Principal AI Security Engineer
$123.3k - $221.95kCapital District Physicians' Health Plan
Job Description:
Summary:
The Principal Artificial Intelligence (AI) Security Engineer serves as the technical lead for securing machine learning (ML), generative artificial intelligence (GenAI), and agentic systems in production, with emphasis on healthcare and other regulated environments. This role creates security architecture, threat modeling, control design, and detection strategy across the AI lifecycle, including data ingestion, feature engineering, training and fine-tuning, evaluation, model serving, retrieval-augmented generation (RAG) pipelines, agent frameworks, application programming interface (API) mediation, and post-deployment monitoring. The Principal AI Security Engineer leads and partners throughout the organization to build enforceable guardrails for protected health information and electronic protected health information handling, identity and access control, secrets isolation, model and dataset provenance, output safety, and evidence collection for audits and investigations.
Essential Accountabilities
- Creates reference architectures, defines security requirements and patterns for model training, inference, retrieval-augmented generation (RAG), agent orchestration, tool calling, and multi-model pipelines across cloud and hybrid environments.
- Performs deep threat modeling for artificial intelligence (AI) systems, including prompt injection, indirect prompt injection, insecure output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, data poisoning, model theft, model inversion, supply chain compromise, and denial-of-service.
- Defines guardrails for protected health information and electronic protected health information processing, including data minimization, de-identification, context scoping, encryption in transit and at rest, retention boundaries, and access paths into model context windows, vector stores, caches, and logs.
- Designs and implement secure machine learning operations (MLOps) controls for datasets, features, models, prompts, and policies: provenance tracking, artifact signing, environment separation, approval workflows, reproducible builds, rollback paths, and tamper-evident audit trails.
- Defines and sets standards for identity, service-to-service authentication, secrets management, token scoping, least privilege, just-in-time access, and network segmentation for AI services, model gateways, and external tool integrations.
- Leads offensive security activities for AI systems, including adversarial testing, AI red teaming, prompt and tool abuse simulation, fuzzing, jailbreak testing, attack path validation, and control verification against production-like workflows and third-party model providers.
- Leads defensive security and blue team capabilities for AI platforms, including telemetry design, prompt and response event logging, model gateway instrumentation, security information and event management/security orchestration, automation, and response (SIEM/SOAR) integration, detection engineering, exfiltration and jailbreak detections, anomalous agent action monitoring, incident triage playbooks, and continuous tuning based on observed attack patterns.
- Leads security reviews of RAG and agentic systems, including chunking and retrieval policies, vector store isolation, embedding pipeline validation, retrieval authorization, tool allow-listing, action confirmation, and human-in-the-loop controls for high-risk operations.
- Defines security requirements for model evaluation pipelines, benchmark data handling, canary tests, policy enforcement, and release gates so unsafe or noncompliant behavior is identified before promotion.
- Collaborates to ensure secure, compliant handling of sensitive and regulated data across AI systems and enterprise data platforms, including enforcement of data classification, retention, access controls, auditability, and secure data readiness for approved AI use cases.
- Collaborates on the design and implementation of AI and data governance frameworks, translating legal, regulatory, and compliance requirements into enforceable technical controls, security standards, and operational processes.
- Coordinates the development of secure data pipelines and control implementations, ensuring proper data sourcing, minimization, de-identification, and consistent application of enterprise data protection controls (e.g., DLP, encryption, retention) within AI architectures and workflows.
- Partner with application security, platform engineering, and data science teams to enable secure adoption of AI technologies.
- Jointly support investigations, incident response, and regulatory inquiries involving AI systems and enterprise data, including forensic analysis, evidence preservation, defensible documentation, and production of audit-ready artifacts for legal and compliance purposes.
- Develop and maintain integrated monitoring, detection, and response capabilities, aligning tools and processes (e.g., DSPM, eDiscovery, SIEM/SOAR, AI observability) to proactively identify and mitigate data leakage, insider risk, AI misuse, and anomalous system or user behavior.
