AI Security Engineer (GRC – Healthcare) | W2 Contract | USC Only |
Dallas, TX - USA
Job Summary
The Job
TheAISecurity Engineer (GRC) serves as the organizations dedicated subject matter expert at the intersection of artificial intelligence and cybersecurity within a regulated healthcare environment. This role is responsible for evaluatingAIvendors and technologies establishing and enforcing secureAIimplementation standards and providing hands-on guidance to development and engineering teams adoptingAIplatforms such as Microsoft Copilot Studio AzureAIFoundry Snowflake Cortex Claude Code and other large language model (LLM)-powered tooling.
Operating within the HIPAA-regulated landscape this analyst will ensureAIintegrations including Model Context Protocol (MCP) servers agentic workflows command-line interfaces (CLIs) APIs and third-partyAIextensions are architected and deployed in a manner consistent with NISTAIRMF HITRUST and organizational security policies. The role acts as a trusted advisor security gatekeeper and enabler for responsibleAIadoption across the enterprise.
You Will
1. AIVendor & Technology Evaluation
- Lead structured security assessments ofAIvendors platforms and tools prior to organizational adoption or renewal
- Evaluate vendor data handling practices model trainingtransparencyanddata residency
- Assess the security posture ofAIplatforms including:
- Microsoft Copilot Studio plugin trust boundaries connector authentication Power Platform DLP policies
- AzureAIFoundry model deployment pipelines private endpoint configuration managed identity usage
- Snowflake Cortex data access controls inAI-generated SQL Snowpark security role-based privilege enforcement Cortex function access policies and query result exposure risks
- Claude Code & Anthropic APIs system prompt injection risks tool use / agentic permissions data retention settings
- GitHub Copilot Cursor and otherAI-assisted development tools code telemetry and secret leakage exposure
- Produce written Vendor Security Assessment Reports (VSARs) including risk ratings compensating controls and recommendations
- Maintain anAItechnology registry with risk classifications and review cadence schedules
2. Secure AIImplementation Guidance for Development Teams
- Serve as the embedded security advisor to software engineering data science and clinical informatics teams adoptingAItooling
- Define and enforce secure-by-default configurations forAIdevelopment environments and agentic systems
- Review and approve MCP server configurations ensuring:
- Tool definitions follow least-privilege principles no excessive file system network or shell access
- Server authentication uses OAuth 2.0 /mTLSand does not rely on static API keys stored in plaintext
- Transport layer security (TLS 1.2) is enforced on all MCP server communications
- Prompt injection attack surfaces areidentifiedand mitigated in tool descriptions and system prompts
- Logging and audit trails are enabled for all MCP tool invocations touching PHI or sensitive data
- Establish CLI security standards forAI-assisted development tools (Claude Code CLI GitHub Copilot CLI Azure Developer CLI) including credential hygiene shell history scrubbing and token scope minimization
- Conduct secure code review forAIintegration code with focus on prompt injection insecure deserialization and unsafe agentic action chains
- Develop andmaintaina library of reference architectures secure configuration templates and implementation checklists for approvedAIplatforms
3. AIRisk Management & Compliance
- Maintainthe organizationsAIRisk Register aligned with NISTAIRMF (Govern Map Measure Manage)
- EnsureAIdeploymentscomply withHIPAA Security Rule (45 CFR 164) HITECH Act obligations and applicable state privacy laws
- ConductAI-specific Threat Modeling (STRIDE / PASTA) and red-team exercises targeting:
- Prompt injection and jailbreak scenarios
- Indirect prompt injection via external data sources (email documents web retrieval)
- Model inversion and membership inference attacks on fine-tuned healthcare models
- Data exfiltration through agentic tool chains
- Track emergingAIthreats and threat actor TTPs relevant to healthcareAIsystems via MITRE ATLAS and sector ISACs
- Participate inAIgovernance committee meetings and contributeAIsecurity perspectives to organizationalAIpolicies
4. SecurityIntegration Reviews
- ReviewAIintegration architectures for network segmentation data flow and trust boundary enforcement
