Suki is a healthcare technology company focused on making technology invisible and assistive for clinicians. They are seeking a Cloud & AI Security Engineer to secure their enterprise cloud infrastructure and AI/ML product capabilities, while ensuring compliance with healthcare regulations.
Responsibilities:
- Manage large security projects, proactively enhance system defenses, and ensure compliance with regulations like HIPAA and the HITRUST r2 CSF
- Develop robust and secure code for security tooling, automation, and critical integrations to improve our security posture
- Drive adoption and integration of Suki’s paved path security solutions across all business units
- Partner with cross-departmental leaders in Suki to reduce the friction, increase speed-to-market and deliver secure-by-design products
- Conduct security assessments and red-teaming on proprietary and third-party AI/ML models, LLMs, and data pipelines (testing for prompt injection, data poisoning, training data extraction, and model inversion)
- Implement guardrails to prevent PHI exposure in model training, vector databases, RAG architectures, and fine-tuning datasets
- Own the technical security architecture across our multi-cloud footprint (AWS / GCP / Azure), ensuring zero-trust principles and robust Cloud Security Posture Management (CSPM)
- Secure Kubernetes clusters, container registries, and Infrastructure-as-Code (Terraform / CloudFormation) within CI/CD deployment pipelines
- Design and enforce least-privilege IAM policies, role-based access controls (RBAC), just-in-time (JIT) provisioning, and secrets management across cloud environments
- Design and enforce microsegmentation, VPC architecture, SASE/VPN solutions, and strict network isolation for multi-tenant health data architectures
- Manage network security controls, intrusion detection/prevention systems (IDS/IPS), and Web Application Firewalls (WAF) to prevent unauthorized data exfiltration
- Proven track record in cloud network design, VPC routing, cloud firewalls, Zero Trust Network Access (ZTNA), and egress control
Requirements:
- 7+ years in Information Security, with 1+ years evaluating and remediating AI risk
- Hands-on experience securing AWS, GCP, or Azure environments using automated tools and native security services
- Strong coding skills for developing secure tooling, automation, including leveraging agentic AI
- Deep understanding of healthcare compliance standards and security protocols, including HIPAA / HITECH, HITRUST CSF, and NIST including a foundational understanding of NIST AI RMF in a cloud environment (GCP preferred)
- Demonstrated leadership ability with experience managing security projects and mentoring junior team members
- Excellent communication and collaboration skills to lead technical discussions