About the role
Founded in 1977 as the Senior Care Action Network, SCAN began with a simple but radical idea: that older adults deserve to stay healthy and independent.
Today, SCAN is a nonprofit health organization serving more than 500,000 people across Arizona, California, Nevada, New Mexico, Texas, and Washington, with over $8 billion in annual revenue.
The Job: The AI Security Engineer (GRC) serves as the organization's dedicated subject matter expert at the intersection of artificial intelligence and cybersecurity within a regulated healthcare environment. This role is responsible for evaluating AI vendors and technologies, establishing and enforcing secure AI implementation standards, and providing hands-on guidance to development and engineering teams adopting AI platforms such as Microsoft Copilot Studio, Azure AI Foundry, Snowflake Cortex, Claude Code, and other large language model (LLM)-powered tooling.
Operating within the HIPAA-regulated landscape, this analyst will ensure AI integrations — including Model Context Protocol (MCP) servers, agentic workflows, command-line interfaces (CLIs), APIs, and third-party AI extensions — are architected and deployed in a manner consistent with NIST AI RMF, HITRUST, and organizational security policies.
You Will:
1. AI Vendor & Technology Evaluation – Lead structured security assessments of AI vendors, platforms, and tools prior to organizational adoption or renewal. Evaluate vendor data handling practices, model training transparency and data residency. Produce written Vendor Security Assessment Reports (VSARs).
1. Secure AI Implementation Guidance for Development Teams – Serve as the embedded security advisor to software engineering, data science, and clinical informatics teams adopting AI tooling. Review and approve MCP server configurations. Establish CLI security standards for AI-assisted development tools.
1. AI Risk Management & Compliance – Maintain the organization's AI Risk Register aligned with NIST AI RMF. Ensure AI deployments comply with HIPAA Security Rule, HITECH Act obligations, and applicable state privacy laws. Conduct AI-specific Threat Modeling (STRIDE / PASTA).
1. Security Integration Reviews – Review AI integration architectures for network segmentation, data flow, and trust boundary enforcement. Validate that PHI is never transmitted to external AI models without de-identification or explicit BAA coverage.
1. Training, Awareness & Policy – Develop AI security training curricula for developers, data engineers, clinical staff, and IT personnel. Author and maintain AI security policies.
Your Qualifications:
Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or a closely related field; Master's degree preferred
7+ years of progressive experience in information security, with a minimum of 2 years focused on AI/ML security or applied AI technology evaluation
Demonstrated hands-on experience with Copilot Studio, Azure AI Foundry, Claude / Anthropic APIs, OpenAI API, GitHub Copilot, or LLM agentic frameworks
Experience working in a HIPAA-regulated environment; healthcare industry background strongly preferred
Deep understanding of LLM attack surface: prompt injection, indirect prompt injection, system prompt extraction, and model manipulation
Knowledge of OWASP Top 10 for LLM Applications
Thorough understanding of HIPAA Security Rule requirements
Practical knowledge of NIST AI Risk Management Framework (AI RMF)
Base Salary Range: $172,780 to $225,720 annually
#LI-JB1 #LI-Remote
Minimum requirements
- Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or related field; Master's preferred
- 7+ years in information security, including 2+ years in AI/ML security or AI technology evaluation
- Experience with AI platforms (Copilot Studio, Azure AI Foundry, Anthropic APIs), HIPAA compliance, and NIST AI RMF knowledge
This listing was parsed by AI and may not be complete. Check the official posting on SCAN's site for the most accurate information.