Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal AI Security Engineer

$123.3k - $221.95k

Excellus BlueCross BlueShield Inc

Excited to grow your career?We value our talented employees, and strive to help employees grow professionally. If you think the open position you see is right for you, we encourage you to apply!

Job Description:

Summary:

The Principal Artificial Intelligence (AI) Security Engineer serves as the technical lead for securing machine learning (ML), generative artificial intelligence (GenAI), and agentic systems in production, with emphasis on healthcare and other regulated environments. This role creates security architecture, threat modeling, control design, and detection strategy across the AI lifecycle, including data ingestion, feature engineering, training and fine-tuning, evaluation, model serving, retrieval-augmented generation (RAG) pipelines, agent frameworks, application programming interface (API) mediation, and post-deployment monitoring. The Principal AI Security Engineer leads and partners throughout the organization to build enforceable guardrails for protected health information and electronic protected health information handling, identity and access control, secrets isolation, model and dataset provenance, output safety, and evidence collection for audits and investigations.

Essential Accountabilities

  • Creates reference architectures, defines security requirements and patterns for model training, inference, retrieval-augmented generation (RAG), agent orchestration, tool calling, and multi-model pipelines across cloud and hybrid environments.

  • Performs deep threat modeling for artificial intelligence (AI) systems, including prompt injection, indirect prompt injection, insecure output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, data poisoning, model theft, model inversion, supply chain compromise, and denial-of-service.

  • Defines guardrails for protected health information and electronic protected health information processing, including data minimization, de-identification, context scoping, encryption in transit and at rest, retention boundaries, and access paths into model context windows, vector stores, caches, and logs.

  • Designs and implement secure machine learning operations (MLOps) controls for datasets, features, models, prompts, and policies: provenance tracking, artifact signing, environment separation, approval workflows, reproducible builds, rollback paths, and tamper-evident audit trails.

  • Defines and sets standards for identity, service-to-service authentication, secrets management, token scoping, least privilege, just-in-time access, and network segmentation for AI services, model gateways, and external tool integrations.

  • Leads offensive security activities for AI systems, including adversarial testing, AI red teaming, prompt and tool abuse simulation, fuzzing, jailbreak testing, attack path validation, and control verification against production-like workflows and third-party model providers.

  • Leads defensive security and blue team capabilities for AI platforms, including telemetry design, prompt and response event logging, model gateway instrumentation, security information and event management/security orchestration, automation, and response (SIEM/SOAR) integration, detection engineering, exfiltration and jailbreak detections, anomalous agent action monitoring, incident triage playbooks, and continuous tuning based on observed attack patterns.

  • Leads security reviews of RAG and agentic systems, including chunking and retrieval policies, vector store isolation, embedding pipeline validation, retrieval authorization, tool allow-listing, action confirmation, and human-in-the-loop controls for high-risk operations.

  • Defines security requirements for model evaluation pipelines, benchmark data handling, canary tests, policy enforcement, and release gates so unsafe or noncompliant behavior is identified before promotion.

  • Collaborates to ensure secure, compliant handling of sensitive and regulated data across AI systems and enterprise data platforms, including enforcement of data classification, retention, access controls, auditability, and secure data readiness for approved AI use cases.

  • Collaborates on the design and implementation of AI and data governance frameworks, translating legal, regulatory, and compliance requirements into enforceable technical controls, security standards, and operational processes.

  • Coordinates the development of secure data pipelines and control implementations, ensuring proper data sourcing, minimization, de-identification, and consistent application of enterprise data protection controls (e.g., DLP, encryption, retention) within AI architectures and workflows.

  • Partner with application security, platform engineering, and data science teams to enable secure adoption of AI technologies.

  • Jointly support investigations, incident response, and regulatory inquiries involving AI systems and enterprise data, including forensic analysis, evidence preservation, defensible documentation, and production of audit-ready artifacts for legal and compliance purposes.

  • Develop and maintain integrated monitoring, detection, and response capabilities, aligning tools and processes (e.g., DSPM, eDiscovery, SIEM/SOAR, AI observability) to proactively identify and mitigate data leakage, insider risk, AI misuse, and anomalous system or user behavior.

  • Consistently demonstrates high standards of integrity by supporting the Lifetime Healthcare Companies’ mission and values, adhering to the Corporate Code of Conduct, and leading to the Lifetime Way values and beliefs.

  • Maintains high regard for member privacy in accordance with the corporate privacy policies and procedures.

  • Regular and reliable attendance is expected and required.

  • Performs other functions as assigned by management.

Minimum Qualifications

  • Ten (10) years of hands-on security engineering experience spanning application security, cloud security, security architecture, detection and response, platform security, or infrastructure security.

  • Bachelor's degree in computer science, information technology, or relevant field. In lieu of degree, six (6) cumulative years of related experience required.

  • Demonstrated experience securing production AI/ML systems, including large language model (LLM) applications, model serving stacks, retrieval-augmented generation architecture, or agent frameworks.

  • CISA, CISM, CCSP, HCISPP, GIAC and or CISSP certifications preferred.

  • Demonstrated advanced expertise in AI threat modeling and adversarial testing, including prompt injections, jailbreaks, insecure tool use, data and model poisoning, vector store abuse, model extraction, and sensitive data disclosure.

  • Strong implementation knowledge of secure software development lifecycle (SDLC), continuous integration/continuous delivery (CI/CD) security, infrastructure as code (IaC), container and Kubernetes security, application programming interface (API) security, identity and access management (IAM), secrets management, key management service/hardware security module (KMS/HSM) integration, and cloud-native telemetry pipelines.

  • Experience designing or reviewing controls for secure machine learning operations (MLOps): artifact provenance, signed builds, feature and dataset integrity, model registry controls, environment promotion, reproducibility, and rollback.

  • Experience instrumenting detections and response workflows using logs, traces, metrics, security information and event management/security orchestration, automation, and response (SIEM/SOAR) pipelines, alert tuning, and incident handling for distributed systems or AI services.

  • Advanced working knowledge of RAG security, embedding pipelines, retrieval authorization, policy engines, content filtering, and evaluation harnesses for safety, security, and regulated-data compliance.

  • Prior experience in healthcare, payer, provider or similarly regulated environments with PHI/ePHI safeguards preferred.

  • Advanced ability to write engineering standards, design docs, threat models, and control requirements that can be implemented and tested by platform and product teams.

  • Hands-on familiarity with model gateways, policy enforcement layers, prompt filtering, content moderation, retrieval authorization, vector databases, and AI observability tooling.

  • Working knowledge of static/dynamic application security testing, infrastructure as code (IaC) scanning, container image scanning, software bill of materials generation, artifact signing, secret scanning, and dependency-risk management as applied to AI delivery pipelines.

  • Experience with AI red teaming platforms, safety and abuse evaluation harnesses, benchmark design, and automated release gates for model or prompt changes.

  • Familiarity with Sarbanes Oxley, HIPAA, OCR, AI RFM, HCFA, PCI/DSS, NIST and other regulations impacting security (with ISO17799 and NIST security standards) is preferred, as well as COBIT and COSO familiarity.

Physical Requirements:

  • Ability to work prolonged periods sitting and/or standing at a workstation and working on a computer.

  • Ability to travel across the Health Plan service region for meetings and/or trainings as needed.

  • Ability to work in a home office for continuous periods of time for business continuity.

In support of the Americans with Disabilities Act, this job description lists only those responsibilities and qualifications deemed essential to the position.

Equal Opportunity Employer

Compensation Range(s):

Minimum: $123,304 - Maximum: $221,948

The salary range indicated in this posting represents the minimum and maximum of the salary range for this position. Actual salary will vary depending on factors including, but not limited to, budget available, prior experience, knowledge, skill and education as they relate to the position’s minimum qualifications, in addition to internal equity. The posted salary range reflects just one component of our total rewards package. Other components of the total rewards package may include participation in group health and/or dental insurance, retirement plan, wellness program, paid time away from work, and paid holidays.

