AI Security Engineer
2 days ago
Chicago
The Aspen Group (TAG) is one of the largest and most trusted retail healthcare business support organizations in the U.S. and has supported over 20,000 healthcare professionals and team members with close to 1,500 health and wellness offices across 48 states in four distinct categories: dental care, urgent care, medical aesthetics, and animal health. Working in partnership with independent practice owners and clinicians, the team is united with a single purpose: to prove that healthcare can be better and smarter for everyone. TAG provides a comprehensive suite of centralized business support services that power the impact of five consumer-facing businesses: Aspen Dental, ClearChoice Dental Implant Centers, WellNow Urgent Care, Chapter Aesthetic Studio, and Lovet. Each brand has access to a deep community of experts, tools and resources to grow their practices, and an unwavering commitment to delivering high-quality consumer healthcare experiences at scale. As a reflection of our current needs and planned growth we are very pleased to offer a new opportunity to join our dedicated team as a AI Security Engineer. Job Overview: An AI security engineer designs and implements security controls for AI systems, protecting models, data, and infrastructure from threats like adversarial attacks and prompt injection. Key responsibilities include performing technical security assessments, developing AI-specific defenses, integrating security into the AI/ML lifecycle, and creating automated security tools for tasks like threat detection and compliance. This role requires a combination of cybersecurity fundamentals and AI-specific knowledge, including secure coding for AI and understanding AI-related vulnerabilities. Essential Job Duties • Collaboratively develop agent RBAC (role-based access control) to ensure AI agents operate under permissions aligned to firm roles, enforcing least-privilege access, • Design integrations for AI systems with corporate IAM/SSO (Entra, Okta, etc.) to manage persona- and role-based access across the enterprise, • Design Data Loss Prevention (DLP) and redaction pipelines to prevent confidential, regulated, or proprietary data from being sent to external LLM endpoints, • Provide technical advice, direction, and hands-on support to design and develop safe, compliant, and resilient AI workflows, • Evaluate existing and proposed AI/ML architectures for bias, fairness, drift, hallucination, and security risks; recommend controls aligned with NIST AI RMF, EU AI Act, ISO/IEC 42001, CIS, • Collaborate with Information Security, Cloud, Governance, and Engineering teams to implement standardized AI safety and compliance practices, • Actively contribute to the development of AI security standards, playbooks, and architectural patterns, • Automate guardrails, compliance checks, and AI gateway protections for scale and efficiency, • Build and maintain initiative-level artifacts, including AI policy-as-code configs (YAML), architectural diagrams, and risk assessments, • Monitor, log, and audit AI activity for policy violations, compliance tracking, and security event correlation. YAML-based guardrails, architectural diagrams, and AI risk assessments, • Design and build systems to detect and prevent AI abuse, such as anti-abuse agents., • Perform technical security assessments, code reviews, and penetration testing on AI products and systems., • Integrate security controls throughout the AI/ML lifecycle, from data handling and model training to deployment and monitoring., • Develop and implement AI-driven automation for tasks like real-time alert enrichment, log analysis, and incident triage using tools like Security Copilot and other AI-assisted platforms., • Research and reproduce vulnerabilities in AI systems, develop mitigation strategies, and work with engineering teams to improve security., • Contribute to creating and implementing governance policies, security standards, and privacy frameworks for AI systems., • Develop AI-specific incident response plans and playbooks., • Stay up-to-date on emerging AI security threats, such as adversarial attacks, prompt injection, and data leakage. Skills and Experience • At least 5+ years’ experience in cybersecurity, including compliance and risk management with a system and network security engineering background., • Strong background in traditional cybersecurity, including networking, web-based protocols, and security systems., • Experience in secure software development, including secure coding for AI-powered applications., • Familiarity with AI concepts, machine learning, and the AI/ML lifecycle., • Experience with implementing security controls like encryption, access controls, and authentication for AI systems., • Experience with security tools and platforms like Chronicle & Orca/Wiz, and familiarity with concepts like SAST/DAST., • Excellent problem-solving, communication, and leadership skills., • Experience with dynamic and static analysis tools., • Track record of acting with integrity, taking pride in work, seeking to excel, being curious and adaptable, and communicating effectively. Additional Qualifications • Experience with applications hosted in Google Cloud Platform (GCP), Amazon Web Services (AWS) or Microsoft Azure., • Experience with cryptography controls and measures to secure applications and data. Proficiency with scripting in Python, JavaScript, PowerShell, PHP or Ruby., • Proficiency with Terraform, Python, and cloud automation, • Prior experience in cloud security, data protection, and SIEM/logging for AI traffic, • Experience with one or more of the following: ISO 27001, NIST, PCI Data Security Standard (PCI DSS), HIPAA, Health Information Technology for Economic and Clinical Health (HITECH) Act, SOX, the General Data Protection Regulation (GDPR), Center for Internet Security (CIS) standards or Service Organization Controls (SOC) 2., • Working knowledge of Windows, Linux and Unix., • Familiarity with state privacy laws., • Highly trustworthy; leads by example. Education Requirements • Bachelor’s degree in computer science, information assurance, MIS or related field, or equivalent. Experience Requirements • 5-7+ years of related experience required Certification Requirements • SANS certifications (GWAPT) and others; CISSP (preferred, or CSSLP), OSCP (and related) Annual Salary Range: $130,000-$150,000/year, with a generous benefits package that includes paid time off, health, dental, vision, and 401(k) savings plan with match. If you are an applicant residing in California, please view our privacy policy here: