Enter a job title or keyword

AI Security Engineer (GRC – Healthcare) | W2 Contract | USC Only |

Xlysi


Job Location:

Dallas, TX - USA

Monthly Salary: Not provided by the employer
Posted: 23 July 2026 (30+ days ago)
Application Deadline: 20 October 2026
Vacancies: 1 Vacancy

Job Summary

The Job

TheAISecurity Engineer (GRC) serves as the organizations dedicated subject matter expert at the intersection of artificial intelligence and cybersecurity within a regulated healthcare environment. This role is responsible for evaluatingAIvendors and technologies establishing and enforcing secureAIimplementation standards and providing hands-on guidance to development and engineering teams adoptingAIplatforms such as Microsoft Copilot Studio AzureAIFoundry Snowflake Cortex Claude Code and other large language model (LLM)-powered tooling.

Operating within the HIPAA-regulated landscape this analyst will ensureAIintegrations including Model Context Protocol (MCP) servers agentic workflows command-line interfaces (CLIs) APIs and third-partyAIextensions are architected and deployed in a manner consistent with NISTAIRMF HITRUST and organizational security policies. The role acts as a trusted advisor security gatekeeper and enabler for responsibleAIadoption across the enterprise.

You Will

1. AIVendor & Technology Evaluation

  • Lead structured security assessments ofAIvendors platforms and tools prior to organizational adoption or renewal
  • Evaluate vendor data handling practices model trainingtransparencyanddata residency
  • Assess the security posture ofAIplatforms including:
  • Microsoft Copilot Studio plugin trust boundaries connector authentication Power Platform DLP policies
  • AzureAIFoundry model deployment pipelines private endpoint configuration managed identity usage
  • Snowflake Cortex data access controls inAI-generated SQL Snowpark security role-based privilege enforcement Cortex function access policies and query result exposure risks
  • Claude Code & Anthropic APIs system prompt injection risks tool use / agentic permissions data retention settings
  • GitHub Copilot Cursor and otherAI-assisted development tools code telemetry and secret leakage exposure
  • Produce written Vendor Security Assessment Reports (VSARs) including risk ratings compensating controls and recommendations
  • Maintain anAItechnology registry with risk classifications and review cadence schedules

2. Secure AIImplementation Guidance for Development Teams

  • Serve as the embedded security advisor to software engineering data science and clinical informatics teams adoptingAItooling
  • Define and enforce secure-by-default configurations forAIdevelopment environments and agentic systems
  • Review and approve MCP server configurations ensuring:
  • Tool definitions follow least-privilege principles no excessive file system network or shell access
  • Server authentication uses OAuth 2.0 /mTLSand does not rely on static API keys stored in plaintext
  • Transport layer security (TLS 1.2) is enforced on all MCP server communications
  • Prompt injection attack surfaces areidentifiedand mitigated in tool descriptions and system prompts
  • Logging and audit trails are enabled for all MCP tool invocations touching PHI or sensitive data
  • Establish CLI security standards forAI-assisted development tools (Claude Code CLI GitHub Copilot CLI Azure Developer CLI) including credential hygiene shell history scrubbing and token scope minimization
  • Conduct secure code review forAIintegration code with focus on prompt injection insecure deserialization and unsafe agentic action chains
  • Develop andmaintaina library of reference architectures secure configuration templates and implementation checklists for approvedAIplatforms

3. AIRisk Management & Compliance

  • Maintainthe organizationsAIRisk Register aligned with NISTAIRMF (Govern Map Measure Manage)
  • EnsureAIdeploymentscomply withHIPAA Security Rule (45 CFR 164) HITECH Act obligations and applicable state privacy laws
  • ConductAI-specific Threat Modeling (STRIDE / PASTA) and red-team exercises targeting:
  • Prompt injection and jailbreak scenarios
  • Indirect prompt injection via external data sources (email documents web retrieval)
  • Model inversion and membership inference attacks on fine-tuned healthcare models
  • Data exfiltration through agentic tool chains
  • Track emergingAIthreats and threat actor TTPs relevant to healthcareAIsystems via MITRE ATLAS and sector ISACs
  • Participate inAIgovernance committee meetings and contributeAIsecurity perspectives to organizationalAIpolicies

4. SecurityIntegration Reviews

  • ReviewAIintegration architectures for network segmentation data flow and trust boundary enforcement
  • Validate that PHI is never transmitted to externalAImodels without de-identification or explicit BAA coverage
  • Assess retrieval-augmented generation (RAG) architectures for unauthorized data access and embedding extraction risks
  • Evaluate agenticAIworkflows and multi-agent orchestration systems for privilege escalation and uncontrolled action chains
  • Provide security sign-off onAIinfrastructure as part of the Change Advisory Board (CAB) process

5. Training Awareness & Policy

  • DevelopAIsecurity training curricula for developers data engineers clinical staff and IT personnel
  • Author andmaintain AIsecurity policiesincluding:Acceptable Use of GenerativeAIAIVendor Onboarding Standards MCP and Agentic System Security Policy and Sensitive Data Handling inAIContexts
  • Publish internal guidance and threat intelligence briefings tailored to clinical and technical audiences

Your Qualifications

  • Bachelors degree in Cybersecurity Computer Science Information Systems or a closely related field
  • Masters degree preferred; equivalent professional experience considered
  • 7 years of progressive experience in information security with a minimum of 2 years focused onAI/ML security or appliedAItechnology evaluation
  • Demonstrated hands-on experience with one or more of the following: Copilot Studio AzureAIFoundry Claude / Anthropic APIs OpenAI API GitHub Copilot or LLM agentic frameworks (LangChain AutoGen Semantic Kernel)
  • Experience working in a HIPAA-regulated environment; healthcare industry background strongly preferred
  • Proven track record conducting vendor risk assessments and producing executive-level risk documentation
  • Deep understanding of LLM attack surface: prompt injection indirect prompt injection system prompt extraction and model manipulation
  • Familiarity withAIred-teaming methodologies and tools (Garak PyRIT PromptBench)
  • Knowledge of OWASP Top 10 for LLM Applications
  • Understanding ofAImodel lifecycle risks: training data poisoning supply chain risks in model registries (Hugging Face Azure Model Catalog)
  • Ability to audit and secure Model Context Protocol (MCP) server implementations including:
  • Reviewing tool definitions and permissions for least-privilege violations
  • Validating authentication mechanisms (no hardcoded credentials proper token scoping)
  • Assessing stdio vs. SSE transport security implications
  • Identifying SSRF and command injection risks in custom MCP toolimplementations
  • Experience securingAICLIs including credential storage environment variable exposure and shell integration risks
  • Knowledge of agentic permission models understanding whenAIagents should require human-in-the-loop approval
  • Ability to evaluate multi-stepAIworkflow chains for unintended capability escalation
  • Microsoft Copilot Studio: Plugin manifest security review connector authentication sensitivity label enforcement
  • AzureAIFoundry: Managed identity configuration private endpoints content filtering policy management model deployment governance
  • Snowflake Cortex: SecuringAI-generated SQL and Cortex LLM functions Snowpark container security column-level data masking network policy enforcement and OAuth integration for service accounts
  • Claude Code: System prompt construction tool-use permission hardening CLI credential isolation API key scoping
  • GitHub Copilot Enterprise: Telemetry settings suggestion filtering for secrets IDE extension trust policies
  • Strong grounding in identity and access management OAuth 2.0 OIDC SAML managed identities workload identity federation
  • API security: authentication schemes rate limiting input validation and output sanitization forAIendpoints
  • Network security: micro-segmentation private endpoints WAF configuration forAIservice ingress
  • SIEM/SOAR integration forAIaudit log ingestion anomaly detection and automated response
  • Threat modeling methodologies: STRIDE PASTA and application of MITRE ATT&CK and ATLAS frameworks
  • Thorough understanding of HIPAA Security Rule requirements and how they apply toAIdata processing pipelines
  • Experience with HITRUST CSF controls relevant toAIand cloud-based processing of ePHI
  • Practical knowledge of NISTAIRisk Management Framework (AIRMF) Govern Map Measure Manage functions
  • Familiarity with EUAIAct classifications and their implications for healthcareAIsystems (high-riskAIdesignation)
  • Experience reviewing BAAs and DPAs forAIvendor engagements

Required Experience:

IC


About Company

Company Logo

Transform your business with our cloud services. We offer digital transformation solutions, software development, and consulting services.

View Profile View Profile