With about 4,000 employees, 31 counties, and serving the needs of over 1.5 million members, you can imagine the gamut of skills it takes to keep our organization growing and our members flourishing. As an internal job seeker, this means growth and development in many directions, divisions, and roles.Take a look at information regarding our hiring process here. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Principal AI Security Engineer in Rochester, NY vacancy
  • $123.3k - $221.95k

     ...Principal Artificial Intelligence (AI) Security Engineer The Principal Artificial Intelligence (AI) Security Engineer serves as the technical lead for securing machine learning (ML), generative artificial intelligence (GenAI), and agentic systems in production, with... 
    Principal
    Work from home
    Home office

    Univera Healthcare

    Rochester, NY
    2 days ago
  • $135k - $225k

     ...The Role in Your Life at MKS: As a Sr. Principal Security Engineer at MKS Inc., you will be a partner with all Engineering Teams, Operations Teams, Business Units, Field Services, and Vendors as required to perform engineering design and implementation of the company... 
    Principal
    Permanent employment
    Work experience placement
    Work at office
    Remote work
    Relocation package

    MKS Instruments

    Rochester, NY
    1 day ago
  • $100k - $172.5k

     ...more at Job Function: Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture Job...  ...Description: We are searching for the best talent for a Principal Product Security Engineer to be located in Danvers, MA or Raritan, NJ. Remote... 
    Principal
    Full time
    Temporary work
    Work at office
    Local area
    Immediate start
    Remote work
    3 days per week

    Johnson & Johnson

    Rochester, NY
    1 day ago
  • $95k - $127k

    A leading technology firm seeks a Senior Conversational AI Engineer to design and implement conversational experiences on Dialogflow CX...  ...Platform. The role involves building robust flows, implementing secure integrations, and tuning NLU. Candidates should have 4-7+... 
    Suggested
    Remote work

    ChatGPT Jobs

    Rochester, NY
    19 hours ago
  • $95k - $127k

     ...Job Description SR Conversational AI Engineer (GCP+DialogFlow CX+Python) - (Remote, US) About The Role We're looking for a hands...  ...CX and the Google Cloud Platform. You will build robust flows, secure integrations, product feature enhancements, and telemetry that... 
    Suggested
    Remote work
    Flexible hours

    ChatGPT Jobs

    Rochester, NY
    19 hours ago
  •  ...AI Engineer This position is available for US based applicants only. Rochester, New York Contract-9 to 12 months with possible conversion Hybrid Overview The AI Engineer will play a crucial role in developing and implementing artificial intelligence solutions... 
    Contract work
    Work visa

    Damco

    Rochester, NY
    2 hours ago
  • $190.4k - $238k

     ...strategy. Ideal candidates will bring over 7 years of experience, a Bachelor's Degree in a relevant field, and the capability to leverage AI tools. Competitive salary with a pay range of $190,400–$238,000 per year, health coverage, and other benefits are included. #J-18808-... 

    Cohesity

    Rochester, NY
    3 days ago
  • $125.1k - $216.89k

     ...Description: The Lockheed Martin Data & AI Enablement – Advanced Solutions team supporting Rotary & Mission Systems (RMS) is responsible...  ...that drive tangible business improvements. A Senior AI/ML Engineer will be a hands‑on practitioner tasked with conducting... 
    Full time
    Temporary work
    Work experience placement
    Work at office
    Remote work
    Relocation
    Flexible hours
    Shift work
    3 days per week

    Lockheed Martin Corporation

    Rochester, NY
    3 days ago
  • $73.5k - $212.28k

     ...At PwC, our people in data and analytics engineering focus on leveraging advanced technologies...  ...will lead the development of innovative AI solutions that drive remarkable client...  ...while managing client service accounts, securing the delivery of quality results that meet... 
    Full time
    H1b

