AI Security Engineer

University of Washington Medical CenterSeattle, WA
$87,624 - $142,392Hybrid

About The Position

UW Information Technology has an outstanding opportunity for an AI Security Engineer to join their team. Reporting to the Technology Manager, the AI Security Engineer will support the security, governance, and compliance of artificial intelligence (AI) initiatives at the university and its three campuses. The AI Security Engineer exists to secure the university's AI platforms, primarily Purple, built on Cloudforce nebulaONE and hosted in Azure AI Foundry, ensuring that AI services delivered to over 50,000 faculty, staff, and students across three campuses operate within a robust, compliant, and trustworthy security framework.

Requirements

  • Bachelor's Degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a related field, or equivalent combination of education and experience.
  • 3+ years of experience in cloud security engineering, DevSecOps, or infrastructure security with hands-on cloud platform experience.
  • Hands-on experience with Azure security services such as: Defender for Cloud, Sentinel, Entra ID/RBAC, Azure Policy, Key Vault, and network security configurations. Candidates with equivalent depth in AWS or GCP who can demonstrate the ability to ramp on Azure are also encouraged to apply; Azure experience is strongly preferred.
  • Understanding of Zero Trust architecture principles, identity governance, and conditional access.
  • Experience with container or Kubernetes security concepts.
  • Proficiency in Python, PowerShell, or Bash for security automation.
  • Experience with SIEM tools (Azure Sentinel or equivalent) and incident response.
  • Working knowledge of at least two compliance frameworks: FERPA, HIPAA, NIST 800-53/800-171, or SOC 2.
  • Strong written and verbal communication skills with the ability to explain security concepts to both technical

Nice To Haves

  • Microsoft Certified: Cloud and AI Security Engineer Associate
  • SC-100 (Cybersecurity Architect Expert), SC-200 (Security Operations Analyst).
  • HashiCorp Terraform Associate certification.
  • Experience with infrastructure-as-code (Bicep and/or Terraform), including IaC scanning and policy-as-code concepts.
  • Experience embedding security into CI/CD pipelines: SAST, DAST, SCA, or container scanning.
  • CISSP or CISM (note: CISSP requires 5 years experience, which may be aspirational for mid-level candidates).
  • Exposure to AI/ML application security risks: prompt injection defense, RAG data isolation, agent authorization, output filtering.
  • Familiarity with OWASP LLM Top 10, OWASP Top 10 for Agentic Applications, or MITRE ATLAS.
  • Knowledge of AI governance frameworks: NIST AI RMF, NIST Generative AI Profile, ISO/IEC 42001.
  • Experience with the Azure Well-Architected Framework (security pillar) and Microsoft cloud security benchmark.
  • Production multi-tenant SaaS or AI-platform operations experience.
  • Azure cost-management and FinOps awareness.
  • Experience in higher education or public sector IT.
  • Experience with HECVAT, VPAT, and vendor security assessment processes.
  • Familiarity with penetration testing methodologies and tools.
  • Knowledge of Washington My Health My Data Act, GLBA, GDPR.
  • Experience with Agile/Scrum methodologies and tools (Jira, Azure Boards).

Responsibilities

  • Implement and maintain security controls for AI platforms within Microsoft Azure, including network security groups, firewalls, encryption, key management, and secure landing zones aligned with the Azure Well-Architected Framework (security pillar) and the Microsoft cloud security benchmark.
  • Configure and manage identity and access management using Entra ID, RBAC, conditional access policies, and Zero Trust architecture principles across management-group and subscription hierarchies.
  • Implement and maintain infrastructure-as-code (IaC) security using Bicep and/or Terraform, including policy-as-code enforcement (Azure Policy, Sentinel policies) and IaC scanning in CI/CD pipelines.
  • Embed security into CI/CD pipelines (DevSecOps) using GitHub Advanced Security or equivalent, including SAST, DAST, SCA, container image scanning, and auto-remediation workflows.
  • Develop security automation scripts and tools (Python, PowerShell, Bash) to streamline vulnerability scanning, configuration hardening, and compliance evidence collection.
  • Support the security of AI application-layer components specific to Purple and nebulaONE, including RAG data isolation, least-privilege tool/function-call authorization, agent action budgets and rate limits, output filtering, and secrets isolation.
  • Participate in recurring red-team exercises against AI platforms mapped to the OWASP LLM Top 10, the OWASP Top 10 for Agentic Applications, and MITRE ATLAS, documenting findings and supporting remediation.
  • Assess and help mitigate AI-specific security risks including prompt injection, jailbreak attacks, data leakage through model outputs, and adversarial attacks.
  • Support implementation of guardrails for LLM and agent application patterns including RAG, tool/function calling, MCP (Model Context Protocol), and multi-agent orchestration workflows.
  • Apply AI security governance practices aligned with the NIST AI Risk Management Framework (AI RMF), the NIST Generative AI Profile, and ISO/IEC 42001.
  • Produce and maintain compliance evidence (not policy) for FERPA, HIPAA (where PHI is in scope, including areas outside UW Medicine), GLBA, NIST 800-171/CMMC, and SOC 2 as it relates to AI platforms and cloud infrastructure.
  • Support vendor security oversight of Cloudforce and Microsoft, including HECVAT completion/review, VPAT assessment, SOC 2 report analysis, data processing agreement reviews, and security questionnaire management.
  • Monitor AI platform security posture using Azure Sentinel (SIEM), writing and tuning KQL queries for detection rules, alert triage, and threat hunting.
  • Maintain and execute incident response playbooks specific to AI platforms, including data breaches, unauthorized access, prompt injection attacks, model compromise, and agent misuse scenarios.
  • Triage and investigate security incidents, coordinate response activities with UWIT Office of Information Security, and contribute to post-incident reports with root cause analysis.
  • Contribute to 'paved-road' security patterns -- reusable, pre-approved templates and configurations that make the secure path the easy path for developers and administrators.
  • Develop and maintain security documentation, including architecture diagrams, runbooks, standard operating procedures, and incident response playbooks.
  • Evaluate emerging security tools and technologies; make recommendations for adoption.

Benefits

  • For information about benefits for this position, visit https://www.washington.edu/jobs/benefits-for-uw-staff/
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service