Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal AI Security Engineer

$123.3k - $221.95k

Capital District Physicians' Health Plan

Job Description:

Summary:

The Principal Artificial Intelligence (AI) Security Engineer serves as the technical lead for securing machine learning (ML), generative artificial intelligence (GenAI), and agentic systems in production, with emphasis on healthcare and other regulated environments. This role creates security architecture, threat modeling, control design, and detection strategy across the AI lifecycle, including data ingestion, feature engineering, training and fine-tuning, evaluation, model serving, retrieval-augmented generation (RAG) pipelines, agent frameworks, application programming interface (API) mediation, and post-deployment monitoring. The Principal AI Security Engineer leads and partners throughout the organization to build enforceable guardrails for protected health information and electronic protected health information handling, identity and access control, secrets isolation, model and dataset provenance, output safety, and evidence collection for audits and investigations.

Essential Accountabilities

  • Creates reference architectures, defines security requirements and patterns for model training, inference, retrieval-augmented generation (RAG), agent orchestration, tool calling, and multi-model pipelines across cloud and hybrid environments.
  • Performs deep threat modeling for artificial intelligence (AI) systems, including prompt injection, indirect prompt injection, insecure output handling, excessive agency, system prompt leakage, vector and embedding weaknesses, data poisoning, model theft, model inversion, supply chain compromise, and denial-of-service.
  • Defines guardrails for protected health information and electronic protected health information processing, including data minimization, de-identification, context scoping, encryption in transit and at rest, retention boundaries, and access paths into model context windows, vector stores, caches, and logs.
  • Designs and implement secure machine learning operations (MLOps) controls for datasets, features, models, prompts, and policies: provenance tracking, artifact signing, environment separation, approval workflows, reproducible builds, rollback paths, and tamper-evident audit trails.
  • Defines and sets standards for identity, service-to-service authentication, secrets management, token scoping, least privilege, just-in-time access, and network segmentation for AI services, model gateways, and external tool integrations.
  • Leads offensive security activities for AI systems, including adversarial testing, AI red teaming, prompt and tool abuse simulation, fuzzing, jailbreak testing, attack path validation, and control verification against production-like workflows and third-party model providers.
  • Leads defensive security and blue team capabilities for AI platforms, including telemetry design, prompt and response event logging, model gateway instrumentation, security information and event management/security orchestration, automation, and response (SIEM/SOAR) integration, detection engineering, exfiltration and jailbreak detections, anomalous agent action monitoring, incident triage playbooks, and continuous tuning based on observed attack patterns.
  • Leads security reviews of RAG and agentic systems, including chunking and retrieval policies, vector store isolation, embedding pipeline validation, retrieval authorization, tool allow-listing, action confirmation, and human-in-the-loop controls for high-risk operations.
  • Defines security requirements for model evaluation pipelines, benchmark data handling, canary tests, policy enforcement, and release gates so unsafe or noncompliant behavior is identified before promotion.
  • Collaborates to ensure secure, compliant handling of sensitive and regulated data across AI systems and enterprise data platforms, including enforcement of data classification, retention, access controls, auditability, and secure data readiness for approved AI use cases.
  • Collaborates on the design and implementation of AI and data governance frameworks, translating legal, regulatory, and compliance requirements into enforceable technical controls, security standards, and operational processes.
  • Coordinates the development of secure data pipelines and control implementations, ensuring proper data sourcing, minimization, de-identification, and consistent application of enterprise data protection controls (e.g., DLP, encryption, retention) within AI architectures and workflows.
  • Partner with application security, platform engineering, and data science teams to enable secure adoption of AI technologies.
  • Jointly support investigations, incident response, and regulatory inquiries involving AI systems and enterprise data, including forensic analysis, evidence preservation, defensible documentation, and production of audit-ready artifacts for legal and compliance purposes.
  • Develop and maintain integrated monitoring, detection, and response capabilities, aligning tools and processes (e.g., DSPM, eDiscovery, SIEM/SOAR, AI observability) to proactively identify and mitigate data leakage, insider risk, AI misuse, and anomalous system or user behavior.
  • Consistently demonstrates high standards of integrity by supporting the Lifetime Healthcare Companies' mission and values, adhering to the Corporate Code of Conduct, and leading to the Lifetime Way values and beliefs.
  • Maintains high regard for member privacy in accordance with the corporate privacy policies and procedures.
  • Regular and reliable attendance is expected and required.
  • Performs other functions as assigned by management.

