Talent.com
Employer Direct Healthcare
Director, Application & AI SecurityEmployer Direct Healthcare • Dallas, TX, United States
Director, Application & AI Security

Director, Application & AI Security

Employer Direct Healthcare • Dallas, TX, United States
4 hours ago
Job type
  • Full-time
Job description

Director, Application & AI Security

Lantern is the specialty care platform connecting people with the best care when they need it most. By curating a Network of Excellence comprised of the nation's top specialists for surgery, cancer care, infusions and more, Lantern delivers excellent care with significant cost savings to employers and their workforces. Lantern also pairs members with a dedicated care team, including Care Advocates and nurses, for the entirety of their care journey, helping them get back to good health, back to their families and back to work. With convenient access to specialists nationwide, Lantern means quality care is within driving distance for most. Lantern is trusted by the nation's largest employers to deliver care to more than 6 million members across the country.

Lantern is the specialty care platform, connecting people with high-quality, affordable specialty care close to home. We operate in a regulated healthcare environment (HIPAA, HITRUST, SOC 2), we handle protected health information at scale, and we are becoming an AI healthcare company, with AI adoption a top company priority. The Director, Application & AI Security owns application and AI security end to end: the security of the software and the AI systems Lantern builds. It is the seat most directly tied to our AI strategy. The job is to make it safe to move fast, building the golden paths and secure defaults that let teams ship product and adopt AI without waiting in a permission queue, while keeping PHI and external-model data egress genuinely protected. You will lead a growing function. At hire, the team includes a senior application security engineer, with several open roles to fill across security architecture, AI/ML security, DevSecOps, and product security. You will build that team and set the secure-design standards the whole engineering organization builds against. Our security philosophy is open by default, secure by design. Security exists to help the business move fast, safely, and the default answer is "yes, safely," because guardrails are built into the platform, pipelines, and tooling rather than enforced by someone saying no. Gates exist only where risk genuinely warrants them, and even then they are automated, fast, and transparent. Location: Hybrid - at least 3 days/wk in our Dallas, TX office

Responsibilities:

  • Own application security across the development lifecycle, covering static, dynamic, and interactive analysis (SAST/DAST/SCA/IAST), code and dependency security, API security, and runtime protections such as WAF and API gateways, all delivered through engineering teams rather than filed as findings.
  • Own AI and ML security, including model and agent security, prompt-injection and tool-use risk, and data-egress controls for third-party model providers, plus continuous AI security posture management informed by the OWASP LLM Top 10, MITRE ATLAS, and AI risk-management standards (NIST AI RMF, ISO/IEC 42001).
  • Own security architecture and threat modeling, including secure-by-design review and ownership of cryptographic standards.
  • Own DevSecOps and pipeline security, with scanning as a default in CI/CD and MLOps/LLMOps pipelines, release gating calibrated to risk, and software supply chain and SBOM practice.
  • Own the security-review intake as a single front door with risk-based triage, reported against a turnaround commitment, so security accelerates the business rather than bottlenecking it.
  • Own the application and AI security tool stack and the secure-design standards behind it.

Key Deliverables in Your First Year:

  • An AI golden path: an approved-model catalog and automated data-egress controls, so teams adopt AI on a governed route instead of case-by-case approvals.
  • A secure SDLC paved road, with scanning in the pipeline by default and critical findings resolved within SLA.
  • A single security-review intake that delivers fast, risk-based answers on a published turnaround.
  • A built-out team, with the open roles filled and performing.

How You Will Work:

Much of this scope is delivered in partnership. Engineering carries remediation on application, API, and dependency findings. Platform Engineering operates the CI/CD pipelines you secure. AI Engineering builds the model integrations you govern on the security side, while the Governance, Risk & Compliance team owns AI use governance, meaning acceptable use, model inventory, and third-party model data-egress scoping, as the companion to your security accountability. Setting and holding clear service expectations across these partners is part of the role.

