|
Teladoc Health is a global, whole person care company made up of a diverse community of people dedicated to transforming the healthcare experience. As an employee, you're empowered to show up every day as your most authentic self and be a part of something bigger - thriving both personally and professionally. Together, let's empower people everywhere to live their healthiest lives.
Summary of Position The Principal AI Security Engineer is a senior technical leader on the AI Security team, responsible for designing, building, and operating security controls for generative AI and Machine Learning (ML) systems across their full lifecycle: data, training, deployment, and runtime. This role is deeply hands-on: you will work directly with data science, MLOps, platform, devops and application teams to secure LLMs, RAG systems, AI agents, and AI-enabled products. You will also lead the intake and review process for AI use cases, helping the organization adopt AI safely and at scale in a highly regulated environment. The ideal candidate combines: * Strong security engineering and cloud architecture experience * Deep, current familiarity with modern AI/LLM tooling and practices * Familiar and can cover basic coding within the AI tooling space (python, others) * The ability to communicate clearly with senior leadership and influence enterprise wide strategy Essential duties and responsibilities: Secure AI / ML platforms and workloads
- Lead security architecture and threat modeling for AI/ML systems, including LLMs, RAG pipelines, agents, and AI-powered applications.
- Design and implement security controls as code (services, libraries, infrastructure-as-code, policy-as-code) for AI/ML platforms and workloads.
- Lead and help setup the basic infrastructure needed to safely rollout AI - MCPs, LLMs, pipelines, Test harness for AI (ie: harmbench), intake automation.
- Partner with data science and MLOps teams to harden:
- Data ingestion and labeling
- Training and fine-tuning pipelines
- Model registries and deployment workflows
- Inference APIs, agents, and integrations
- Define and champion secure reference architectures and patterns for common AI use cases and focus on composable archiecture.
AI use case intake & governance
- Design, implement, and continuously improve the intake, triage, and review process for AI/ML and generative AI use cases across the organization.
- Build and automate self-service workflows (e.g., request forms, risk questionnaires, routing, approvals) that balance speed of delivery with security, privacy, and compliance with a focus on risk scoring and scorecards.
- Define risk-based criteria for AI use case approval, including data sensitivity, model and vendor selection, integration patterns, and control requirements; this will involve in re-mapping the complete end to end lifecycle.
- Review proposed AI solutions from concept through deployment, providing clear, actionable guidance to product and engineering teams.
- Maintain visibility into the AI use case portfolio and risk posture, and provide regular reporting to leadership and governance bodies.
Monitoring, detection & assurance
- Establish and maintain monitoring and detection for AI-specific threats, such as:
- Prompt injection and jailbreak attempts
- Data exfiltration and sensitive data exposure
- Misuse or abuse of AI tools and agents
- Anomalous model or pipeline behavior
- Integrate AI/ML systems with existing logging, SIEM, and incident response processes.
- Lead or participate in AI-focused security assessments, red-teaming, and adversarial testing; drive remediation and verification.
Strategy, leadership & enablement
- Help define and evolve the organization's AI security strategy, standards, and roadmap in partnership with Security, Engineering, Data, Legal, Privacy, and Risk.
- Translate global privacy, data sovereignty, and regulatory requirements into practical technical controls for AI workloads across multiple cloud environments.
- Prepare and deliver executive-ready briefings and narratives on AI security risks, controls, and progress.
- Mentor other engineers and serve as THE internal subject matter expert on AI/ML security, generative AI, and LLM-based systems.
Minimum Qualifications:
- 7+ years of experience in information security, security engineering, or related fields, including significant time building and securing production systems.
- 3+ years of hands-on experience with AI/ML technologies (such as LLMs, RAG, model training/fine-tuning, MLOps, or AI-powered products), including implementation of security controls or guardrails for these systems.
- Strong programming skills in one or more relevant languages (e.g., Python, TypeScript/JavaScript, Go, or similar), with a track record of contributing to production-grade tools, services, or libraries.
- Deep understanding of cloud security architecture and controls on at least one major cloud platform (AWS, Azure, or GCP), including identity, networking, secrets management, data protection, logging, and monitoring.
