Scanhealthplan

Scanhealthplan

AI Security Engineer (GRC)

Remote, US · Contract

Sponsorship not specified$125k-$216kDetected 27 days ago
Code ReviewGitSQLSnowflakeAzureOAuthMachine LearningData ScienceNLPLLMsRAGAgentic AIAI OrchestrationCybersecurityNetwork SecuritySIEMSOARComplianceSupply ChainCadenceFirewallHIPAACommunication

About the role

  • Today, SCAN is a nonprofit health organization serving more than 500,000 people across Arizona, California, Nevada, New Mexico, Texas, and Washington, with over $8 billion in annual revenue.
  • Our work spans Medicare Advantage, fully integrated care models, primary care, care for the most medically and socially complex populations, and next-generation care delivery models.
  • The Job The AI Security Engineer (GRC) serves as the organization's dedicated subject matter expert at the intersection of artificial intelligence and cybersecurity within a regulated healthcare environment.

Responsibilities

  • Each of us has a responsibility to drive Equality in our communities and workplaces.

Requirements

  • 7+ years of progressive experience in information security, with a minimum of 2 years focused on AI/ML security or applied AI technology evaluation
  • Demonstrated hands-on experience with one or more of the following: Copilot Studio, Azure AI Foundry, Claude / Anthropic APIs, OpenAI API, GitHub Copilot, or LLM agentic frameworks (LangChain, AutoGen, Semantic Kernel)
  • Proven track record conducting vendor risk assessments and producing executive-level risk documentation
  • Familiarity with AI red-teaming methodologies and tools (Garak, PyRIT, PromptBench)
  • Knowledge of OWASP Top 10 for LLM Applications
  • Ability to audit and secure Model Context Protocol (MCP) server implementations including:
  • Experience securing AI CLIs including credential storage, environment variable exposure, and shell integration risks
  • Knowledge of agentic permission models - understanding when AI agents should require human-in-the-loop approval
  • Ability to evaluate multi-step AI workflow chains for unintended capability escalation
  • Experience with HITRUST CSF controls relevant to AI and cloud-based processing of ePHI

Nice to have

  • Prompt injection and jailbreak scenarios
  • Data exfiltration through agentic tool chains
  • Participate in AI governance committee meetings and contribute AI security perspectives to organizational AI policies
  • Security Integration Reviews
  • Review AI integration architectures for network segmentation, data flow, and trust boundary enforcement
  • Assess retrieval-augmented generation (RAG) architectures for unauthorized data access and embedding extraction risks
  • Evaluate agentic AI workflows and multi-agent orchestration systems for privilege escalation and uncontrolled action chains
  • Training, Awareness & Policy

Skills

  • AI Vendor & Technology Evaluation
  • Evaluate vendor data handling practices, model training transparency and data residency
  • Microsoft Copilot Studio - plugin trust boundaries, connector authentication, Power Platform DLP policies
  • Azure AI Foundry - model deployment pipelines, private endpoint configuration, managed identity usage
  • Claude Code & Anthropic APIs - system prompt injection risks, tool use / agentic permissions, data retention settings
  • GitHub Copilot, Cursor, and other AI-assisted development tools - code telemetry and secret leakage exposure
  • Produce written Vendor Security Assessment Reports (VSARs) including risk ratings, compensating controls, and recommendations
  • Secure AI Implementation Guidance for Development Teams
  • Serve as the embedded security advisor to software engineering, data science, and clinical informatics teams adopting AI tooling
  • Define and enforce secure-by-default configurations for AI development environments and agentic systems
  • Tool definitions follow least-privilege principles - no excessive file system, network, or shell access
  • Server authentication uses OAuth 2.0 / mTLS and does not rely on static API keys stored in plaintext

Compensation

  • An annual employee bonus program
  • 11 paid holidays per year, 1 floating holiday, birthday off, and 2 volunteer days
  • $125,400 to $215,975
  • We are committed to creating a workforce that reflects our community through inclusive programs and initiatives such as equal pay, employee resource groups, inclusive benefits, and more.
  • The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant.

Benefits

  • Robust Wellness Program
  • Generous paid-time-off (PTO)
  • Excellent 401(k) Retirement Saving Plan with employer match
  • Tuition reimbursement

Company info

  • Founded in 1977 as the

Equal opportunity

  • Employer/Protected Veterans/Individuals with Disabilities
  • The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant.
  • However, employ
  • SCAN is proud to be an Equal Employment Opportunity and Affirmative Action workplace.

This listing is sourced directly from Scanhealthplan's careers page and normalized into a canonical job model.