Lead Security Engineer - Artificial Intelligence

Wellmark Blue Cross Blue Shield
United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Working hours
Regular working hours
Job source

Tech stack

Java (Programming Language) Microsoft Windows Active Directory Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Computing Platforms Audit Trail User Authentication Microsoft Azure Bash Shell Command-Line Interface
+49 more
Cloud Computing Cloud Computing Security Code Generation Encodings Continuous Integration Information Leak Prevention Linux DevOps Hardware Virtualization Identity and Access Management Intrusion Detection and Prevention Intrusion Detection Systems JSON Python (Programming Language) Network Security Linux Security Modules MySQL Open Source Technology Open Web Application Security Windows PowerShell Systems Development Life Cycle Role-Based Access Control Red Hat Enterprise Linux Cloud Services Security Information and Event Management Systems Integration Management of Software Versions Software Vulnerability Management Extensible Markup Language (XML) Data Logging Google Cloud Enterprise Software Applications Cloud Platform System Large Language Models IT Architecture Software Security Model Validation Web Filtering AI Platforms Kubernetes Infrastructure Automation Frameworks Virtual Agents Terraform Network Server GPT Automation Anywhere Devsecops Docker Vmware

Job description

We are seeking a Lead Security Engineer with deep experience securing enterprise systems, cloud platforms, and agent-based AI development environments at scale. This role is hands-on and execution-focused, responsible for defining guardrails around AI workloads across the full lifecycle-development, deployment, training, and inference.

The ideal candidate combines production grade AI engineering with advanced expertise in cloud security, DevSecOps, identity, and governance, enabling organizations to adopt GenAI, Microsoft Agents, and AI-assisted code generation platforms safely and at scale.

This role aligns closely to modern Engineer expectations, with a specialization in AI platform security, and risk-aware AI delivery.

What you will do:

  • Secure corporate AI capabilities used in enterprise applications
  • Establish Best Practices for model implementation, versioning, monitoring and governance for AI Systems on the Enterprise.
  • Design/Implement guardrails for AI code-generation tools used in developer workflows
  • Enable and implement safe AI-assisted development across IDEs, CI/CD pipelines, and local developer environments
  • Support model selection and integrations within the organization (Claude class, GPT-class, and similar platforms)
  • Engineer and secure Microsoft Agents, Copilot-style workflows, and agent-driven automation.
  • Prevent insecure code generation, prompt leakage, and unsafe agent behavior while preserving developer velocity, a. Identify risk-related issues and architect solutions to avoid potential security incidents and business impact.

b. Create architecture policies aligning with industry best practices for cybersecurity and resiliency.

c. Design security for monitoring, logging, IAM, encryption, data protection, detection. and preventive controls.

d. Provide expertise and best practices for implementing cloud security and secured code detection and prevention.

e. Deploy strong identity and access management (IDAM) controls across applications and computing environments.

f. Develop and maintain secure, resilient enterprise-grade cloud processes in tandem with architects and system engineers.

g. Actively monitor, assess, and recommend tactical and strategic initiatives based on new and emerging threats posing risk to cloud computing environments.

h. Align with architects to create secure workloads in AWS, Microsoft Azure and Google Cloud.

i. Advise and design with commercial and open-source security tools and controls.

j. Communicate security posture to cybersecurity leaders, stakeholders, IT and developers.

k. Design for integrated security controls, workflows, data protection, authentication and authorization.

l. Acts as technical architect for Windows, Linux, VMware, Kubernetes, Docker and others used to support business needs.

m. Other duties as assigned.

Requirements

Preferred:

  • Experience with creating/managing AI Agent IDs and MCP servers and integrations
  • Strong proficiency in Python for AI workflows, automation, and orchestration
  • Experience with RAG pipelines, embeddings, APIs, and AI service integration
  • Understanding of AI lifecycle risks
  • Strong experience securing AI workloads on AWS & Azure
  • Experience with Cloud Hardening Best Practices.
  • Strong Infrastructure-as-Code (IaC) for Cloud, preferably Terraform
  • Strong background in application security, cloud security, and IAM
  • Experience embedding security into CI/CD, IaC, and SDLC workflows
  • Automation experience using Python, PowerShell, Bash, and APIs
  • Strong RHEL Linux skills, especially at the command line level.
  • Strong understanding of AI/LLM-specific threats such as prompt injection, data poisoning, model theft, adversarial attacks, sensitive data leakage, etc.
  • Experience implementing AI security controls such as guardrails, content filtering, input/output validation, RBAC for AI systems, secure prompt handling, and AI audit logging
  • Understanding of secure AI architecture and AI governance frameworks
  • Familiarity with:
  • OWASP Top 10 for LLM Applications
  • NIST AI Risk Management Framework
  • Responsible AI and AI compliance practices
  • SIEM, threat detection, and vulnerability management. Previous experience with integrating AI with SIEM systems

Required:

  • Bachelor’s degree or direct and applicable work experience.
  • 7+ years of experience working in architecting of server or network controls in any of the following: DevOps, DevSecOps, Identity and Access Management (IAM), system virtualization, Windows and Linux Security, Cloud Security, Network and Network Security, Active Directory, Java, XML, JSON, Azure, AWS, MySQL, Federation, SSO.
  • Knowledge of compliance and regulatory program requirements, such as HIPAA, ISO 27000, NIST, FISMA, and SOC standards.
  • Experience architecting and designing security solutions at the enterprise level. Strong knowledge of high-scale cloud systems within multiple accounts and how they can be secured using agreed best practices.
  • Experience with DevSecOps and automation in highly scalable environments.
  • Strong analytical and problem-solving skills. A certain degree of creativity, innovation and latitude is required (the ability to think outside the box when faced with challenges).
  • High attention to detail while completing tasks and processes. Ability to prioritize to maximize personal efficiency.
  • Ability to help design solutions for cybersecurity problems.
  • Strong compliance and regulatory-focused customer service orientation with effective verbal and written communication skills working with technical and non-technical personnel, with the ability to address all levels of leadership, business, technical, and non-technical staff.
  • Travel required up to 5%

About the company

Why Wellmark: We are a mutual insurance company owned by our policy holders across Iowa and South Dakota, and we’ve built our reputation on over 80 years’ worth of trust. We are not motivated by profits. We are motivated by the well-being of our friends, family, and neighbors-our members. If you’re passionate about joining an organization working hard to put its members first, to provide best-in-class service, and one that is committed to sustainability and innovation, consider applying today!

Why Wellmark Technology? Wellmark is building innovative, modern solutions using cutting edge technology. We are driving organizational transformation and business strategy by empowering our technology team to innovate new and elegant solutions to enhance the customer experience. Together, we are leaning into the future, owning the outcome, and driving organizational change to transform how we work.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dice.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Addressing active AI incident remediation and broad ecosystem support

Matthew Brady Matthew Brady · WWC Europe 2026

40 sec

Generative pre-trained transformer models powering code completions

lgonta lgonta +1 · WWC 2024

3:47 min

Exploring JSON, CBOR, and JOSE for data serialization

Aaron Russell · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

2:09 min

Securing AI agents against internal and external threat vectors

Julia Kordick Julia Kordick · WWC Europe 2026

51 sec

Assessing GPT-4o performance for pull request feedback

Merrill Lutsky Merrill Lutsky · WWC 2025

Videos

See all

Related articles

See all