Sr AI Security Engineer

healthfirst

New York (NY)

On-site

USD 140,000 - 190,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

HealthFirst seeks a Sr AI Security Engineer to monitor vulnerabilities and craft security solutions for our AI-enabled healthcare infrastructure. You will apply cross‑discipline security expertise across IT and application development, with hands‑on work on LLMs, RAG, and AI agents.

Responsibilities include threat modeling, secure AI design, vulnerability assessments, and implementing guardrails. Collaboration with privacy, compliance, and governance teams is essential to meet healthcare

Qualifications

  • Technical degree in Computer Science or Cyber Security and/or equivalent work experience.
  • Experience in security engineering, vulnerability assessment, threat hunting, and incident response.
  • High School diploma or GED from an accredited institution.
  • Hands-on with AI security testing, CI/CD security, and cloud security.

Responsibilities

  • Perform security architecture reviews and threat modeling for AI-enabled applications.
  • Conduct hands-on security testing of LLM, RAG, and agentic AI solutions.
  • Identify vulnerabilities including prompt injection, data exposure, and insecure retrieval.
  • Partner with AI engineering teams to design and implement security controls.
  • Develop reusable security patterns and guardrails for AI architectures.
  • Build or automate security tests and tools for AI applications.
  • Help protect PHI, PII, credentials, and other sensitive information used by AI systems.
  • Evaluate emerging AI security threats and translate findings into engineering guidance.
  • Support secure AI development practices and regulatory requirements.

Skills

Security architecture
Threat modeling
Security testing
AI security
Python scripting
CI/CD security
Cloud security
Vulnerability assessment

Education

Technical Degree in Computer Science or Cyber Security
High School diploma or GED

Tools

Terraform
CloudFormation
Bicep

Job description

The Sr AI Security Engineer continuously monitors the vulnerability of the enterprise and develops engineering solutions to improve the security of the Healthfirst infrastructure. The Sr AI Security Engineer applies expertise across the Cyber Security discipline by demonstrating competency in IT Infrastructure and Application Development. The ideal candidate has a strong background in application, product, or cloud security combined with hands‑on knowledge of modern AI technologies such as LLMs, Retrieval‑Augmented Generation (RAG), and AI agents.

Duties and Responsibilities:
  • Perform security architecture reviews and threat modeling for AI-enabled applications.
  • Conduct hands‑on security testing of LLM, RAG, and agentic AI solutions.
  • Identify vulnerabilities including prompt injection, sensitive‑data exposure, insecure retrieval, excessive permissions, unsafe tool use, and authorization weaknesses.
  • Assess security risks associated with AI agents, APIs, model integrations, vector databases, and third‑party AI services.
  • Partner with developers and AI engineering teams to design and implement practical security controls.
  • Develop reusable security patterns and guardrails for common AI architectures.
  • Build or automate security tests and tools used to evaluate AI applications.
  • Help protect PHI, PII, credentials, and other sensitive information used by AI systems.
  • Evaluate emerging AI security threats and translate relevant findings into engineering guidance.
  • Support the organization’s broader application security and secure AI development practices.
  • Help ensure AI systems handling sensitive healthcare and enterprise information are designed with appropriate security and privacy controls.
  • Assess how PHI, PII, and other sensitive information moves through prompts, models, APIs, retrieval systems, embeddings, vector stores, logs, agents, and downstream systems.
  • Partner with privacy, compliance, legal, risk, and AI governance teams to translate requirements into practical technical controls.
  • Support secure and responsible AI adoption consistent with organizational policies and applicable healthcare and regulatory requirements.
  • Additional duties as required.
Minimum Qualifications:
  • Technical Degree in Computer Science or Cyber Security and/or equivalent work experience
  • Prior work Cyber Security work experience
  • Experience in security engineering, vulnerability assessment, threat hunting, and incident response
  • High School diploma or GED from an accredited institution
Preferred Qualifications:
  • 5+ years of experience in application security, product security, security engineering, cloud security, offensive security, or a related technical security discipline.
  • Strong understanding of application and API security, authentication, authorization, identity, data protection, and secure software development.
  • Hands‑on experience with security architecture reviews, threat modeling, vulnerability assessment, penetration testing, or security testing.
  • Working knowledge of modern AI application architectures, including LLMs, model APIs, RAG, vector databases, and AI agents.
  • Understanding of AI security risks such as prompt injection, data leakage, insecure output handling, excessive agency, and unsafe tool or API access.
  • Programming or scripting experience, preferably Python.
  • Experience working with cloud‑based applications and services.
  • Ability to communicate technical security risks and remediation recommendations effectively to engineering teams.
  • Experience securing production generative AI or LLM applications.
  • Experience with AI/LLM security testing or red teaming.
  • Familiarity with agentic AI security, including tool permissions and least‑privilege access.
  • Familiarity with Model Context Protocol (MCP) security considerations.
  • Experience with Azure OpenAI, AWS Bedrock, Google Vertex AI, or comparable AI platforms.
  • Familiarity with OWASP guidance for LLM/GenAI applications, MITRE ATLAS, or NIST AI security guidance.
  • Experience working with PHI, PII, or other sensitive data in a regulated environment.
  • Experience integrating security testing into CI/CD or DevSecOps workflows.
  • Experience with software supply‑chain security and SBOM practices, including assessing third‑party libraries, dependencies, models, prompts, and other AI application components for security risk.
  • Experience designing secure tool and API consumption patterns for agentic AI, including authentication, authorization, least privilege, trust boundaries, credential management, and control of agent actions.
  • Experience reviewing or implementing Infrastructure as Code (IaC) and applying security controls to cloud and AI infrastructure; experience with Terraform, Bicep, CloudFormation, or comparable frameworks preferred.
Compliance and Regulatory Responsibilities:
  • See Above
License/Certification:
  • See Above

WE ARE AN EQUAL OPPORTUNITY EMPLOYER. HF Management Services, LLC complies with all applicable laws and regulations. Applicants and employees are considered for positi

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. AI Security Engineer
Sr. AI Security Engineer

McCarthy Holdings, Inc. • Phoenix (AZ), Dallas (TX)

On-site
USD 120,000 - 160,000
Senior AI Security Architect
Senior AI Security Architect

Healthfirst • Layton (UT)

On-site
USD 120,000 - 194,000
AI Security Engineer (GRC)
AI Security Engineer (GRC)

SCAN Group • United States

On-site
USD 120,000 - 180,000
Enterprise Security Architect, AI Health Cloud
Enterprise Security Architect, AI Health Cloud

BrightSpring Health Services • Louisville (TN)

On-site
USD 170,000 - 250,000
Senior Security AI Engineer
Senior Security AI Engineer

Imperial PFS • Kansas City (MO)

On-site
USD 130,000 - 160,000
Enterprise Security Architect, AI Health Cloud
Enterprise Security Architect, AI Health Cloud

BrightSpring Health Services • Louisville (KY)

On-site
USD 150,000 - 230,000
Senior Security AI Engineer
Senior Security AI Engineer

Imperial Funding Corporation • Kansas City (MO)

On-site
USD 130,000 - 190,000
Medical, prescription, dental benefits
Wellness program and EAP
401(k) with company match
+1
Principal AI Security Engineer
Principal AI Security Engineer

Capitolis • Atlanta (GA)

Hybrid
USD 120,000 - 150,000
AI Security Analyst-- BHADC5698041
AI Security Analyst-- BHADC5698041

Compunnel Inc. • United States

On-site
USD 70,000 - 90,000
AI-Application Security Engineer
AI-Application Security Engineer

Stifel Financial Corp. • St. Louis (MO)

On-site
USD 90,000 - 120,000