×
Register Here to Apply for Jobs or Post Jobs. X

Director, Application & AI Security

Job in Dallas, Dallas County, Texas, 75215, USA
Listing for: Lantern
Full Time position
Listed on 2026-08-30
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Security Management & Operations, AI Engineer (Applied/Software)
Salary/Wage Range or Industry Benchmark: 180000 - 280000 USD Yearly USD 180000.00 280000.00 YEAR
Job Description & How to Apply Below

Lantern is the specialty care platform, connecting people with high-quality, affordable specialty care close to home. We operate in a regulated healthcare environment (HIPAA, HITRUST, SOC
2), we handle protected health information at scale, and we are becoming an AI healthcare company, with AI adoption a top company priority.

The Director, Application & AI Security owns application and AI security end to end: the security of the software and the AI systems Lantern builds. It is the seat most directly tied to our AI strategy. The job is to make it safe to move fast, building the golden paths and secure defaults that let teams ship product and adopt AI without waiting in a permission queue, while keeping PHI and external-model data egress genuinely protected.

You will lead a growing function. At hire, the team includes a senior application security engineer, with several open roles to fill across security architecture, AI/ML security, Dev Sec Ops , and product security. You will build that team and set the secure-design standards the whole engineering organization builds against.

Our security philosophy is open by default, secure by design. Security exists to help the business move fast, safely, and the default answer is "yes, safely," because guardrails are built into the platform, pipelines, and tooling rather than enforced by someone saying no. Gates exist only where risk genuinely warrants them, and even then they are automated, fast, and transparent.

Location: Hybrid - at least 3 days/wk in our Dallas, TX office

Responsibilities
  • Own application security across the development lifecycle, covering static, dynamic, and interactive analysis (SAST/DAST/SCA/IAST), code and dependency security, API security, and runtime protections such as WAF and API gateways, all delivered through engineering teams rather than filed as findings.
  • Own AI and ML security, including model and agent security, prompt-injection and tool-use risk, and data-egress controls for third‑party model providers, plus continuous AI security posture management informed by the OWASP LLM Top 10, MITRE ATLAS, and AI risk‑management standards (NIST AI RMF, ISO/IEC 42001).
  • Own security architecture and threat modeling, including secure‑by‑design review and ownership of cryptographic standards.
  • Own Dev Sec Ops  and pipeline security, with scanning as a default in CI/CD and MLOps/LLMOps pipelines, release gating calibrated to risk, and software supply chain and SBOM practice.
  • Own the security‑review intake as a single front door with risk‑based triage, reported against a turnaround commitment, so security accelerates the business rather than bottlenecking it.
  • Own the application and AI security tool stack and the secure‑design standards behind it.
Key Deliverables in Your First Year
  • An AI golden path: an approved‑model catalog and automated data‑egress controls, so teams adopt AI on a governed route instead of case‑by‑case approvals.
  • A secure SDLC paved road, with scanning in the pipeline by default and critical findings resolved within SLA.
  • A single security‑review intake that delivers fast, risk‑based answers on a published turnaround.
  • A built‑out team, with the open roles filled and performing.
How You Will Work

Much of this scope is delivered in partnership. Engineering carries remediation on application, API, and dependency findings. Platform Engineering operates the CI/CD pipelines you secure. AI Engineering builds the model integrations you govern on the security side, while the Governance, Risk & Compliance team owns AI use governance, meaning acceptable use, model inventory, and third‑party model data‑egress scoping, as the companion to your security accountability.

Setting and holding clear service expectations across these partners is part of the role.

Requirements
  • A minimum of 8 years application or product security.
  • A minimum of 3 years leading a team with function‑level accountability.
  • Demonstrated AI and ML security ownership at production scale, including model and agent security, prompt‑injection and tool‑use risk, and data‑egress control for third‑party model providers, with working fluency in the OWASP LLM Top 10, MITRE ATLAS, and AI…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary