Cloud and AI Security Engineer

Suki AI Suki AI · Vertical AI · Suki HQ · Engineering

The Cloud & AI Security Engineer will architect and lead security for enterprise cloud infrastructure, network boundaries, and AI/ML product capabilities in a high-growth healthcare SaaS environment. This role involves managing security projects, developing secure code for tooling and automation, conducting security assessments on AI/ML models and data pipelines, implementing data privacy guardrails, owning cloud security architecture, and securing Kubernetes, IaC, IAM, and network segmentation. The position requires strong coding skills, experience with AI risk assessment, and deep understanding of healthcare compliance standards.

What you'd actually do

  1. Manage large security projects, proactively enhance system defenses, and ensure compliance with regulations like HIPAA and the HITRUST r2 CSF.
  2. Develop robust and secure code for security tooling, automation, and critical integrations to improve our security posture. Drive adoption and integration of Suki’s paved path security solutions across all business units.
  3. Conduct security assessments and red-teaming on proprietary and third-party AI/ML models, LLMs, and data pipelines (testing for prompt injection, data poisoning, training data extraction, and model inversion).
  4. Implement guardrails to prevent PHI exposure in model training, vector databases, RAG architectures, and fine-tuning datasets.
  5. Own the technical security architecture across our multi-cloud footprint (AWS / GCP / Azure), ensuring zero-trust principles and robust Cloud Security Posture Management (CSPM).

Skills

Required

  • 7+ years in Information Security
  • 1+ years evaluating and remediating AI risk
  • Hands-on experience securing AWS, GCP, or Azure environments
  • Strong coding skills for developing secure tooling, automation
  • Deep understanding of healthcare compliance standards and security protocols, including HIPAA / HITECH, HITRUST CSF, and NIST
  • Foundational understanding of NIST AI RMF in a cloud environment
  • Demonstrated leadership ability with experience managing security projects
  • Mentoring junior team members
  • Excellent communication and collaboration skills

Nice to have

  • GCP preferred

What the JD emphasized

  • HIPAA
  • HITRUST r2 CSF
  • PHI
  • AI/ML
  • LLMs
  • vector databases
  • RAG architectures
  • fine-tuning datasets
  • AWS / GCP / Azure
  • zero-trust principles
  • Cloud Security Posture Management (CSPM)
  • Kubernetes
  • Infrastructure-as-Code (Terraform / CloudFormation)
  • CI/CD
  • Identity & Access Management (IAM)
  • Zero Trust Network Access (ZTNA)
  • AI risk
  • agentic AI

Other signals

  • AI/ML product capabilities
  • AI risk management
  • AI/ML models, LLMs, and data pipelines
  • PHI & Data Privacy Governance
  • Cloud Posture & Architecture
  • Container & IaC Security
  • Identity & Access Management (IAM)
  • Zero Trust & Network Segmentation
  • Egress/Ingress Monitoring
  • Network Security Mastery
  • evaluating and remediating AI risk
  • leveraging agentic AI