Principal Application Security Engineer – AI & Agentic Systems

CVS Health CVS Health · Healthcare · Albany, NY +52 · Innovation and Technology

Principal Application Security Engineer focused on securing AI and agentic systems at CVS Health. Responsibilities include developing security policies, architecting secure designs for LLM-based agents and RAG pipelines, performing security testing, and advising leadership on AI security risks and strategy. Requires extensive experience in application security, AI/ML workloads, and cloud platforms.

What you'd actually do

  1. Lead development and enforcement of application and AI security policies, standards, and guardrails, embedding security-by-design across both traditional and AI-driven systems.
  2. Establish secure design patterns for AI agent frameworks, covering prompt management, tool invocation, memory handling, autonomy boundaries, and escalation controls.
  3. Serve as the principal SME for securing AI-enabled applications and agentic system architectures.
  4. Architect and review secure designs for systems leveraging LLMs/foundation models, autonomous and semi-autonomous agents, RAG pipelines, and tool‑using or decision‑making workflows.
  5. Lead advanced security testing and risk assessments for AI-enabled systems, including threat modeling of agent workflows, abuse/misuse analysis, and secure design reviews of AI pipelines.

Skills

Required

  • Designing, building, and securing large-scale applications and platforms
  • Application security, including threat modeling, secure design, and vulnerability management
  • Programming experience in Python, Java, JavaScript, C#, or Go
  • Developing and securing AI and ML workloads, with recent experience in generative AI and agentic workloads
  • Public cloud platforms (AWS, Azure, and/or GCP) and modern application architectures
  • Containerized, serverless, and microservice-based architectures

Nice to have

  • Hands-on experience securing AI agents, RAG pipelines, and tool-using LLM systems
  • Lead complex security initiatives from concept through enterprise-scale adoption
  • Familiarity with AI governance, responsible AI principles, and emerging AI security standards
  • Experience integrating security controls into CI/CD pipelines for AI and application workloads
  • Strong understanding of compliance frameworks (PCI, HIPAA, NIST, HITRUST, CSA)
  • Experience influencing security strategy beyond a single team, including enterprise or platform-level impact
  • Contributions to security research, open-source projects, or industry communities

What the JD emphasized

  • AI security policies
  • AI agent frameworks
  • AI-specific risks
  • AI-enabled applications
  • agentic system architectures
  • LLMs/foundation models
  • autonomous and semi-autonomous agents
  • RAG pipelines
  • tool‑using or decision‑making workflows
  • agentic environments
  • responsible AI delivery
  • AI security implications
  • emerging AI threats
  • AI-enabled systems
  • AI pipelines
  • AI security tools
  • application or AI systems
  • AI security practices
  • application and AI security roadmap
  • AI adoption
  • securing AI and ML workloads
  • generative AI and agentic workloads
  • securing AI agents
  • RAG pipelines
  • tool-using LLM systems
  • AI governance
  • responsible AI principles
  • AI security standards
  • CI/CD pipelines for AI
  • enterprise or platform-level impact

Other signals

  • Develop and enforce application and AI security policies, standards, and guardrails
  • Establish secure design patterns for AI agent frameworks
  • Serve as the principal SME for securing AI-enabled applications and agentic system architectures
  • Architect and review secure designs for systems leveraging LLMs/foundation models, autonomous and semi-autonomous agents, RAG pipelines, and tool-using or decision-making workflows
  • Lead advanced security testing and risk assessments for AI-enabled systems