Senior AI Security Engineer

Job not on LinkedIn

🔥 7 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Highmark Health

Highmark Health

10,000+ employees

Founded 1852

🛡️ Insurance

💼 Consulting

📦 Logistics

💰 $5M Grant on 2021-05

Insurance • Consulting • Logistics

Highmark Health is a healthcare company committed to reinventing the healthcare system and improving its services for everyone. The organization offers a broad range of career opportunities across various fields such as clinical care, technology, finance, and marketing. Highmark Health emphasizes diversity, equity, and inclusion in its workforce, creating a supportive environment for employees from all backgrounds. The company has been recognized for its commitment to disability inclusion, diversity, and military-friendly employment. As an independent licensee of the Blue Cross Blue Shield Association, Highmark Health strives to create remarkable healthcare experiences for its customers and employees alike.

📋 Description

• This job secures AI/ML, Generative AI, and agentic systems across the enterprise by designing, testing, and operating controls that protect these systems at scale in a regulated healthcare environment. • They combine hands on adversarial testing, deep understanding of LLM and agent architectures, and production security expertise to prevent, detect, and contain AI driven risk involving PHI while advising engineering and security leadership on emerging AI threats and regulatory exposure. • Design, implement, and operate security controls for AI/ML, GenAI, and agentic systems — spanning model-level, data-level, and platform-level protections across Azure, GCP, AWS, and SaaS. • Engineer and enforce guardrails that mitigate prompt injection, unsafe outputs, unauthorized tool execution, data leakage, and insecure agentic workflow behavior, with explicit focus on PHI/PII exposure. • Design and execute AI red-team exercises targeting LLMs and AI agents including prompt injection (direct and indirect), jailbreaking, tool and memory poisoning, behavioral drift, unsafe autonomy, and emergent privilege escalation. • Analyze agent logic, tool graphs, and multi-step workflows to identify systemic security weaknesses beyond prompt-level attacks; translate findings into reusable attack libraries and actionable engineering fixes. • Build and maintain monitoring, logging, and alerting for AI systems covering prompt behavior, tool invocation patterns, output anomalies, and workflow execution — and implement detection content for policy-violating AI behavior. • Embed security controls into CI/CD pipelines and agentic delivery workflows; partner with AI platform, data engineering, and application teams to integrate security requirements from design through deployment gate. • Apply NIST AI RMF, MITRE ATLAS, and OWASP LLM Top 10 to assess and manage AI security risks; contribute to enterprise AI security standards, reference architectures, and governance policy; advise leadership on AI cybersecurity risk and regulatory considerations specific to healthcare AI deployment.

🎯 Requirements

• 5 years of experience in Cybersecurity engineering, application security, or platform security • 3 years of experience in AI/ML or Generative AI security (prompt injection defense, unsafe output handling, tool-use abuse, data leakage) • 5 years of experience in Securing production systems in enterprise environments (preferred) • 3 years of experience in Hybrid multi-cloud security (Azure, GCP, AWS) (preferred) • 2 years of experience in Detection engineering, monitoring, and alerting for complex application or workflow environments (preferred) • 2 years of experience in AI red-team execution (jailbreaking, behavioral drift, misuse-case validation; tools such as PyRIT, Promptfoo, AgentDojo (preferred) • 2 years of experience in Securing agentic systems, multi-step AI workflows, or tool-calling architectures (preferred) • 2 years of experience in Highly regulated industry (healthcare, financial services) with HIPAA or equivalent compliance obligations (preferred) • 1 year of experience in Identity, access management, secrets handling, and runtime policy enforcement for AI workloads (preferred) • Deep working knowledge of AI/LLM security risks: prompt injection, unsafe outputs, tool-use abuse, data leakage, identity misuse, and agentic workflow escalation • Hands-on proficiency with AI security frameworks: NIST AI RMF, MITRE ATLAS, OWASP LLM Top 10 • Cloud security fluency across Azure, GCP, and AWS, including native security tooling (Defender for Cloud, Wiz, GCP SCC) • Adversarial testing experience with AI red-team tooling (PyRIT, Promptfoo, AgentDojo, or custom harnesses) • Detection engineering — building monitoring logic, alerting pipelines, and telemetry for AI system behavior • Proficiency in Python (or equivalent) for security automation, test harness development, and pipeline integration • Secure API design, access controls, secrets management, and environment-based deployment controls for AI workloads • HIPAA data handling requirements and PHI/PII protection considerations in AI pipelines and agentic workflows • Strong written and verbal communication — capable of producing technical findings, remediation guidance, and executive security narratives • Ability to operate effectively as a senior individual contributor in a large, matrixed healthcare organization

🏖️ Benefits

• None

Apply Now

Similar Jobs

🔥 19 minutes ago

Ryder System, Inc.

10,000+ employees

🚘 Automotive

💼 Consulting

🏥 Healthcare

Corporate Security Manager responsible for security risk management across Ryder's field locations. Evaluating issues, designing systems, and improving compliance to enhance safety and reduce losses.

🔥 37 minutes ago

Bonterra

1001 - 5000

🤝 B2B

🤝 Non-profit

🌍 Social Impact

Security Engineer at Bonterra driving vulnerability remediation with AI-powered workflows. Collaborating with engineering teams to integrate security practices throughout development.

AWS

Cloud

🔥 4 hours ago

AffirmedRx, a Public Benefit Corporation

11 - 50

🏥 Healthcare

⚕️ Healthcare Insurance

Information Security Manager at AffirmedRx managing identity and access while ensuring compliance in a remote environment.

Azure

Cloud

🔥 7 hours ago

Orion Innovation

5001 - 10000

💼 Consulting

🏥 Healthcare

📦 Logistics

Senior Data Security Practitioner leading enterprise Data Security Posture Management at a global financial institution. Evaluating DSPM vendor platforms against internal requirements with client stakeholders across multiple locations.

Python

🔥 8 hours ago

Connected Logistics

51 - 200

📦 Logistics

💼 Consulting

🎖️ Defense

Cybersecurity Assessment & Authorization SME responsible for managing cybersecurity in DLA IT systems. Ensuring compliance, authorizations, and briefings of cybersecurity processes and progress to senior management.

Cyber Security