AI & Agentic Systems is responsible for driving enterprise-wide technology security strategy and providing technical expertise to business areas and project teams, with an emphasis on the implementation of innovative, leading-edge security technology solutions. The role carries specific accountability for the secure adoption of artificial intelligence at the enterprise: generative and predictive AI, retrieval-augmented systems, autonomous and semi-autonomous agents, and the Model Context Protocol (MCP) servers, tools, and connectors through which agents reach enterprise systems and Protected Health Information. The Principal Cybersecurity Architect – AI & Agentic Systems performs thorough enterprise-wide analysis ensuring the highest levels of confidentiality, integrity, and availability, and provides leadership and consultative guidance on projects with extensive size, scope, and risk. The role is responsible for coaching and providing technical oversight to others. It serves the company as an advisor on best practices and as an information technology strategy driver, implementing the principles, models, designs, standards, and guidelines that ensure enterprise technology is consistent, usable, secure, and adds value to the business. Because the company operates as a HIPAA covered entity and business associate, this role is accountable for ensuring that every AI system and agent touching electronic Protected Health Information satisfies the same Privacy Rule, Security Rule, and Breach Notification Rule obligations that apply to a human workforce member performing the same function — minimum necessary access enforced technically rather than by instruction, operation-level audit controls, encryption, executed Business Associate Agreements, and demonstrable risk analysis. The role is expected to make AI adoption faster and safer at the same time: the measure of success is the volume of AI capability the business is able to place into production on approved patterns, not the number of use cases blocked.

What You Will Be Doing
  • Leading project management through the steps of the venture design process. Successfully deliver projects on time and on budget.
  • Drive cross functional collaboration with key stakeholders across the organization (e.g. legal, medical, procurement, business units, project/program managers of connected efforts) at the appropriate times to drive projects through the steps of the venture design process
  • Customer and expert recruitment/scheduling and interfacing with vendors for research and co‑creation activities.
  • Ensure all Stage‑Gate preparations are complete. Manage Gate submissions for executive and steering committee review.
  • Knowledge management: organize, document, and create best practices from collected project knowledge to create best practices for the innovation team.
  • Designs the technical controls that keep Protected Health Information (PHI) inside HIPAA boundaries when AI and agents are in the data path: field‑level PHI classification ahead of agent access, minimum necessary enforcement at a centralized context‑delivery layer, chunk‑level access control in RAG retrieval, de‑identification and tokenization, prompt and output redaction at the point of input, prevention of PHI persistence in model weights, embeddings, caches, memory stores, prompt logs, and observability tooling, and tenant and workload isolation.
  • Designs runtime protection for AI and agentic workloads, including AI and MCP gateway mediation of all model and tool traffic, input and output guardrails, prompt‑injection and jailbreak defenses, tool‑call authorization and rate limiting, sandboxed and isolated code execution, egress filtering to break the data‑exfiltration path, context and memory scoping, and behavioral anomaly detection tuned to agent action patterns rather than traditional user baselines.
  • Establishes AI and agent observability and auditability sufficient to satisfy the HIPAA Security Rule audit controls standard (45 CFR §164.312(b)) at the operation level: tamper‑evident, immutable logging of which agent accessed which PHI, what action it took, under what authorization, and on whose behalf, plus retained decision traces linking every AI‑influenced output to its source data, policies, and logic.
  • Establishes and maintains the enterprise AI asset inventory and AI Bill of Materials (AIBOM) covering models, agents, prompts, datasets, embeddings, MCP servers, tools, and AI‑enabled vendor features. Partners with Security Operations to detect and govern shadow AI and unapproved AI usage across the enterprise and the software development lifecycle.
  • Leads governance processes for intake, review, and lifecycle management of new AI and non‑AI technologies and solutions. Serves as the senior security voice on the enterprise AI governance body, setting risk‑tiering criteria, pre‑deployment assessment requirements, conditions of approval, monitoring obligations, and decommissioning standards.
  • Embeds security into the AI and agentic development lifecycle (MLSecOps / AI SDC). Partners with data science, MLOps, platform, and DevOps teams to shift controls left into CI/CD — model and dependency scanning, secrets detection, prompt and configuration review, evaluation gates, policy‑as‑code enforcement, and continuous posture assessment and remediation workflows.
  • Owns the security architecture requirements for AI‑related third‑party and supply‑chain risk. Defines pre‑contract security requirements for AI vendors and models, ensures Business Associate Agreements and security addenda are in place before PHI reaches any AI service, evaluates AI frameworks, agents, vector databases, and AI platforms for enterprise readiness, and influences vendor roadmaps and future product releases.
  • Ensures AI and agentic architectures are demonstrably aligned to applicable regulation and recognized frameworks, including the HIPAA Privacy, Security, and Breach Notification Rules and anticipated Security Rule amendments, HITECH, the NIST AI Risk Management Framework and generative AI profile, NIST Cybersecurity Framework, HITRUST, SOC 2, state AI and health‑data statutes, and CMS and payer program requirements. Produces the architecture evidence auditors and regulators request.
  • Serves as security architecture subject matter expert to business areas, project teams, client groups, and vendors — with emphasis on AI‑enabled workflows such as utilization and prior authorization, claims and payment integrity, care management, member and provider service, appeals and grievances, coding, and enterprise productivity copilots. Leads efforts to examine technology vision, opportunities, and challenges.
  • Builds consensus around the principles of security architecture, including the principles of least privilege and least agency for autonomous systems, and interprets and clarifies these principles for technical and business audiences.
  • Participates in the evaluation, selection, and implementation of technology solutions, including AI security tooling such as AI and MCP gateways, AI security posture management, data security posture management, model and agent scanning, guardrail engines, and AI red‑team platforms. Provides detailed pros‑and‑cons and build‑versus‑buy analysis and total cost of ownership assessment.
  • Maintains operational, architectural, and design documentation including procedures, task lists, architecture blueprints, agent and data‑flow diagrams, control mappings, and reusable design components and patterns that can be reused between projects.
  • Establishes and leads an AI red‑teaming and adversarial evaluation program. Defines the enterprise methodology for AI security assessment across applications, agents, tools, and multi‑step workflows; commissions and oversees internal and third‑party engagements explicitly covering agentic and MCP attack patterns, not solely model‑level testing; and drives remediation of findings to closure.
  • Investigates and reports on security threats and incidents involving AI and agentic systems. Develops and maintains AI‑specific incident response playbooks addressing prompt‑injection compromise, agent credential abuse, rogue and drifted agent behavior, poisoned memory or tooling, and PHI exposure through prompts, logs, or non‑BAA services, including breach‑assessment triggers. Conducts post‑event reviews and drives corrective action. (5%)
  • Provides technical leadership, coaching, and oversight to less experienced Cybersecurity Architects and to engineering and data science partners, promoting knowledge‑sharing and professional growth. Continually enhances own breadth and depth of knowledge, benchmarks technology strategies and architectures against peer payers and industry, monitors and anticipates trends, and prepares benchmarking reports and presentations for leadership.
What We Require
  • 8+ years related work experience as an Architect working on progressively complex IT and cybersecurity projects, including enterprise-wide initiatives with significant size, scope

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Cybersecurity Architect AI
Principal Cybersecurity Architect AI

Florida Blue Group • United States

On-site
USD 180,000 - 240,000
Principal Cybersecurity Architect AI
Principal Cybersecurity Architect AI

WEB-TPA, Inc. • United States

On-site
USD 180,000 - 260,000
Security Architect
Security Architect

Maganti IT Resources, LLC • Dallas (TX)

On-site
USD 180,000 - 260,000
Care Innovation - Senior Solution Architect 136-2001
Care Innovation - Senior Solution Architect 136-2001

CommunityCare, Inc. • Tulsa (OK)

Hybrid
USD 150,000 - 190,000
AI Security Architect
AI Security Architect

TechDigital Group • Bolingbrook (IL)

On-site
USD 160,000 - 230,000
Principal AI Security Architect for Enterprise PHI & HIPAA
Principal AI Security Architect for Enterprise PHI & HIPAA

WEB-TPA, Inc. • United States

On-site
USD 180,000 - 260,000
Cybersecurity Technology Architect
Cybersecurity Technology Architect

Spectraforce • Oakland (CA)

On-site
USD 140,000 - 180,000
Principal Agentic AI Architect
Principal Agentic AI Architect

Ppl-Corporation • Allentown

On-site
USD 180,000 - 260,000
Principal AI Security
Principal AI Security

Urbint • Austin (TX)

On-site
USD 180,000 - 280,000
Paid maternity & paternity leave
Paid holidays & sick time
Volunteer time off
+4
AI Security Engineer
AI Security Engineer

Coforge • United States

On-site
USD 130,000 - 160,000