Requirements:

  • A minimum of 8 years application or product security.
  • A minimum of 3 years leading a team with function-level accountability.
  • Demonstrated AI and ML security ownership at production scale, including model and agent security, prompt-injection and tool-use risk, and data-egress control for third-party model providers, with working fluency in the OWASP LLM Top 10, MITRE ATLAS, and AI risk-management standards (NIST AI RMF, ISO/IEC 42001).
  • Secure SDLC leadership across static, dynamic, and interactive analysis (SAST/DAST/SCA/IAST), dependency and software supply-chain risk, SBOM practice, and remediation delivered through engineering teams.
  • Security architecture and threat-modeling depth, with the standing to review a design and be heard by senior engineers.
  • DevSecOps and pipeline security experience, including scanning as a default in CI/CD, risk-calibrated release gating, and pipeline secret handling.
  • API security experience on a platform handling regulated data.
  • A track record of delivering security as paved roads and secure defaults rather than review gates, with evidence of adoption.
  • Bachelor's degree in a relevant field, or equivalent professional experience.

Strong Candidates Will:

  • Healthcare or another regulated domain where PHI or comparable data flows through AI systems.
  • Experience standing up an AI golden path, including an approved-model catalog, a governed adoption route, and automated egress controls.
  • Experience building a single security-review intake with risk-based triage and a turnaround commitment.
  • Cryptographic standards ownership, including customer-managed key models.
  • Hands-on familiarity with tools such as Snyk, GitHub Advanced Security, AI security posture management (for example, Wiz), and AI-assisted code scanning.
  • Familiarity with AI red-teaming and adversarial-testing tooling (for example, Garak, PyRIT, Promptfoo).
  • Product security experience shipping customer-facing security features as differentiators.
  • Experience hiring and building a team from a single senior individual contributor.
  • CSSLP, OSWE, GWAPT, or equivalent.

Who Thrives in This Role:

  • Guardrails over gates. You instinctively ask how to remove a queue rather than how to staff one.
  • Engineering credibility. You earn influence with builders through technical depth, not process authority.
  • Risk calibration. You reserve genuine gates for what earns them, namely PHI exposure, external model egress, and privileged access, and you keep even those automated and fast.
  • Delivery orientation. You treat a roadmap as a commitment with dates.
  • Team building. You can grow a function from one senior IC and a set of open roles.

Benefits:

  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • Short & Long Term Disability
  • Life Insurance
  • 401k with company match
  • Flexible Time Off
  • Paid Parental Leave

About You:

  • You use LOGIC in your decision making and understand that progress is critical to making change. You focus on the execution of your content while balancing a fast-paced environment and you take the time to celebrate both the small & big wins.
  • INCLUSION is a core tenant of your personal beliefs. A diverse and inclusive environment is incredibly important to you. You understand and desire to be a part of a diverse team with different experiences and perspectives & you cherish the differences in each individual that you interact with.
  • You have the GRIT, drive and ambition to tackle big problems. Big problems require big ideas and a team that supports new ideas.
  • You care deeply for your customers are driven to keep HUMANITY in all decisions. Your customers
Create a job alert for this search

Director, Application & AI Security • Dallas, TX, United States

Similar jobs

Artificial Intelligence Sr. Manager/Director

ClifyXDallas, TX, United States
Full-time

Locations: AZ - Phoenix, CO - Denver, TX - Austin, TX - Dallas, TX - Houston.Position: Fulltime travelling position.Minimum 7 years hands on machine learning experience.Minimum 5 years experience w... Show more

 • Promoted

Director Engineering - Sensing Solutions NPI

Honeywell InternationalRichardson, TX, United States
Full-time

Director Engineering - Sensing Solutions NPI.The Director Engineering - Sensing Solutions NPI will be responsible for technology roadmap, strategy development and new product introductions for the ... Show more

 • Promoted

Associate Director for Competitive Intelligence

University of Texas at DallasRichardson, TX, United States
Full-time

Posting DetailsPosting DetailsPosting NumberS06890PPosition TitleAssociate Director for Competitive IntelligenceFunctional TitleAssociate Director for Competitive IntelligenceDepartmentVP Strategic... Show more

 • Promoted

AMD Public-Dallas-Vice President-Security Engineering

Goldman SachsDallas, TX, United States
Full-time

Job DescriptionRole OverviewThe Head of Technology Risk for Asset Management is a critical senior leadership position responsible for defining, implementing, and overseeing the comprehensive inform... Show more

 • Promoted

C&I Application Director

S&CDallas, TX, United States
Full-time

Job DescriptionAs an S&C Electric team member, you'll work on projects that have real-world impact.You'll help transform the grid for resilient and reliable power worldwide.S&C has more tha... Show more