- Consistently demonstrates high standards of integrity by supporting the Lifetime Healthcare Companies' mission and values, adhering to the Corporate Code of Conduct, and leading to the Lifetime Way values and beliefs.
- Maintains high regard for member privacy in accordance with the corporate privacy policies and procedures.
- Regular and reliable attendance is expected and required.
- Performs other functions as assigned by management.
Minimum Qualifications
- Ten (10) years of hands-on security engineering experience spanning application security, cloud security, security architecture, detection and response, platform security, or infrastructure security.
- Bachelor's degree in computer science, information technology, or relevant field. In lieu of degree, six (6) cumulative years of related experience required.
- Demonstrated experience securing production AI/ML systems, including large language model (LLM) applications, model serving stacks, retrieval-augmented generation architecture, or agent frameworks.
- CISA, CISM, CCSP, HCISPP, GIAC and or CISSP certifications preferred.
- Demonstrated advanced expertise in AI threat modeling and adversarial testing, including prompt injections, jailbreaks, insecure tool use, data and model poisoning, vector store abuse, model extraction, and sensitive data disclosure.
- Strong implementation knowledge of secure software development lifecycle (SDLC), continuous integration/continuous delivery (CI/CD) security, infrastructure as code (IaC), container and Kubernetes security, application programming interface (API) security, identity and access management (IAM), secrets management, key management service/hardware security module (KMS/HSM) integration, and cloud-native telemetry pipelines.
- Experience designing or reviewing controls for secure machine learning operations (MLOps): artifact provenance, signed builds, feature and dataset integrity, model registry controls, environment promotion, reproducibility, and rollback.
- Experience instrumenting detections and response workflows using logs, traces, metrics, security information and event management/security orchestration, automation, and response (SIEM/SOAR) pipelines, alert tuning, and incident handling for distributed systems or AI services.
- Advanced working knowledge of RAG security, embedding pipelines, retrieval authorization, policy engines, content filtering, and evaluation harnesses for safety, security, and regulated-data compliance.
- Prior experience in healthcare, payer, provider or similarly regulated environments with PHI/ePHI safeguards preferred.
- Advanced ability to write engineering standards, design docs, threat models, and control requirements that can be implemented and tested by platform and product teams.
- Hands-on familiarity with model gateways, policy enforcement layers, prompt filtering, content moderation, retrieval authorization, vector databases, and AI observability tooling.
- Working knowledge of static/dynamic application security testing, infrastructure as code (IaC) scanning, container image scanning, software bill of materials generation, artifact signing, secret scanning, and dependency-risk management as applied to AI delivery pipelines.
- Experience with AI red teaming platforms, safety and abuse evaluation harnesses, benchmark design, and automated release gates for model or prompt changes.
- Familiarity with Sarbanes Oxley, HIPAA, OCR, AI RFM, HCFA, PCI/DSS, NIST and other regulations impacting security (with ISO17799 and NIST security standards) is preferred, as well as COBIT and COSO familiarity.
Physical Requirements:
- Ability to work prolonged periods sitting and/or standing at a workstation and working on a computer.
- Ability to travel across the Health Plan service region for meetings and/or trainings as needed.
- Ability to work in a home office for continuous periods of time for business continuity.
***********
In support of the Americans with Disabilities Act, this job description lists only those responsibilities and qualifications deemed essential to the position.
Equal Opportunity Employer
Compensation Range(s):
Minimum: $123,304 - Maximum: $221,948
The salary range indicated in this posting represents the minimum and maximum of the salary range for this position. Actual salary will vary depending on factors including, but not limited to, budget available, prior experience, knowledge, skill and education as they relate to the position's minimum qualifications, in addition to internal equity. The posted salary range reflects just one component of our total rewards package. Other components of the total rewards package may include participation in group health and/or dental insurance, retirement plan, wellness program, paid time away from work, and paid holidays.
Please note: There may be opportunity for remote work within all jobs posted by the CDPHP Talent Acquisition team. This decision is made on a case-by-case basis.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
- ...A leading cybersecurity firm in the United States is seeking a Principal Engineer to define the technical direction for AI-powered security capabilities. This senior individual-contributor role involves setting the architecture and standards for AI in security-sensitive...PrincipalRemote work
- ...A leading cybersecurity company in the United States is seeking a Principal Engineer specialized in AI-powered security capabilities. This remote role will define technical directions and set architectural standards for security-sensitive product experiences. Candidates...PrincipalRemote work
- ...OpenAI is looking for a Principal Software Engineer to join the Infrastructure Security team. This role involves designing and implementing high-scale security systems... ...OpenAI promotes a collaborative culture focused on the benefits of AI for humanity. #J-18808-Ljbffr...Principal
- A global law firm is seeking a Principal Security Engineer to manage their information security systems and processes. The ideal candidate has over 7 years of experience in information security engineering, extensive knowledge of SIEM systems, and the ability to analyze...PrincipalRemote work
$140k - $170k
...RadNet, Inc. is looking for an AI Security Engineer in the United States who will work at the intersection of AI engineering and security. The role involves assessing AI architectures for security exposure, designing governance frameworks, and integrating security into...Suggested$178.4k - $226.7k
...Amazon is seeking a Senior Security Engineer for our AI Red Team within Threat Operations. This experienced engineer will conduct Red Team operations targeting AI systems and develop automated solutions to enhance our security capabilities. The ideal candidate will have...- ...Senior Security Engineer - AI New York, NY (Hybrid, 3 days in office) Highly competitive compensation package Join an elite technology and research group at the forefront of global finance, where world-class engineering and quantitative research converge to...Work at office
- ...Framework Ventures is looking for a Security Engineer to build AI-driven security infrastructure for LLM applications. The role involves designing multi-agent systems and integrating security methods into development pipelines. Candidates should have at least 3 years of...
$119.98k - $179.97k
...EdSurge is looking for a Software Engineer (AI Systems) to join their team remotely in the US. This full-time position involves hands-on development for AI-powered products and designing innovative systems that support their review process. Candidates should have over...PrincipalFull timeRemote work$100.63k - $167.79k
...AI Security Engineer Where Ambition Meets Innovation Build a career that matches all your initiative with an impressive dose of innovation... ...log in or create an account to apply to this position. Principals only. EOE. Information on Interviews: LPL will only...Work from home$155k - $175k
...Lumin Digital is hiring a Senior Application Security Engineer to secure its B2B2C SaaS platform. This role involves leading security architecture reviews, developing secure coding standards, and mentoring teams in secure development practices. With 7+ years of experience...Remote work$94.2k
...Company : enGen Job Description : JOB SUMMARY This job secures AI/ML, Generative AI, and agentic systems across the enterprise... ..., and contain AI driven risk involving PHI while advising engineering and security leadership on emerging AI threats and regulatory...For contractorsWork at officeLocal areaRemote work$215k - $270k
NextPath Career Partners is seeking a Principal AI Engineer: Generative & Agentic to join a client’s team in New York, NY. This is a remote, direct hire position with a salary range of $215,000 - $270,000 depending on experience. The ideal candidate will have 15+ years...PrincipalRemote job- ...Sigma Software LLC is seeking a Principal AI-Augmented Test Automation Engineer to lead and scale AI-native E2E test automation offerings. This role involves shaping engagement models and establishing scalable testing processes in AI-driven quality engineering. The successful...PrincipalRemote work
$150k - $225k
...Lumistry is seeking a Principal Software Engineer to drive technical strategy and lead development on core products for pharmacy care in the U.S. This role emphasizes building an AI-first engineering culture, involving cross-functional collaboration, scaling technical...Principal- ...proficient in Python, Go, or Java, and possess hands-on experience with deploying LLM agents. The role requires strong understanding of AI security, Docker, and Kubernetes. The position offers a competitive compensation package and various employee benefits including wellness...
