AI Security Engineer (GRC)
Listed on 2026-08-05
-
IT/Tech
AI Engineer (Applied/Software), Cybersecurity, Information Security & Data Protection
AI Security Engineer (GRC)
The AI Security Engineer (GRC) serves as the organization's dedicated subject matter expert at the intersection of artificial intelligence and cybersecurity within a regulated healthcare environment. This role is responsible for evaluating AI vendors and technologies, establishing and enforcing secure AI implementation standards, and providing hands-on guidance to development and engineering teams adopting AI platforms such as Microsoft Copilot Studio, Azure AI Foundry, Snowflake Cortex, Claude Code, and other large language model (LLM)-powered tooling.
Operating within the HIPAA-regulated landscape, this analyst will ensure AI integrations — including Model Context Protocol (MCP) servers, agentic workflows, command-line interfaces (CLIs), APIs, and third-party AI extensions — are architected and deployed in a manner consistent with NIST AI RMF, HITRUST, and organizational security policies. The role acts as a trusted advisor, security gatekeeper, and enabler for responsible AI adoption across the enterprise.
You Will
1. AI Vendor & Technology Evaluation
- Lead structured security assessments of AI vendors, platforms, and tools prior to organizational adoption or renewal
- Evaluate vendor data handling practices, model training transparency and data residency
- Assess the security posture of AI platforms including:
- Microsoft Copilot Studio — plugin trust boundaries, connector authentication, Power Platform DLP policies
- Azure AI Foundry — model deployment pipelines, private endpoint configuration, managed identity usage
- Snowflake Cortex — data access controls in AI-generated SQL, Snowpark security, role-based privilege enforcement, Cortex function access policies, and query result exposure risks
- Claude Code & Anthropic APIs — system prompt injection risks, tool use / agentic permissions, data retention settings
- Git Hub Copilot, Cursor, and other AI-assisted development tools — code telemetry and secret leakage exposure
- Produce written Vendor Security Assessment Reports (VSARs) including risk ratings, compensating controls, and recommendations
- Maintain an AI technology registry with risk classifications and review cadence schedules
2. Secure AI Implementation Guidance for Development Teams
- Serve as the embedded security advisor to software engineering, data science, and clinical informatics teams adopting AI tooling
- Define and enforce secure-by-default configurations for AI development environments and agentic systems
- Review and approve MCP server configurations, ensuring:
- Tool definitions follow least-privilege principles — no excessive file system, network, or shell access
- Server authentication uses OAuth 2.0 / mTLS and does not rely on static API keys stored in plaintext
- Transport layer security (TLS 1.2+) is enforced on all MCP server communications
- Prompt injection attack surfaces are identified and mitigated in tool descriptions and system prompts
- Logging and audit trails are enabled for all MCP tool invocations touching PHI or sensitive data
- Establish CLI security standards for AI-assisted development tools (Claude Code CLI, Git Hub Copilot CLI, Azure Developer CLI), including credential hygiene, shell history scrubbing, and token scope minimization
- Conduct secure code review for AI integration code — with focus on prompt injection, insecure deserialization, and unsafe agentic action chains
- Develop and maintain a library of reference architectures, secure configuration templates, and implementation checklists for approved AI platforms
3. AI Risk Management & Compliance
- Maintain the organization's AI Risk Register aligned with NIST AI RMF (Govern, Map, Measure, Manage)
- Ensure AI deployments comply with HIPAA Security Rule (45 CFR §164), HITECH Act obligations, and applicable state privacy laws
- Conduct AI-specific Threat Modeling (STRIDE / PASTA) and red-team exercises targeting:
- Prompt injection and jailbreak scenarios
- Indirect prompt injection via external data sources (email, documents, web retrieval)
- Model inversion and membership inference attacks on fine-tuned healthcare models
- Data exfiltration through agentic tool chains
- Track emerging AI threats and threat actor TTPs relevant to healthcare…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).