Назад
Company hidden
5 часов назад

Director, Application & AI Security (AI)

Формат работы
hybrid
Тип работы
fulltime
Грейд
director
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Director, Application & AI Security (AI): Owning application, AI, and ML security for a regulated healthcare platform with an accent on secure SDLC, AI model and agent security, and protected health information. Focus on building AI golden paths, automated data-egress controls, secure CI/CD and MLOps pipelines, and a growing security function.

Location: Hybrid in Dallas, Texas, with at least 3 days per week in the office

Company

hirify.global is a specialty care platform connecting members with high-quality specialist care while handling protected health information in a regulated healthcare environment.

What you will do

  • Own application security across the development lifecycle, including SAST, DAST, SCA, IAST, dependency security, API security, WAF, and API gateway protections.
  • Lead AI and ML security for models and agents, including prompt-injection, tool-use risks, third-party model data-egress controls, and AI security posture management.
  • Define security architecture, threat-modeling practices, cryptographic standards, and secure-by-design reviews.
  • Secure CI/CD, MLOps, and LLMOps pipelines through default scanning, risk-calibrated release gates, secrets handling, SBOMs, and software supply-chain controls.
  • Establish a single security-review intake with risk-based triage and clear turnaround commitments.
  • Build the application and AI security function, hire for open roles, and set secure-design standards across engineering.

Requirements

  • At least 8 years of application or product security experience.
  • At least 3 years leading a team with function-level accountability.
  • Production-scale ownership of AI and ML security, including model and agent security, prompt-injection and tool-use risks, and third-party model data-egress controls.
  • Experience leading secure SDLC, DevSecOps, pipeline security, API security, threat modeling, dependency risk management, SBOM practices, and software supply-chain security.
  • Ability to deliver security through paved roads and secure defaults while influencing senior engineers and partner teams.
  • Bachelor’s degree in a relevant field or equivalent professional experience.

Nice to have

  • Healthcare or other regulated-domain experience involving PHI or comparable data in AI systems.
  • Experience creating an AI golden path, approved-model catalog, automated egress controls, or a risk-based security-review intake.
  • Ownership of cryptographic standards, including customer-managed key models.
  • Experience with Snyk, GitHub Advanced Security, Wiz, Garak, PyRIT, Promptfoo, or AI-assisted code scanning.
  • Product security experience and certifications such as CSSLP, OSWE, or GWAPT.

Culture & Benefits

  • Security is delivered through automated guardrails, secure defaults, and fast, transparent risk-based gates.
  • Close partnership with Engineering, Platform Engineering, AI Engineering, and Governance, Risk & Compliance.
  • Medical, dental, and vision insurance.
  • Short- and long-term disability insurance, life insurance, and a 401(k) with company match.
  • Flexible time off and paid parental leave.
  • Emphasis on logic, inclusion, grit, humanity, truth, and team collaboration.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →