Remote job
AI Security Engineer
Job details
About this role
Role overview A hands-on technical role securing AI and machine learning systems across a healthcare technology platform that helps providers and patients navigate the prescription journey. The engineer partners with data and engineering teams to assess models, data pipelines, and AI-enabled applications for vulnerabilities, then builds the guardrails and monitoring needed to keep them safe in production.
Responsibilities - Lead security assessments of AI/ML models, data pipelines, and AI-enabled applications, identifying risks such as prompt injection, model inversion, data poisoning, and adversarial inputs - Partner with data and engineering teams to embed threat modeling and security requirements into the AI development lifecycle, from data collection through deployment - Build and maintain guardrails, monitoring, and detection controls for production AI systems, flagging anomalous model behavior and unauthorized data access - Review third-party AI tools, APIs, and vendors, including LLM providers, before integration, and lead incident response for AI-related security events - Advise on standards for secure and responsible AI use, validate access controls, encryption, and data segmentation, and use AI tools to accelerate security testing while modeling responsible use
Requirements - Bachelor's degree and 5+ years in security engineering or application security, including hands-on experience securing AI/ML systems or LLM-based applications - Deep knowledge of AI/ML security risks such as the OWASP Top 10 for LLMs, adversarial ML, and data poisoning, with proven ability to test for and mitigate them - Experience with SAST/DAST, vulnerability scanning, and comfort scripting in Python or a comparable language - Understanding of cloud infrastructure such as AWS, Azure, or GCP and how AI/ML workloads are deployed and secured within it - Clear communication skills and comfort operating in a fast-paced, evolving environment
Nice to have - Experience securing systems in regulated healthcare or life sciences environments (HIPAA, HITRUST) - Familiarity with LLM security frameworks such as MITRE ATLAS, Garak, or promptfoo - Security certifications such as OSCP, GCIH, or CISSP, and red-teaming experience
Benefits and work setup - Remote-first within the US, with a one-time home office stipend and monthly Wi-Fi reimbursement, plus flexible scheduling and core collaboration hours - Competitive compensation, comprehensive medical, dental, and vision coverage with HSA/FSA contributions, 401(k) with company match, flexible PTO, 17 company holidays, paid sick and parental leave, and an annual company offsite