 • Promoted

Cloud Security Manager Azure Infrastructure & AI

DeloitteDallas, TX, United States
Full-time

Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity.Join our team to deliver powerful solutions to help our clients navigate the ever-changi... Show more

 • Promoted

Agentic AI Delivery Leader

AscensusDallas, TX, United States
Full-time

Senior Manager, Agentic AI Delivery.Ascensus is the leading independent technology and service platform powering savings plans across America, providing products and expertise that help nearly 16 m... Show more

 • Promoted

Lead Enterprise Endpoint Security Architect - Remote

PrattwhitneyRichardson, TX, United States
Remote
Full-time

A leading aerospace and defense firm is seeking a Principal Enterprise Endpoint Security Portfolio Architect to define and manage endpoint security strategies.The ideal candidate will have deep tec... Show more

 • Promoted

Security Manager Sr - Application Security Program Leader

PNCDallas, TX, United States
Full-time +1

Position OverviewAt PNC, our people are our greatest differentiator and competitive advantage in the markets we serve.We are all united in delivering the best experience for our customers.We work t... Show more

 • Promoted

Senior Director of Channel Sales, AI cybersecurity, Remote

Planet Green SearchDallas, TX, United States
Remote
Full-time

Senior Director of Channel Sales, AI Cybersecurity, Remote.We are a fast-growing, venture-backed cybersecurity company building the next-generation autonomous data security platform.Our solution au... Show more

 • Promoted

Cloud Security Architect + PM

IntersourcesFrisco, TX, United States
Full-time

Certified Diverse Supplier, was founded in 2007 and offers innovative solutions to help clients with Digital Transformations across various domains and industries.Our history spans over 16 years an... Show more

 • Promoted

Senior Manager, Participant Security ISO Lead

Capital onePlano, TX, United States
Full-time +1

Senior Manager, Participant Security ISO LeadAt Capital One, you will help consult on initiatives, programs, and projects to raise their game in Information Security.You are pragmatic and practical... Show more

 • Promoted

Application Security Engineer (Web3)Remote (Worldwide)

Institute of Free TechnologyDallas, TX, United States
Remote
Full-time

Application Security Engineer Vac builds public good protocols for the decentralised web.We do applied research based on which we build protocols, libraries and publications.Vac's R&D Service U... Show more

 • Promoted

Director, Machine Learning Engineering

GEICODallas, TX, United States
Full-time

Director Runtime Intelligence & Personalization.We are seeking a strategic and execution-oriented Director to lead our Runtime Intelligence & Personalization function.This leader will own the visi... Show more

 • Promoted

Director of DevOps, IT, and Security

ZippyDallas, TX, United States
Full-time

Director Of DevOps, It, And Security.Zippy was founded with one mission: to make getting a loan for a manufactured home simple, fast, and fully online.We believe modern manufactured homes are affor... Show more

 • Promoted

VP, Global Head of Product Security and Risk

CircleDallas, TX, United States
Full-time

VP, Global Head Of Product Security & Risk.Circle is building the next generation of global financial infrastructure through programmable money, blockchain-based payments, and cloud-native APIs.As ... Show more

 • Promoted

Director of eDiscovery

Contact Government ServicesDallas, TX, United States
Full-time

Employment Type: Full Time, Executive Level.Department: eDiscovery and Litigation.Contact Government Services is seeking an experienced and motivated Director of eDiscovery for one of our large gov... Show more

 • Promoted

Sr Director/AVP

E-SolutionsDallas, TX, United States
Full-time

Location: US (Dallas, Chicago, Princeton, US -Remote).I dont want to be constrained on location for the right resource as he/she needs to travel.Full time role Primary skill Data and Analytics Sol... Show more

 • Promoted

VP, AI Compliance Officer

Morgan StanleyDallas, TX, United States
Full-time

Vice President, Artificial Intelligence Compliance Officer in Wealth Management Compliance.We're seeking someone to join our team as a Vice President, Artificial Intelligence Compliance Officer in ... Show more

 • Promoted

Senior Director Security

MavenirRichardson, TX, United States
Full-time

Mavenir is building the future of networks and pioneering advanced technology, focusing on the vision of a single, software-based automated network that runs on any cloud.As the industry's only end... Show more