Principal AI Security Engineer
$123.3k - $221.95kCapital District Physicians' Health Plan
Job Description:
Summary:
The Principal Artificial Intelligence (AI) Security Engineer serves as the technical lead for securing machine learning (ML), generative artificial intelligence (GenAI), and agentic systems in production, with emphasis on healthcare and other regulated environments. This role creates security architecture, threat modeling, control design, and detection strategy across the AI lifecycle, including data ingestion, feature engineering, training and fine-tuning, evaluation, model serving, retrieval-augmented generation (RAG) pipelines, agent frameworks, application programming interface (API) mediation, and post-deployment monitoring. The Principal AI Security Engineer leads and partners throughout the organization to build enforceable guardrails for protected health information and electronic protected health information handling, identity and access control, secrets isolation, model and dataset provenance, output safety, and evidence collection for audits and investigations.
Essential Accountabilities
- Creates reference architectures, defines security requirements and patterns for model training, inference, retrieval-augmented generation (RAG), agent orchestration, tool calling, and multi-model pipelines across cloud and hybrid environments.
- Performs deep threat modeling for artificial intelligence (AI) systems, including prompt injection, indirect prompt injection, insecure output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, data poisoning, model theft, model inversion, supply chain compromise, and denial-of-service.
- Defines guardrails for protected health information and electronic protected health information processing, including data minimization, de-identification, context scoping, encryption in transit and at rest, retention boundaries, and access paths into model context windows, vector stores, caches, and logs.
- Designs and implement secure machine learning operations (MLOps) controls for datasets, features, models, prompts, and policies: provenance tracking, artifact signing, environment separation, approval workflows, reproducible builds, rollback paths, and tamper-evident audit trails.
- Defines and sets standards for identity, service-to-service authentication, secrets management, token scoping, least privilege, just-in-time access, and network segmentation for AI services, model gateways, and external tool integrations.
- Leads offensive security activities for AI systems, including adversarial testing, AI red teaming, prompt and tool abuse simulation, fuzzing, jailbreak testing, attack path validation, and control verification against production-like workflows and third-party model providers.
- Leads defensive security and blue team capabilities for AI platforms, including telemetry design, prompt and response event logging, model gateway instrumentation, security information and event management/security orchestration, automation, and response (SIEM/SOAR) integration, detection engineering, exfiltration and jailbreak detections, anomalous agent action monitoring, incident triage playbooks, and continuous tuning based on observed attack patterns.
- Leads security reviews of RAG and agentic systems, including chunking and retrieval policies, vector store isolation, embedding pipeline validation, retrieval authorization, tool allow-listing, action confirmation, and human-in-the-loop controls for high-risk operations.
- Defines security requirements for model evaluation pipelines, benchmark data handling, canary tests, policy enforcement, and release gates so unsafe or noncompliant behavior is identified before promotion.
- Collaborates to ensure secure, compliant handling of sensitive and regulated data across AI systems and enterprise data platforms, including enforcement of data classification, retention, access controls, auditability, and secure data readiness for approved AI use cases.
- Collaborates on the design and implementation of AI and data governance frameworks, translating legal, regulatory, and compliance requirements into enforceable technical controls, security standards, and operational processes.
- Coordinates the development of secure data pipelines and control implementations, ensuring proper data sourcing, minimization, de-identification, and consistent application of enterprise data protection controls (e.g., DLP, encryption, retention) within AI architectures and workflows.
- Partner with application security, platform engineering, and data science teams to enable secure adoption of AI technologies.
- Jointly support investigations, incident response, and regulatory inquiries involving AI systems and enterprise data, including forensic analysis, evidence preservation, defensible documentation, and production of audit-ready artifacts for legal and compliance purposes.
- Develop and maintain integrated monitoring, detection, and response capabilities, aligning tools and processes (e.g., DSPM, eDiscovery, SIEM/SOAR, AI observability) to proactively identify and mitigate data leakage, insider risk, AI misuse, and anomalous system or user behavior.
- Consistently demonstrates high standards of integrity by supporting the Lifetime Healthcare Companies' mission and values, adhering to the Corporate Code of Conduct, and leading to the Lifetime Way values and beliefs.
- Maintains high regard for member privacy in accordance with the corporate privacy policies and procedures.
- Regular and reliable attendance is expected and required.
- Performs other functions as assigned by management.
Minimum Qualifications
- Ten (10) years of hands-on security engineering experience spanning application security, cloud security, security architecture, detection and response, platform security, or infrastructure security.
- Bachelor's degree in computer science, information technology, or relevant field. In lieu of degree, six (6) cumulative years of related experience required.
- Demonstrated experience securing production AI/ML systems, including large language model (LLM) applications, model serving stacks, retrieval-augmented generation architecture, or agent frameworks.
- CISA, CISM, CCSP, HCISPP, GIAC and or CISSP certifications preferred.
- Demonstrated advanced expertise in AI threat modeling and adversarial testing, including prompt injections, jailbreaks, insecure tool use, data and model poisoning, vector store abuse, model extraction, and sensitive data disclosure.
- Strong implementation knowledge of secure software development lifecycle (SDLC), continuous integration/continuous delivery (CI/CD) security, infrastructure as code (IaC), container and Kubernetes security, application programming interface (API) security, identity and access management (IAM), secrets management, key management service/hardware security module (KMS/HSM) integration, and cloud-native telemetry pipelines.
- Experience designing or reviewing controls for secure machine learning operations (MLOps): artifact provenance, signed builds, feature and dataset integrity, model registry controls, environment promotion, reproducibility, and rollback.
- Experience instrumenting detections and response workflows using logs, traces, metrics, security information and event management/security orchestration, automation, and response (SIEM/SOAR) pipelines, alert tuning, and incident handling for distributed systems or AI services.
- Advanced working knowledge of RAG security, embedding pipelines, retrieval authorization, policy engines, content filtering, and evaluation harnesses for safety, security, and regulated-data compliance.
- Prior experience in healthcare, payer, provider or similarly regulated environments with PHI/ePHI safeguards preferred.
- Advanced ability to write engineering standards, design docs, threat models, and control requirements that can be implemented and tested by platform and product teams.
- Hands-on familiarity with model gateways, policy enforcement layers, prompt filtering, content moderation, retrieval authorization, vector databases, and AI observability tooling.
- Working knowledge of static/dynamic application security testing, infrastructure as code (IaC) scanning, container image scanning, software bill of materials generation, artifact signing, secret scanning, and dependency-risk management as applied to AI delivery pipelines.
- Experience with AI red teaming platforms, safety and abuse evaluation harnesses, benchmark design, and automated release gates for model or prompt changes.
- Familiarity with Sarbanes Oxley, HIPAA, OCR, AI RFM, HCFA, PCI/DSS, NIST and other regulations impacting security (with ISO17799 and NIST security standards) is preferred, as well as COBIT and COSO familiarity.
Physical Requirements:
- Ability to work prolonged periods sitting and/or standing at a workstation and working on a computer.
- Ability to travel across the Health Plan service region for meetings and/or trainings as needed.
- Ability to work in a home office for continuous periods of time for business continuity.
***********
In support of the Americans with Disabilities Act, this job description lists only those responsibilities and qualifications deemed essential to the position.
Equal Opportunity Employer
Compensation Range(s):
Minimum: $123,304 - Maximum: $221,948
The salary range indicated in this posting represents the minimum and maximum of the salary range for this position. Actual salary will vary depending on factors including, but not limited to, budget available, prior experience, knowledge, skill and education as they relate to the position's minimum qualifications, in addition to internal equity. The posted salary range reflects just one component of our total rewards package. Other components of the total rewards package may include participation in group health and/or dental insurance, retirement plan, wellness program, paid time away from work, and paid holidays.