    PwC

    Rochester, NY
    4 days ago
  • $55k - $151.47k

     ...At PwC, our people in data and analytics engineering focus on leveraging advanced technologies...  ...Opportunity As part of the People Tech & AI team you will develop, test, and validate...  ...factors thoughtfully to establish a secure and trusted workplace for all. Applications... 
    Full time
    Work experience placement
    H1b
    Remote work

    PwC

    Rochester, NY
    3 days ago
  • $84.2k - $145.94k

     ...healthy, fulfilling life at and outside of work. This is a place for engineers, scientists, and problem-solvers who are ready to engage deeply,...  ...This is where the best are built. The Lockheed Martin Data & AI Enablement – Advanced Solutions team supporting Rotary & Mission... 
    Full time
    Temporary work
    Work experience placement
    Work at office
    Remote work
    Relocation
    Flexible hours
    Shift work
    3 days per week

    Lockheed Martin Corporation

    Rochester, NY
    3 days ago
  • $150k - $180k

     ...Principal Software Engineer / Remote (Polyglot Needed)1 day ago Be among the first 25 applicants Base...  ...Microservice builds Distributed Systems & AI Solutions Complete product builds...  ...and implement robust, scalable, and secure DevOps solutions that drive efficiency... 
    Principal
    Local area
    Remote work

    Jobot

    Rochester, NY
    3 days ago
  • $105.8k - $174.8k

     ...wherever you want it to go.  Join EY and help to build a better working world. Technology – Data and Decision Science – AI Native Engineering Physical AI Engineering Consultant, Senior Consultant The opportunity Our Artificial Intelligence and Data team helps... 
    Full time
    Work experience placement
    Summer holiday
    Flexible hours

    EY

    Rochester, NY
    19 hours ago
  • $90k - $175k

     ...Lead AI/ML Engineer Rochester, NY | Laboratory for Laser Energetics (LLE), University of Rochester The Laboratory for Laser Energetics is seeking a highly skilled and collaborative Lead AI/ML Engineer to help build the next generation of AI-driven scientific systems... 

    University of Rochester

    Rochester, NY
    3 hours ago
  • $86.5k - $142.7k

     ...who designs, prototypes and builds modern, AI‑enabled applications and digital products...  ...building proofs‑of‑concept, and guiding engineering teams through complex technical decisions...  ...while enforcing clean architecture, security and maintainability. • Review AI‑generated... 
    Summer holiday
    Flexible hours

    EY

    Rochester, NY
    3 days ago
  • $124k - $280k

     ...Specialty/Competency: Data, Analytics & AI Industry/Sector: Health Services Time...  ...At PwC, our people in data and analytics engineering focus on leveraging advanced technologies...  ...factors thoughtfully to establish a secure and trusted workplace for all. Applications... 
    Full time
    H1b

    PwC

    Rochester, NY
    4 days ago
  •  ...Solutions is a Premier Tier AWS Partner delivering cloud and Generative AI solutions for SMB, startup, and enterprise customers. Our GenAI...  ..., and technology. Role Overview We’re looking for a GenAI Engineer to join our Professional Services team, building and deploying... 
    Remote job
    Full time

    Innovative Solutions

    Rochester, NY
    19 hours ago
  • 37.5 hours per week, 12 months per year. Includes benefits and NYS retirement. Job Qualifications Must be on the current Office Clerk II certification of eligibles, be eligible for a transfer or be eligible to take the Office Clerk II exam. Civil Service Title:...
    Principal
    Work at office

    Brighton Central Schools

    Rochester, NY
    4 days ago
  • $124k - $280k

     ...Specialty/Competency: Data, Analytics & AI Industry/Sector: Health Services Time...  ...At PwC, our people in data and analytics engineering focus on leveraging advanced technologies...  ...factors thoughtfully to establish a secure and trusted workplace for all. Applications... 
    Full time
    H1b

    PwC

    Rochester, NY
    1 day ago
  • $106.9k - $176.5k

     ...wherever you want it to go.  Join EY and help to build a better working world. Technology – Data and Decision Science – AI Native Engineering AI/Machine Learning Engineer, Senior Consultant The opportunity Our Artificial Intelligence and Data team helps... 
    Full time
    Work experience placement
    Summer holiday
    Flexible hours