- Validate that PHI is never transmitted to externalAImodels without de-identification or explicit BAA coverage
- Assess retrieval-augmented generation (RAG) architectures for unauthorized data access and embedding extraction risks
- Evaluate agenticAIworkflows and multi-agent orchestration systems for privilege escalation and uncontrolled action chains
- Provide security sign-off onAIinfrastructure as part of the Change Advisory Board (CAB) process
5. Training Awareness & Policy
- DevelopAIsecurity training curricula for developers data engineers clinical staff and IT personnel
- Author andmaintain AIsecurity policiesincluding:Acceptable Use of GenerativeAIAIVendor Onboarding Standards MCP and Agentic System Security Policy and Sensitive Data Handling inAIContexts
- Publish internal guidance and threat intelligence briefings tailored to clinical and technical audiences
Your Qualifications
- Bachelors degree in Cybersecurity Computer Science Information Systems or a closely related field
- Masters degree preferred; equivalent professional experience considered
- 7 years of progressive experience in information security with a minimum of 2 years focused onAI/ML security or appliedAItechnology evaluation
- Demonstrated hands-on experience with one or more of the following: Copilot Studio AzureAIFoundry Claude / Anthropic APIs OpenAI API GitHub Copilot or LLM agentic frameworks (LangChain AutoGen Semantic Kernel)
- Experience working in a HIPAA-regulated environment; healthcare industry background strongly preferred
- Proven track record conducting vendor risk assessments and producing executive-level risk documentation
- Deep understanding of LLM attack surface: prompt injection indirect prompt injection system prompt extraction and model manipulation
- Familiarity withAIred-teaming methodologies and tools (Garak PyRIT PromptBench)
- Knowledge of OWASP Top 10 for LLM Applications
- Understanding ofAImodel lifecycle risks: training data poisoning supply chain risks in model registries (Hugging Face Azure Model Catalog)
- Ability to audit and secure Model Context Protocol (MCP) server implementations including:
- Reviewing tool definitions and permissions for least-privilege violations
- Validating authentication mechanisms (no hardcoded credentials proper token scoping)
- Assessing stdio vs. SSE transport security implications
- Identifying SSRF and command injection risks in custom MCP toolimplementations
- Experience securingAICLIs including credential storage environment variable exposure and shell integration risks
- Knowledge of agentic permission models understanding whenAIagents should require human-in-the-loop approval
- Ability to evaluate multi-stepAIworkflow chains for unintended capability escalation
- Microsoft Copilot Studio: Plugin manifest security review connector authentication sensitivity label enforcement
- AzureAIFoundry: Managed identity configuration private endpoints content filtering policy management model deployment governance
- Snowflake Cortex: SecuringAI-generated SQL and Cortex LLM functions Snowpark container security column-level data masking network policy enforcement and OAuth integration for service accounts
- Claude Code: System prompt construction tool-use permission hardening CLI credential isolation API key scoping
- GitHub Copilot Enterprise: Telemetry settings suggestion filtering for secrets IDE extension trust policies
- Strong grounding in identity and access management OAuth 2.0 OIDC SAML managed identities workload identity federation
- API security: authentication schemes rate limiting input validation and output sanitization forAIendpoints
- Network security: micro-segmentation private endpoints WAF configuration forAIservice ingress
- SIEM/SOAR integration forAIaudit log ingestion anomaly detection and automated response
- Threat modeling methodologies: STRIDE PASTA and application of MITRE ATT&CK and ATLAS frameworks
- Thorough understanding of HIPAA Security Rule requirements and how they apply toAIdata processing pipelines
- Experience with HITRUST CSF controls relevant toAIand cloud-based processing of ePHI
- Practical knowledge of NISTAIRisk Management Framework (AIRMF) Govern Map Measure Manage functions
- Familiarity with EUAIAct classifications and their implications for healthcareAIsystems (high-riskAIdesignation)
- Experience reviewing BAAs and DPAs forAIvendor engagements
Required Experience:
IC
About Company
Transform your business with our cloud services. We offer digital transformation solutions, software development, and consulting services.