Please note: There may be opportunity for remote work within all jobs posted by the CDPHP Talent Acquisition team. This decision is made on a case-by-case basis.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
$123.3k - $221.95k
...Principal Artificial Intelligence (AI) Security Engineer The Principal Artificial Intelligence (AI) Security Engineer serves as the technical lead for securing machine learning (ML), generative artificial intelligence (GenAI), and agentic systems in production, with...PrincipalWork from homeHome office$97.1k - $161.8k
...A prominent financial institution is looking for a Senior Software Engineer specialized in Generative AI to design and develop AI-enabled features. The ideal candidate should have experience in Java, Python, or C# within enterprise environments, and demonstrate strong...Suggested$91k - $321.5k
...At PwC, our people in data and analytics engineering focus on leveraging advanced technologies... ...will lead the development of innovative AI solutions that drive operational... ...and collaborate with diverse stakeholders, securing impactful results that align with industry...SuggestedFull timeH1b- ...AI Engineer The AI Engineer is part of a highly collaborative team that develops cutting-edge machine learning (ML) and artificial intelligence (AI) models to solve complex business challenges and improve member health outcomes. In this role, you will work on high-impact...SuggestedInternshipRemote workWork from homeHome office
$201.2k - $335.3k
...Overview The Director of AI Engineering manages the activities and strategic direction of multiple departments, including indirectly... ...AI operating model spanning platform engineering, governance, security, and delivery, enabling consistent enterprise adoption while...SuggestedTemporary workFor contractorsWork experience placement$73.5k - $212.28k
...At PwC, our people in data and analytics engineering focus on leveraging advanced technologies... ...with cross-functional teams to incorporate AI into various applications Drive... ...these factors thoughtfully to establish a secure and trusted workplace for all. Applications...Full timeH1b$145k - $175k
...inside and outside of work. Job Title : Knowledge Management Engineering Manager Reporting To: Director, Knowledge Management... ...Experience with Teamcenter Exposure to or experience with AI development and application As the KM Engineering Manager,...Local areaWorldwideRelocationRelocation packageFlexible hours$90 - $100 per hour
...Lighthouse Technology Services is partnering with our client to fill their Senior Azure Cloud Security Engineer position! This is a 12 month contract and will be onsite in Buffalo, NY with 4 days on-site at Seneca One. This role will be a W2 employee of Lighthouse Technology...Contract work$86.5k - $142.7k
...who designs, prototypes and builds modern, AI‑enabled applications and digital products... ...building proofs‑of‑concept, and guiding engineering teams through complex technical decisions... ...while enforcing clean architecture, security and maintainability. • Review AI‑generated...Summer holidayFlexible hours$124k - $280k
...Specialty/Competency: Data, Analytics & AI Industry/Sector: Health Services Time... ...At PwC, our people in data and analytics engineering focus on leveraging advanced technologies... ...factors thoughtfully to establish a secure and trusted workplace for all. Applications...Full timeH1b$121k - $181.49k
...A food product company based in Buffalo, NY, is seeking a Principal Sensory Scientist to lead sensory and consumer research initiatives. This role requires a highly qualified individual with a Ph.D. and substantial experience in innovation within the food industry. Responsibilities...Principal$124k - $280k
...Specialty/Competency: Data, Analytics & AI Industry/Sector: Health Services Time... ...At PwC, our people in data and analytics engineering focus on leveraging advanced technologies... ...factors thoughtfully to establish a secure and trusted workplace for all. Applications...Full timeH1b$106.9k - $176.5k
...wherever you want it to go. Join EY and help to build a better working world. Technology – Data and Decision Science – AI Native Engineering AI/Machine Learning Engineer, Senior Consultant The opportunity Our Artificial Intelligence and Data team helps...Full timeWork experience placementSummer holidayFlexible hours$62.5k - $90k
...National Fuel is currently seeking an OT Security Engineer for an outstanding career opportunity in the Gas Supply department located at our distribution center in West Seneca, NY. National Fuel is proud to have an inclusive workplace where hard work is rewarded and...Flexible hours- ...POA&M tracking activities, supporting remediation efforts and preparation of recurring cybersecurity scorecard data. - Monitor security tools and alerts, performing initial triage and escalating issues in accordance with defined processes. - Maintain and update incident...Minimum wageContract workTemporary workWork experience placementRemote work