$113k - $147k
Msci- is seeking a Principal AI Engineer in New York City to architect and implement advanced AI systems. You'll work with cross-functional teams to deliver enterprise-scale AI solutions that enhance decision-making in financial markets. The ideal candidate should have...PrincipalFlexible hours$40 per hour
A leading AI training company is seeking experienced cybersecurity professionals for a remote role. Candidates will evaluate AI-generated security content, solve cybersecurity problems, and provide critical feedback to enhance AI systems. The ideal applicant has over two...Hourly payRemote work$40 per hour
A leading cybersecurity firm is seeking experienced professionals to evaluate AI-generated security content and solve technical problems. This flexible position offers the freedom to choose projects, working remotely from the US or select countries. Candidates must have...Hourly payRemote workFlexible hours$40 per hour
A cybersecurity-focused AI company is seeking experienced cybersecurity professionals to evaluate AI-generated security content, solve technical problems, and enhance AI systems. Successful candidates will have hands-on experience in cybersecurity and coding skills. This...Hourly payRemote work$40 per hour
A cybersecurity AI training company is looking for experienced cybersecurity professionals to evaluate AI-generated security content and solve technical issues. You will engage directly with advanced AI models and offer feedback to improve AI security systems. The ideal...Hourly payFull timePart timeRemote workFlexible hours$40 per hour
...cybersecurity professionals to join our team to help train AI models. In this role, you will evaluate AI-generated security content, solve technical cybersecurity problems,... ..., red teaming, incident response, detection engineering, DFIR, malware analysis, threat intelligence, or...Hourly payFull timePart timeRemote work- ...A leading technology company is seeking experienced cybersecurity professionals to evaluate AI-generated security content and solve technical problems. The role offers flexibility, allowing candidates to choose their projects and work on their schedule. Ideal applicants...Full timePart timeRemote work
- ...Mercor is partnering with a leading AI lab to engage cybersecurity and low-level programming experts for a high-impact project. This role focuses on analyzing content for security vulnerabilities using expertise in low-level programming. The opportunity includes a short...Temporary workRemote work
- A cybersecurity solutions provider is seeking experienced cybersecurity professionals to evaluate AI-generated security content and solve technical problems. This role requires 2+ years of hands-on experience, some coding skills, and strong analytical abilities. Candidates...Remote workFlexible hours
$40 per hour
A cybersecurity firm is seeking experienced professionals to join their remote team. In this role, you will evaluate AI-generated security content, address cybersecurity challenges, and provide crucial feedback for advancing AI models. Ideal candidates will have over 2...Hourly payRemote work$40 per hour
...in cybersecurity is seeking experienced cybersecurity professionals for a remote position. In this role, you will evaluate AI-generated security content and solve technical problems to improve AI models. Ideal candidates will have at least 2 years of cybersecurity experience...Hourly payRemote workFlexible hours$40 per hour
A cybersecurity training company is seeking experienced cybersecurity professionals to evaluate AI-generated security content and solve technical challenges. This remote role allows you to choose your projects and work on your own schedule, paying hourly starting at $40...Hourly payRemote work$60 per hour
...A cutting-edge AI firm is seeking experienced cybersecurity professionals to evaluate AI-generated security content and design solutions for training AI systems. This fully remote role offers flexible scheduling and competitive pay up to $60/hour. Candidates should have...Remote workFlexible hours- Intuit Inc. is looking for a Principal Software Engineer in New York to drive technology initiatives and build AI-native applications. You will collaborate with cross-functional teams to deliver end-to-end solutions, leveraging extensive experience in software development...Principal
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal AI Security Engineer. Be the first to apply!
- chief engineer New York State
- principal developer New York State
- general engineer New York State
- data center chief engineer New York State
- hotel chief engineer New York State
- engineering director New York State
- principal engineer New York State
- director software engineering New York State
- ai engineer remote New York State
- ai developer New York State