    EY

    Rochester, NY
    3 days ago
  • $156.4k - $301k

     ...infrastructure development services for a large or very complex AI/ML project, using strong technical capabilities and outstanding...  ...Develops strong working relationships across Development, Engineering and Architecture teams Provides leadership ensuring expectations... 
    Summer holiday
    Local area
    Flexible hours

    EY

    Rochester, NY
    4 days ago
  • $155.66k - $225.16k

     ...with one place to chat, explore and build with a wide variety of AI language models (bots), including o3, o4-mini, Claude 3.7 Sonnet...  ...the Team and Role: We’re hiring our first AI Automation Engineer to lead how we apply AI internally across the company. This is... 
    Remote job
    Full time
    Shift work

    Quora

    Rochester, NY
    2 days ago
  • $137k - $254k

     ...Principal Azure Solutions Architect Expert L3Harris is dedicated to recruiting and developing high-performing talent who are passionate...  ...air, land, sea and cyber domains in the interest of national security. Job Location: Melbourne, FL; Rochester, NY; Salt Lake City... 
    Principal
    Temporary work
    Local area
    Flexible hours

    L3Harris Technologies

    Rochester, NY
    19 hours ago
  • 37.5 hours per week, 12 months per year. Includes benefits, vacation and NYS retirement. Job Qualifications Must be on the current Office Clerk III certification of eligibles, be eligible for a transfer or meet minimum requirements of : Graduation from high school...
    Principal
    Full time
    Part time
    Work at office

    Brighton Central Schools

    Rochester, NY
    1 day ago
  • $92.5k - $171.5k

     ...Information Security Systems Engineer L3Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do. Our employees are unified in a shared dedication to our customers' mission and quest for professional growth. L3Harris... 
    Local area
    Remote work
    Flexible hours

    L3Harris Technologies

    Rochester, NY
    2 days ago
  • $80k - $140k

     ...Audit Manager / Senior Audit Manager / Audit Principal Location: Syracuse or Rochester, NY | Hybrid Work Option Available Department: Audit Type: Full-Time FustCharles LLP is a premier accounting, tax, and advisory firm with over 40 years of delivering trusted services... 
    Principal
    Full time
    Summer work
    Flexible hours

    Fustcharles

    Rochester, NY
    1 day ago
  • $6,475 per month

     ...Position Type: Administration (Certified)/Assistant Principal Date Posted: 5/5/2026 Location: Regional Summer School Administration Date Available: ASAP Closing Date: 05/31/2026 Monroe 2-Orleans BOCES is an educational agency serving... 
    Principal
    Summer work
    Immediate start

    Monroe 2 Boces

    Spencerport, NY
    4 days ago
  • $80.5k - $149.5k

     ..., air, land, sea and cyber domains in the interest of national security.Job Title: Specialist, Information Security Systems EngineerJob...  ...00 countries. Job Description:The Information Security Systems Engineer will be involved in Information Assurance (IA) related architecture... 
    Local area
    Flexible hours

    L3Harris Technologies

    Gates, NY
    4 days ago
  • $80.5k - $149.5k

     ..., air, land, sea and cyber domains in the interest of national security.Job Title: Specialist, Information Security Systems EngineerJob...  ...00 countries. Job Description:The Information Security Systems Engineer will be involved in Information Assurance (IA) related architecture... 
    Local area
    Flexible hours

    L3Harris Technologies

    Irondequoit, NY
    19 hours ago
  • $115k - $130k

     ...Join Us: Advance Smart, Secure Buildings as a Security Electronics Engineer IV - Design Integrated MEP Systems That Protect People and Facilities Are you an experienced engineering professional ready to take on increasingly complex building systems? Do you enjoy... 
    Contract work
    Work at office

    CHA Consulting, Inc.

    Rochester, NY
    8 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal AI Security Engineer. Be the first to apply!