- Experience designing and implementing controls in a highly regulated environment; healthcare or financial services preferred.
- Demonstrated ability to lead complex technical initiatives across multiple teams, from problem definition through design, implementation, and adoption.
- Proven ability to communicate complex technical and risk topics clearly to both engineering teams and senior leadership.
Preferred Qualifications:
- Practical experience securing LLM- and genAI-based systems, such as:
- RAG architectures backed by internal data
- AI assistants, copilots, or agents integrated with enterprise tools
- Fine-tuned models and model hosting platforms
- Experience with AI IDE tools
- cursor, windsurfer, others
- Knows the security problems and has practical solutions that balances innovation with innovation.
- Familiarity with AI/ML frameworks and ecosystems (e.g., TensorFlow, PyTorch, Scikit-learn) and/or modern LLM development stacks and IDEs (e.g., API-based LLMs, self-hosted models, AI-enhanced coding tools).
- Experience with:
- Security for data pipelines, feature stores, and model registries
- Detection engineering or SIEM tuning for AI-related events
- Red-teaming or adversarial testing of AI systems
- Evidence of ongoing engagement with AI and security (such as side projects, open-source contributions, lab environments, publications, or conference talks).
- Familiarity with emerging AI security and safety standards and forward-looking industry guidance and horizon reports.
- Relevant certifications (e.g., cloud security, security engineering, or governance) are a plus.
- Strong analytical and problem-solving skills, with the ability to operate effectively in a fast-evolving technical and regulatory landscape.
- High level of integrity and ethical conduct.
Teladoc Health is the global virtual care leader, offering the only comprehensive virtual care solution spanning telehealth, expert medical, and licensed platform services. Teladoc Health serves the world's leading insurers, employers, and health systems and helps millions of people around the world resolve their healthcare needs with confidence.
The base salary range for this position is$165,000 - $185,000. In addition to a base salary, this position is eligible for a performance bonus and benefits (subject to eligibility requirements) listed here:Teladoc Health Benefits 2025.Total compensation is based on several factors including, but not limited to, type of position, location, education level, work experience, and certifications.This information is applicable for all full-time positions. Teladoc Health will not sponsor or transfer employment work visas for this position. Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.
Why Join Teladoc Health?
A New Category in Healthcare: Teladoc Health is transforming the healthcare experience and empowering people everywhere to live healthier lives.
Our Work Truly Matters: Recognized as the world leader in whole-person virtual care, Teladoc Health uses proprietary health signals and personalized interactions to drive better health outcomes across the full continuum of care, at every stage in a person's health journey.
Make an Impact: In more than 175 countries and ranked Best in KLAS for Virtual Care Platforms in 2020, Teladoc Health leverages more than a decade of expertise and data-driven insights to meet the growing virtual care needs of consumers and healthcare professionals.
Focus on PEOPLE: Teladoc Health has been recognized as a top employer by numerous media and professional organizations. Talented, passionate individuals make the difference, in this fast-moving, collaborative, and inspiring environment.
Diversity and Inclusion: At Teladoc Health we believe that personal and professional diversity is the key to innovation. We hire based solely on your strengths and qualifications, and the way in which those strengths can directly contribute to your success in your new position.
Growth and Innovation: We've already made healthcare yet remain on the threshold of very big things. Come grow with us and support our mission to make a tangible difference in the lives of our Members.
As an Equal Opportunity Employer, we never have and never will discriminate against any job candidate or employee due to age, race, religion, color, ethnicity, national origin, gender, gender identity/expression, sexual orientation, membership in an employee organization, medical condition, family history, genetic information, veteran status, marital status, parental status or pregnancy.
Teladoc Health respects your privacy and is committed to maintaining the confidentiality and security of your personal information. In furtherance of your employment relationship with Teladoc Health, we collect personal information responsibly and in accordance with applicable data privacy laws, including but not limited to, the California Consumer Privacy Act (CCPA). Personal information is defined as: Any information or set of information relating to you, including (a) all information that identifies you or could reasonably be used to identify you, and (b) all information that any applicable law treats as personal information. Teladoc Health's Notice of Privacy Practices for U.S. Employees' Personal information is available at this link.
|