Minimum Qualifications

  • Ten (10) years of hands-on security engineering experience spanning application security, cloud security, security architecture, detection and response, platform security, or infrastructure security.
  • Bachelor's degree in computer science, information technology, or relevant field. In lieu of degree, six (6) cumulative years of related experience required.
  • Demonstrated experience securing production AI/ML systems, including large language model (LLM) applications, model serving stacks, retrieval-augmented generation architecture, or agent frameworks.
  • CISA, CISM, CCSP, HCISPP, GIAC and or CISSP certifications preferred.
  • Demonstrated advanced expertise in AI threat modeling and adversarial testing, including prompt injections, jailbreaks, insecure tool use, data and model poisoning, vector store abuse, model extraction, and sensitive data disclosure.
  • Strong implementation knowledge of secure software development lifecycle (SDLC), continuous integration/continuous delivery (CI/CD) security, infrastructure as code (IaC), container and Kubernetes security, application programming interface (API) security, identity and access management (IAM), secrets management, key management service/hardware security module (KMS/HSM) integration, and cloud-native telemetry pipelines.
  • Experience designing or reviewing controls for secure machine learning operations (MLOps): artifact provenance, signed builds, feature and dataset integrity, model registry controls, environment promotion, reproducibility, and rollback.
  • Experience instrumenting detections and response workflows using logs, traces, metrics, security information and event management/security orchestration, automation, and response (SIEM/SOAR) pipelines, alert tuning, and incident handling for distributed systems or AI services.
  • Advanced working knowledge of RAG security, embedding pipelines, retrieval authorization, policy engines, content filtering, and evaluation harnesses for safety, security, and regulated-data compliance.
  • Prior experience in healthcare, payer, provider or similarly regulated environments with PHI/ePHI safeguards preferred.
  • Advanced ability to write engineering standards, design docs, threat models, and control requirements that can be implemented and tested by platform and product teams.
  • Hands-on familiarity with model gateways, policy enforcement layers, prompt filtering, content moderation, retrieval authorization, vector databases, and AI observability tooling.
  • Working knowledge of static/dynamic application security testing, infrastructure as code (IaC) scanning, container image scanning, software bill of materials generation, artifact signing, secret scanning, and dependency-risk management as applied to AI delivery pipelines.
  • Experience with AI red teaming platforms, safety and abuse evaluation harnesses, benchmark design, and automated release gates for model or prompt changes.
  • Familiarity with Sarbanes Oxley, HIPAA, OCR, AI RFM, HCFA, PCI/DSS, NIST and other regulations impacting security (with ISO17799 and NIST security standards) is preferred, as well as COBIT and COSO familiarity.

Physical Requirements:

  • Ability to work prolonged periods sitting and/or standing at a workstation and working on a computer.
  • Ability to travel across the Health Plan service region for meetings and/or trainings as needed.
  • Ability to work in a home office for continuous periods of time for business continuity.

***********

In support of the Americans with Disabilities Act, this job description lists only those responsibilities and qualifications deemed essential to the position.

Equal Opportunity Employer

Compensation Range(s):

Minimum: $123,304 - Maximum: $221,948

The salary range indicated in this posting represents the minimum and maximum of the salary range for this position. Actual salary will vary depending on factors including, but not limited to, budget available, prior experience, knowledge, skill and education as they relate to the position's minimum qualifications, in addition to internal equity. The posted salary range reflects just one component of our total rewards package. Other components of the total rewards package may include participation in group health and/or dental insurance, retirement plan, wellness program, paid time away from work, and paid holidays.

Please note: There may be opportunity for remote work within all jobs posted by the CDPHP Talent Acquisition team. This decision is made on a case-by-case basis.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Principal AI Security Engineer in Binghamton, NY vacancy
  • $123.3k - $221.95k

     ...Principal Artificial Intelligence (AI) Security Engineer The Principal Artificial Intelligence (AI) Security Engineer serves as the technical lead for securing machine learning (ML), generative artificial intelligence (GenAI), and agentic systems in production, with... 
    Principal
    Work from home
    Home office

    Univera Healthcare

    Binghamton, NY
    3 days ago
  • $100k - $172.5k

     ...more at Job Function: Technology Enterprise Strategy & Security Job Sub Function: Solution Architecture Job...  ...Description: We are searching for the best talent for a Principal Product Security Engineer to be located in Danvers, MA or Raritan, NJ. Remote... 
    Principal
    Full time
    Temporary work
    Work at office
    Local area
    Immediate start
    Remote work
    3 days per week

    Johnson & Johnson

    Binghamton, NY
    2 days ago
  •  ...AI Engineer The AI Engineer is part of a highly collaborative team that develops cutting-edge machine learning (ML) and artificial intelligence (AI) models to solve complex business challenges and improve member health outcomes. In this role, you will work on high-impact... 
    Suggested
    Internship
    Work from home
    Home office

    Excellus Health Plan

    Binghamton, NY
    1 day ago
  • $155.66k - $225.16k

     ...with one place to chat, explore and build with a wide variety of AI language models (bots), including o3, o4-mini, Claude 3.7 Sonnet...  ...the Team and Role: We’re hiring our first AI Automation Engineer to lead how we apply AI internally across the company. This is... 
    Suggested
    Remote job
    Full time
    Shift work

    Quora

    Binghamton, NY
    3 days ago
  • $105k - $143k

     ...search of: The next member of our Software Engineering team. If you enjoy working in a team...  ...of a Senior Software Engineer and Principal Engineer: You may direct other developers...  ...equipment. Create and maintain security and performance minded applications and... 
    Principal
    Work at office
    Remote work
    Home office
    Relocation package

    Security Mutual Life Insurance

    Binghamton, NY
    16 days ago
  •  ...federal partner supporting mission‑critical programs across national security, defense, and public service delivery. Our work focuses on...  ...that matter at a national scale. The Junior Security Engineer supports 24x7 enterprise cybersecurity operations by monitoring... 
    Minimum wage
    Full time
    Contract work
    Temporary work
    Work experience placement
    Remote work

    Maximus

    Binghamton, NY
    3 days ago
  •  ...Anticipated Interim Assistant Principal The Binghamton City School District is seeking candidates to fill the Anticipated Interim Assistant Principal position at East Middle School for the 2026-2027 school year. The BCSD offers competitive salaries, comprehensive benefits... 
    Principal
    Interim role

    Kenmore-Town of Tonawanda Union Free School District

    Binghamton, NY
    19 hours ago
  •  ...Job Description Job Description Assistant Principal Holds a valid Tennessee license with an endorsement for Administrator/Supervisor at the appropriate level As a school administrator, must collaborate with and support professional staff to meet school wide... 
    Principal

    Rutherford County Schools

    Binghamton, NY
    14 days ago
  • $89k - $143.75k

     ...Product Development Job Sub Function: R&D Software/Systems Engineering Job Category: Scientific/Technology All Job Posting...  ...with a cyber-lens. Performing periodic risk assessment of security vulnerabilities in software for the product by identifying and... 
    Full time
    Temporary work
    Work at office
    Local area
    Remote work
    Night shift

    Johnson & Johnson

    Binghamton, NY
    1 day ago
  •  ...Description & Requirements Maximus is a trusted federal partner supporting mission‑critical programs across national security, defense, and public service delivery. Our work focuses on sustaining, operating, and improving essential government systems and services, with... 
    Minimum wage
    Full time
    Contract work
    Temporary work
    Work experience placement
    Remote work

    Maximus

    Binghamton, NY
    3 days ago
  •  ...mission‑critical programs across national security, defense, and public service delivery....  ...develops, trains, evaluates, and integrates AI/ML models and algorithms supporting...  ...for machine learning pipelines, feature engineering, and model lifecycle management - Implements... 
    Minimum wage
    Full time
    Contract work
    Temporary work
    For contractors
    Work experience placement
    Remote work

    Maximus

    Binghamton, NY
    3 days ago
  •  ...Cybersecurity Engineer Triple Cities Network Solutions (TCNS) is seeking an experienced cybersecurity engineer to strengthen our internal and client-facing security posture. This role plays a key part in designing, implementing, and maintaining cybersecurity solutions... 

    Triple Cities Network Solutions

    Binghamton, NY
    17 hours ago
  • $118.3k - $138k

     ...vision is to be the worldwide partner of choice in defense and security, and civil aviation by revolutionizing our customers' training...  ...~ Bachelor's degree in Computer Science, Software Engineering, or a related field (or equivalent experience). ~8+ years... 
    Contract work
    Work experience placement
    Casual work
    Local area
    Worldwide
    Shift work

    CAE

    Binghamton, NY
    4 days ago
  •  ...Description & Requirements Maximus is currently seeking a Software Engineer . In this role, you will provide expertise in the areas of managed file transfer and EDI X12 translations. In addition, they must configure, support and maintain environments and procedures... 
    Minimum wage
    Full time
    Contract work
    Temporary work
    Work experience placement
    Remote work

    Maximus

    Binghamton, NY
    17 hours ago
  •  ...background aligns with future opportunities, we’ll reach out directly when formal applications become available. About Software Engineering Roles at Danaher Are you passionate about building real-world applications, writing clean code, and solving meaningful... 
    Remote job
    Internship

    Danaher

    Binghamton, NY
    1 day ago
  • $128.19k - $184.01k

     ...with one place to chat, explore and build with a wide variety of AI language models (bots), including o3, o4-mini, Claude 3.7 Sonnet...  .... About the Team and Role: We are seeking a talented iOS Engineer to join us in building Poe, an innovative platform that brings together... 
    Remote job
    Full time

    Quora

    Binghamton, NY
    3 days ago
  • $85k - $100k

     ...Description Description: GENERAL JOB DESCRIPTION The Software Engineer is responsible for developing and maintaining backend...  ...software development best practices. Ensure applications meet security, reliability, and performance standards. Support internal business... 
    Monday to Friday

    TeamWorld, Inc.