$155.66k - $225.16k
...with one place to chat, explore and build with a wide variety of AI language models (bots), including o3, o4-mini, Claude 3.7 Sonnet... ...the Team and Role: We’re hiring our first AI Automation Engineer to lead how we apply AI internally across the company. This is...Remote jobFull timeShift work- ...Overview Principal/Sr. Scientist, Plant-Based Beverage, Innovation — entrepreneurial scientific leadership opportunity within an ultra-innovative category defining plant-based food & beverage, functional foods and nutritional products company with state-of-the-art research...PrincipalFull time
- ...Certified - Administrative - Elementary Asst Principal Job Number 3300055383 Start Date Open Date 04/23/2026 Closing Date Assistant Principal (Discipline & Culture Duo) Reports to: Principal and Chief Talent Officer Status...PrincipalContract work
$136.4k - $221.6k
...A global engineering consultancy is seeking a Principal Industrial Hygiene Consultant based in the United States. This role includes managing Industrial Hygiene services, developing client relationships, and mentoring staff across various environmental projects. Candidates...Principal- ...Assistant Principal - North Tonawanda Intermediate North Tonawanda City Schools 176 Walck Road North Tonawanda , NY 14120 Certified - Administrative - School Building Leader (SBL) Job Number 3300055707 Start Date Open Date 05/20/2026 Closing Date 06/...PrincipalFull time
- ...federal partner supporting mission‑critical programs across national security, defense, and public service delivery. Our work focuses on... ...that matter at a national scale. The Junior Security Engineer supports 24x7 enterprise cybersecurity operations by monitoring...Minimum wageFull timeContract workTemporary workWork experience placementRemote work
- ...Job Title Responsibilities/Experience: To assist the principal, faculty, staff, and students in creating a positive school culture that improves student learning and achievement. Assist in overseeing student behavior, discipline, and socio-emotional screening...PrincipalSummer work
- ...Assistant Principal - Elementary School Reports To: Principal Position Summary The Assistant Principal assists... ..., and district regulations. Assist with building safety, security, and crisis response procedures. Family and Community...Principal
$170k - $200k
...NY, NY Pennington, NJ Jersey City, NJ What you will do We're seeking a Principal Architect with deep expertise in Perimeter/DMZ architectures, network segmentation, and secure ingress/egress across on‐premises and cloud environments. This leader will drive...Principal$85k
...Full job description Assistant Principal - John F. Kennedy Middle School Location: John F. Kennedy Middle School, Cheektowaga-Sloan Union Free School District Salary/Pay Scale: Minimum $85,000; Actual salary commensurate with experience and credentials...Principal$148.3k - $247.1k
...as Certified in Risk and Information Systems Control (CRISC®), Certified Information Systems Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP) Demonstrated ability to indirectly lead strategic...PrincipalWork experience placement$125.5k - $230.2k
...wherever you want it to go. Join EY and help to build a better working world. Technology – Data and Decision Science – AI Native Engineering AI/Machine Learning Engineer, Manager Consultant The opportunity Our Artificial Intelligence and Data team helps apply...Full timeWork experience placementSummer holidayFlexible hours- Python Developer We are looking for an experienced Python Developer for our client. You will work on an existing in-house application with over 500 users. This role will require new feature development and monthly platform updates. A background in banking/financial...
$97.1k - $161.8k
M&T Bank is seeking an experienced software developer in Buffalo, NY. This role involves writing code, conducting reviews, and collaborating with teams to meet banking technology standards. Candidates should have a Bachelor’s degree or equivalent experience and at least...- This role requires the skills to build new features that our customers will love while being responsible for the entire stack. Excellent communication skills and attention to detail are key to success in this role. You will build new features and support existing functionality...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal AI Security Engineer. Be the first to apply!
- engineering director Buffalo, NY
- chief engineer Buffalo, NY
- data center chief engineer Buffalo, NY
- hotel chief engineer Buffalo, NY
- principal developer Buffalo, NY
- general engineer Buffalo, NY
- principal engineer Buffalo, NY
- director software engineering Buffalo, NY
- senior ai engineer Buffalo, NY
- ai engineer Buffalo, NY


