AI Security Engineer (GRC)
Core
Subject matter expert at the intersection of artificial intelligence and cybersecurity within a regulated healthcare environment, evaluating AI vendors and establishing secure implementation standards.
Role type
Senior AI Security Engineer (GRC)
Builds
Secure AI integrations, vendor security assessments, and governance frameworks for LLM-powered tooling.
Domain
Healthcare / AI Security / GRC
Deliverable
production ML models | infrastructure
Required skills
AI vendor risk assessment, NIST AI RMF, HIPAA Security Rule, HITRUST CSF, prompt injection mitigation, MCP server security, agentic workflow security, threat modeling (STRIDE/PASTA), OAuth 2.0, managed identities, SIEM/SOAR integration, BAA/DPA review
Preferred skills
Healthcare industry background, EU AI Act familiarity, red-teaming methodologies (Garak/PyRIT)
Technologies
Microsoft Copilot Studio, Azure AI Foundry, Snowflake Cortex, Claude Code, GitHub Copilot, LangChain, AutoGen, Semantic Kernel, MITRE ATLAS
Responsibilities
Lead structured security assessments of AI vendors and platforms; Define and enforce secure-by-default configurations for AI development environments; Maintain the organization's AI Risk Register; Review AI integration architectures for network segmentation and trust boundaries; Develop AI security training curricula and policies
Seniority
Senior, hands-on IC