Founded in 1977 as the Senior Care Action Network, SCAN began with a simple but radical idea: that older adults deserve to stay healthy and independent. That belief was championed by a group of community activists we still honor today as the “12 Angry Seniors.” Their mission continues to guide everything we do.
Today, SCAN is a nonprofit health organization serving more than 500,000 people across Arizona, California, Nevada, New Mexico, Texas, and Washington, with over $8 billion in annual revenue. With nearly five decades of experience, we have built a distinctive, values-driven platform dedicated to improving care for older adults.
Our work spans Medicare Advantage, fully integrated care models, primary care, care for the most medically and socially complex populations, and next-generation care delivery models. Across all of this, we are united by a shared commitment: combining compassion with discipline, innovation with stewardship, and growth with integrity.
At SCAN, we believe scale should strengthen—not dilute—our mission. We are building the future of care for older adults, grounded in purpose, accountability, and respect for the people and communities we serve.
The Job:
We are seeking a visionary Principal AI Security Engineer to serve as the primary architect and guardian of our Artificial Intelligence ecosystem. Reporting directly to the Director of Cybersecurity, you will be responsible for the end-to-end security of our AI architectures, ensuring that innovation never comes at the expense of integrity.
This is a high-impact, "player-coach" role. You will provide strategic governance and framework development while remaining deeply hands-on with enterprise AI configurations, specifically within the Azure AI stack. From securing Model Context Protocol (MCP) implementations to building robust guardrails in Azure AI Foundry, you will be the technical authority ensuring our AI identities and data workflows are impenetrable.
Key Responsibilities:
1. AI Security Architecture & Engineering
-
End-to-End Security: Design and implement secure-by-design architectures for the entire AI lifecycle, including data ingestion, model training, fine-tuning, and inference.
-
Azure AI Specialist: Lead the security configuration for Azure OpenAI Studio, Azure AI Foundry, and Azure AI Search, ensuring enterprise-grade protection.
-
Hands-on Implementation: Develop and deploy security controls, including prompt injection mitigations, rate limiting, and content filtering.
-
MCP Integration: Securely implement and oversee Model Context Protocol (MCP) to facilitate safe communication between AI models and local/remote data sources.
2. Governance & Compliance
-
Framework Ownership: Establish and maintain AI security standards based on global frameworks (e.g., NIST AI RMF, ISO/IEC 42001, OWASP Top 10 for LLMs).
-
Policy Development: Draft enterprise-wide policies for responsible AI usage, data privacy, and model risk management.
-
Identity & Data Security: Architect sophisticated identity management for AI agents (Workload Identities) and ensure data-at-rest/motion is encrypted and permissioned via Azure RBAC and Entra ID.
3. Guardrails & Monitoring
-
Control Building: Build automated guardrails to prevent data leakage and ensure model outputs remain within ethical and legal boundaries.
-
Threat Modeling: Conduct AI-specific threat modeling and red-teaming exercises to identify vulnerabilities in RAG (Retrieval-Augmented Generation) patterns.
-
Observability: Partner with the SOC to develop monitoring dashboards for AI-related anomalies and security events.
Required Qualifications:
-
Experience: 10+ years in Cybersecurity, with at least 3+ years focused specifically on AI/ML Security.
-
Azure Expertise: Proven track record securing Azure OpenAI, Azure AI Search, and Azure Foundry.
-
Technical Depth: Deep understanding of LLM vulnerabilities (Prompt Injection, Insecure Output Handling, Training Data Poisoning).
-
Data Security: Expertise in securing data workflows for AI, including vector database security and sensitive data masking.
-
Governance: Extensive knowledge of AI Governance frameworks and the regulatory landscape (EU AI Act, etc.).
Technical Skills & Tools:
-
Platforms: Azure AI Studio, Azure Machine Learning, Azure Kubernetes Service (AKS).
-
AI Protocols: Experience with Model Context Protocol (MCP) and API security (REST, gRPC).
-
Languages: Proficiency in Python and PowerShell/Bash for automation and security tooling.
-
Identity: Expert-level knowledge of Azure Entra ID (formerly Azure AD) and Managed Identities for AI workloads.
What's in it for you?
Base salary range: $125,400 to $181,419 annually
An annual employee bonus program
Robust Wellness Program
Generous paid-time-off (PTO)
11 paid holidays per year, 1 floating holiday, birthday off, and 2 volunteer days
Excellent 401(k) Retirement Saving Plan with employer match
Robust employee recognition program
Tuition reimbursement
An opportunity to become part of a team that makes a difference to our members and our community every day!
We're always looking for talented people to join our team! Qualified applicants are encouraged to apply now!
At SCAN we believe that it is our business to improve the state of our world. Each of us has a responsibility to drive Equality in our communities and workplaces. We are committed to creating a workforce that reflects our community through inclusive programs and initiatives such as equal pay, employee resource groups, inclusive benefits, and more.
SCAN is proud to be an Equal Employment Opportunity and Affirmative Action workplace. Individuals seeking employment will receive consideration for employment without regard to race, color, national origin, religion, age, sex (including pregnancy, childbirth or related medical conditions), sexual orientation, gender perception or identity, age, marital status, disability, protected veteran status or any other status protected by law. A background check is required.
#LI-JB1 #LI-Hybrid
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor’s legal duty to furnish information. 41 CFR 60-1.35(c)