    Binghamton, NY
    2 days ago
  •  ...company with over 90 years of experience in enabling the ongoing electronics revolution. We are currently seeking an IT Security Analyst/System Engineer to help set and maintain security standards; to provide comprehensive reviews and recommendations to ensure sensitive... 
    Work experience placement

    Amphenol Corporation

    Endicott, NY
    2 days ago
  • $103.71k - $138.28k

     ...growth by connecting people, data and applications – quickly, securely, and effortlessly. Together, we are building a culture and company...  ...knowledge and experience in system architecture and engineering disciplines. Specific technical knowledge of enterprise level... 
    Full time
    Temporary work
    Remote work

    Lumen

    Binghamton, NY
    17 hours ago
  •  ...Provides steps for resolution, explains preventative measures and follows up with users. Works with school districts to implement security for software applications using best practices to ensure data security and privacy. Assists in training of staff in the use of software... 

    Kenmore-Town of Tonawanda Union Free School District

    Binghamton, NY
    1 day ago
  •  ...Provide Applications Engineering for Simulated EV Lab. Work with Customers and R&D staff for client sim setup and EV drive train simulation stages Job Requirements Minimum Security Clearance: Bondable BS in Electrical or Computer Engineering. Software... 

    MLS Technologies

    Binghamton, NY
    4 days ago
  •  ...Resident Engineer - Data Center Technology Campus - Binghamton, NY   This opportunity is working with a mission-critical data center...  ...supporting Enterprise Clients, Colo Providers, Hyperscale Companies, AI / HPC, etc. This opportunity provides a career-growth minded... 
    For contractors

    Pkaza LLC

    Binghamton, NY
    17 hours ago
  •  ...partner supporting mission‑critical programs across national security, defense, and public service delivery. Our work focuses on sustaining...  ...architecture and governance standards, partnering with Cloud Engineers and Architects to support system suitability assessments and... 
    Minimum wage
    Full time
    Contract work
    Temporary work
    Work experience placement

    Maximus

    Binghamton, NY
    3 days ago
  • $150k - $175k

     ...1990, WWT is a global technology solutions provider leading the AI and Digital Revolution. WWT combines the power of strategy, execution...  ..., Inc. (WWT) is seeking a highly driven and experienced Cyber Security Specialist to join our dynamic Security Sales team. In this role... 
    Full time
    Remote work
    Shift work

    World Wide Technology

    Binghamton, NY
    2 days ago
  •  ...partner supporting mission‑critical programs across national security, defense, and public service delivery. Our work focuses on sustaining...  ...Essential Duties and Responsibilities: - Provide Tier‑3 engineering support for Microsoft 365 GCC, Exchange Online, hybrid... 
    Minimum wage
    Full time
    Contract work
    Temporary work
    Work experience placement

    Maximus

    Binghamton, NY
    2 days ago
  • $115k - $155k

     ...We are currently seeking qualified candidates for consideration to fill an open Principal Engineer - Transmission Lines position in our Program Management Services Division. This position will be located at our Client’s Binghamton, NY office. The Program Management... 
    Principal
    Full time
    Temporary work
    Work at office
    Local area
    Flexible hours

    LaBella Associates

    Binghamton, NY
    more than 2 months ago
  • Job Description Job Description Position Summary A market-leading supplier of specialty products supporting a nationwide customer base is seeking a high-impact  Senior Procurement Manager to join its leadership team in Binghamton, NY. The organization...

    Thunderbolt Talent Partners

    Binghamton, NY
    29 days ago
  • $70k - $75k

     ...design, and develop computer software systems to aid in innovating and improving our advanced automation assembly equipment. The engineer will access our advanced automation machines and equipment in our engineering labs for a hands-on approach to develop software algorithms... 
    Work experience placement
    Flexible hours

    Universal Instruments, A Delta Group Company

    Conklin, NY
    3 days ago
  •  ...SUMMARY Working closely with IT and Analytics team, this role will be responsible for the design, implementation, maintenance, and security of our databases. The position will require programming skills to optimize performance, develop automation scripts, and support... 
    Work experience placement
    Relocation
    Home office
    Visa sponsorship
    Work visa

    Care Compass Network

    Binghamton, NY
    5 days ago
  •  ...Insero Talent Solutions is recruiting a Senior IT Systems Engineer with a fast growing IT services company in Binghamton, NY. We are looking for an experienced Senior Systems Engineer to work with our clients. Excellent benefits and high compensation available to the... 
    Work at office

    Insero Talent Solutions

    Binghamton, NY
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal AI Security Engineer. Be the first to apply!