- Continuously monitor enterprise vulnerabilities and develop engineering solutions to improve Healthfirst infrastructure security
- Perform security architecture reviews and threat modeling for AI-enabled applications
- Conduct hands-on security testing of LLM, RAG, and agentic AI solutions
- Identify vulnerabilities such as prompt injection, sensitive-data exposure, insecure retrieval, excessive permissions, unsafe tool use, and authorization weaknesses
- Assess security risks associated with AI agents, APIs, model integrations, vector databases, and third-party AI services
- Partner with developers and AI engineering teams to design and implement practical security controls
- Develop reusable security patterns and guardrails for common AI architectures
- Build or automate security tests and tools for evaluating AI applications
- Protect PHI, PII, credentials, and other sensitive information used by AI systems
- Evaluate emerging AI security threats and translate findings into engineering guidance
- Support application security and secure AI development practices
- Ensure AI systems handling sensitive healthcare and enterprise information have appropriate security and privacy controls
- Assess sensitive-information flows through prompts, models, APIs, retrieval systems, embeddings, vector stores, logs, agents, and downstream systems
- Partner with privacy, compliance, legal, risk, and AI governance teams to translate requirements into technical controls
- Support secure and responsible AI adoption consistent with organizational policies and healthcare and regulatory requirements
- Perform additional duties as required
Requirements
- Technical Degree in Computer Science or Cyber Security and/or equivalent work experience
- Prior Cyber Security work experience
- Experience in security engineering, vulnerability assessment, threat hunting, and incident response
- High School diploma or GED from an accredited institution
- 5+ years of experience in application security, product security, security engineering, cloud security, offensive security, or a related technical security discipline (preferred)
- Strong understanding of application and API security, authentication, authorization, identity, data protection, and secure software development
- Hands-on experience with security architecture reviews, threat modeling, vulnerability assessment, penetration testing, or security testing
- Working knowledge of LLMs, model APIs, RAG, vector databases, and AI agents
- Understanding of AI security risks including prompt injection, data leakage, insecure output handling, excessive agency, and unsafe tool or API access
- Programming or scripting experience, preferably Python
- Experience working with cloud-based applications and services
- Experience securing production generative AI or LLM applications
- Experience with AI/LLM security testing or red teaming
- Familiarity with agentic AI security, MCP security considerations, OWASP LLM/GenAI guidance, MITRE ATLAS, or NIST AI security guidance
- Experience with Azure OpenAI, AWS Bedrock, Google Vertex AI, or comparable AI platforms
- Experience working with PHI, PII, or other sensitive data in a regulated environment
- Experience integrating security testing into CI/CD or DevSecOps workflows
- Experience with software supply-chain security and SBOM practices
- Experience designing secure tool and API consumption patterns for agentic AI
- Experience reviewing or implementing Infrastructure as Code and cloud/AI infrastructure security controls
- Experience with Terraform, Bicep, CloudFormation, or comparable frameworks preferred
Core Competencies
Demonstrates expertise in security engineering, vulnerability assessment, and application security, with a strong focus on AI-enabled applications and compliance with healthcare regulations. Proficient in developing security controls, conducting threat modeling, and implementing secure software development practices.
Highest-signal resume keywords
- Security Engineering
- Vulnerability Assessment
- Application Security
- AI Security Testing
- Cloud Security
Hard Skills
- Threat Modeling
- Penetration Testing
- Security Architecture Reviews
- Programming in Python
- CI/CD Integration
- Infrastructure as Code
- Data Protection
- API Security
- Security Testing
- Incident Response
Certifications & Qualifications
- Technical Degree in Computer Science
- Technical Degree in Cyber Security
Industry Keywords
- PHI
- PII
- Healthcare Regulations
- OWASP
- MITRE ATLAS
- NIST AI Security Guidance
- Sensitive Data
- Agentic AI Security
- MCP Security Considerations
- Software Supply-Chain Security
Tools & Technologies
- Azure OpenAI
- AWS Bedrock
- Google Vertex AI
- Terraform
- Bicep
- CloudFormation
- DevSecOps
- LLM
- RAG
- Vector Databases