Назад
Company hidden
10 дней назад

Director, Application & AI Security

200 000 - 275 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
director
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Director, Application & AI Security (AI/Healthcare): Own application, AI, ML, DevSecOps, and security architecture for a regulated healthcare platform handling PHI at scale, with an accent on secure defaults, AI governance, and automated security controls. Focus on building an AI golden path, securing model and agent integrations, embedding SAST/DAST/SCA/IAST into delivery pipelines, and growing the security function.

Location: Hybrid in New York, NY; at least 3 days per week in the NYC office

Salary: $200,000–$275,000 annually, plus an annual bonus

Company

hirify.global is a specialty care platform connecting members with leading specialists while operating in a regulated healthcare environment involving HIPAA, HITRUST, SOC 2, and protected health information.

What you will do

  • Own application security across the software lifecycle, including SAST, DAST, SCA, IAST, API security, dependency security, WAF, and API gateway protections.
  • Lead AI and ML security for models and agents, including prompt-injection, tool-use, and third-party model data-egress risks.
  • Own security architecture, threat modeling, secure-by-design reviews, and cryptographic standards.
  • Secure CI/CD, MLOps, and LLMOps pipelines through automated scanning, risk-based release gating, secrets handling, and SBOM practices.
  • Build a risk-based security-review intake and establish secure-design standards, paved roads, and secure defaults.
  • Build and lead the application and AI security function across architecture, AI/ML security, DevSecOps, and product security.

Requirements

  • At least 8 years of application or product security experience and 3 years leading a team with function-level accountability.
  • Production-scale ownership of AI and ML security, including model and agent security, prompt-injection and tool-use risks, and data-egress controls.
  • Fluency with the OWASP LLM Top 10, MITRE ATLAS, NIST AI RMF, and ISO/IEC 42001.
  • Experience leading secure SDLC, DevSecOps, pipeline security, software supply-chain risk management, SBOM practices, API security, and threat modeling.
  • Experience delivering security through automated paved roads and secure defaults rather than manual review queues.
  • Bachelor’s degree in a relevant field or equivalent professional experience.

Nice to have

  • Healthcare or other regulated-domain experience involving PHI or comparable data in AI systems.
  • Experience creating an AI golden path, approved-model catalog, automated egress controls, and risk-based security-review intake.
  • Cryptographic standards ownership, customer-managed keys, product security, or experience building a team from one senior individual contributor.
  • Familiarity with Snyk, GitHub Advanced Security, Wiz, Garak, PyRIT, Promptfoo, or AI-assisted code scanning.
  • CSSLP, OSWE, GWAPT, or an equivalent certification.

Culture & Benefits

  • Security is delivered through automated guardrails and secure defaults, with gates reserved for genuinely high-risk areas.
  • Close partnership with Engineering, Platform Engineering, AI Engineering, and Governance, Risk & Compliance.
  • Medical, dental, and vision insurance.
  • Short- and long-term disability insurance, life insurance, and a 401(k) with company match.
  • Flexible time off and paid parental leave.

Hiring process

  • Apply to the role and connect with the Talent Acquisition team to discuss the interview process.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →