671,804open jobs
39,060companies
102,874added this week
Browse all
Salary
$200k – $275k per year
Location
Remote/Hybrid (New York, United States)
Seniority
Architect · 8+ years exp
Overview
Company
Impact
Profile match
Carrum Health is a California company founded in 2014 that connects employers with centres of excellence for surgery and cancer care. Its platform bundles payments and steers patients to high-quality providers. The company works with large self-insured employers.

About Lantern

Lantern is the specialty care platform connecting people with the best care when they need it most. By curating a Network of Excellence comprised of the nation's top specialists for surgery, cancer care, infusions and more, Lantern delivers excellent care with significant cost savings to employers and their workforces. Lantern also pairs members with a dedicated care team, including Care Advocates and nurses, for the entirety of their care journey, helping them get back to good health, back to their families and back to work. With convenient access to specialists nationwide, Lantern means quality care is within driving distance for most. Lantern is trusted by the nation's largest employers to deliver care to more than 6 million members across the country. Learn more about us at lanterncare.com. 

Lantern is the specialty care platform, connecting people with high-quality, affordable specialty care close to home. We operate in a regulated healthcare environment (HIPAA, HITRUST, SOC 2), we handle protected health information at scale, and we are becoming an AI healthcare company, with AI adoption a top company priority.

The Director, Application & AI Security owns application and AI security end to end: the security of the software and the AI systems Lantern builds. It is the seat most directly tied to our AI strategy. The job is to make it safe to move fast, building the golden paths and secure defaults that let teams ship product and adopt AI without waiting in a permission queue, while keeping PHI and external-model data egress genuinely protected.

You will lead a growing function. At hire, the team includes a senior application security engineer, with several open roles to fill across security architecture, AI/ML security, DevSecOps, and product security. You will build that team and set the secure-design standards the whole engineering organization builds against.

Our security philosophy is open by default, secure by design. Security exists to help the business move fast, safely, and the default answer is “yes, safely,” because guardrails are built into the platform, pipelines, and tooling rather than enforced by someone saying no. Gates exist only where risk genuinely warrants them, and even then they are automated, fast, and transparent.

Location: Hybrid - at least 3 days/wk in our NYC, NY offices

Responsibilities:

  • Own application security across the development lifecycle, covering static, dynamic, and interactive analysis (SAST/DAST/SCA/IAST), code and dependency security, API security, and runtime protections such as WAF and API gateways, all delivered through engineering teams rather than filed as findings.
  • Own AI and ML security, including model and agent security, prompt-injection and tool-use risk, and data-egress controls for third-party model providers, plus continuous AI security posture management informed by the OWASP LLM Top 10, MITRE ATLAS, and AI risk-management standards (NIST AI RMF, ISO/IEC 42001).
  • Own security architecture and threat modeling, including secure-by-design review and ownership of cryptographic standards.
  • Own DevSecOps and pipeline security, with scanning as a default in CI/CD and MLOps/LLMOps pipelines, release gating calibrated to risk, and software supply chain and SBOM practice.
  • Own the security-review intake as a single front door with risk-based triage, reported against a turnaround commitment, so security accelerates the business rather than bottlenecking it.
  • Own the application and AI security tool stack and the secure-design standards behind it.

Key Deliverables in Your First Year:

  • An AI golden path: an approved-model catalog and automated data-egress controls, so teams adopt AI on a governed route instead of case-by-case approvals.
  • A secure SDLC paved road, with scanning in the pipeline by default and critical findings resolved within SLA.
  • A single security-review intake that delivers fast, risk-based answers on a published turnaround.
  • A built-out team, with the open roles filled and performing.

How You Will Work:

Much of this scope is delivered in partnership. Engineering carries remediation on application, API, and dependency findings. Platform Engineering operates the CI/CD pipelines you secure. AI Engineering builds the model integrations you govern on the security side, while the Governance, Risk & Compliance team owns AI use governance, meaning acceptable use, model inventory, and third-party model data-egress scoping, as the companion to your security accountability. Setting and holding clear service expectations across these partners is part of the role.

Requirements:

  • A minimum of 8 years application or product security.
  • A minimum of 3 years leading a team with function-level accountability.
  • Demonstrated AI and ML security ownership at production scale, including model and agent security, prompt-injection and tool-use risk, and data-egress control for third-party model providers, with working fluency in the OWASP LLM Top 10, MITRE ATLAS, and AI risk-management standards (NIST AI RMF, ISO/IEC 42001).
  • Secure SDLC leadership across static, dynamic, and interactive analysis (SAST/DAST/SCA/IAST), dependency and software supply-chain risk, SBOM practice, and remediation delivered through engineering teams.
  • Security architecture and threat-modeling depth, with the standing to review a design and be heard by senior engineers.
  • DevSecOps and pipeline security experience, including scanning as a default in CI/CD, risk-calibrated release gating, and pipeline secret handling.
  • API security experience on a platform handling regulated data.
  • A track record of delivering security as paved roads and secure defaults rather than review gates, with evidence of adoption.
  • Bachelor’s degree in a relevant field, or equivalent professional experience.

Strong Candidates Will:

  • Healthcare or another regulated domain where PHI or comparable data flows through AI systems.
  • Experience standing up an AI golden path, including an approved-model catalog, a governed adoption route, and automated egress controls.
  • Experience building a single security-review intake with risk-based triage and a turnaround commitment.
  • Cryptographic standards ownership, including customer-managed key models.
  • Hands-on familiarity with tools such as Snyk, GitHub Advanced Security, AI security posture management (for example, Wiz), and AI-assisted code scanning.
  • Familiarity with AI red-teaming and adversarial-testing tooling (for example, Garak, PyRIT, Promptfoo).
  • Product security experience shipping customer-facing security features as differentiators.
  • Experience hiring and building a team from a single senior individual contributor.
  • CSSLP, OSWE, GWAPT, or equivalent.

Who Thrives in This Role:

  • Guardrails over gates. You instinctively ask how to remove a queue rather than how to staff one.
  • Engineering credibility. You earn influence with builders through technical depth, not process authority.
  • Risk calibration. You reserve genuine gates for what earns them, namely PHI exposure, external model egress, and privileged access, and you keep even those automated and fast.
  • Delivery orientation. You treat a roadmap as a commitment with dates.
  • Team building. You can grow a function from one senior IC and a set of open roles.

Benefits

  • Medical Insurance
  • Dental Insurance
  • Vision Insurance
  • Short & Long Term Disability
  • Life Insurance
  • 401k with company match
  • Flexible Time Off
  • Paid Parental Leave

The salary range for this position is $200,000 - $275,000  annually, based on experience, skills, and qualifications. This position is also eligible for an annual bonus, separate from and in addition to the base salary range listed above. Lantern provides this range in good faith in compliance with New York's pay transparency requirements.

About You:

  • You use LOGIC in your decision making and understand that progress is critical to making change. You focus on the execution of your content while balancing a fast-paced environment and you take the time to celebrate both the small & big wins. 
  • INCLUSION is a core tenant of your personal beliefs. A diverse and inclusive environment is incredibly important to you. You understand and desire to be a part of a diverse team with different experiences and perspectives & you cherish the differences in each individual that you interact with.
  • You have the GRIT, drive and ambition to tackle big problems. Big problems require big ideas and a team that supports new ideas. 
  • You care deeply for your customers are driven to keep HUMANITY in all decisions. Your customers aren’t just the individuals using your product. They are the driving factor in your motivation to make a change.
  • Integrity guides you in life. Focusing on the TRUTH vs. giving people the answers they want to hear. 
  • You thrive in a Team Environment. Collaboration is key in innovation and creating change.

These pillars of LIGHT are a reminder to our team that we are making a difference by providing guidance and support in navigating the often complex and confusing landscape of healthcare. We hope that through this  LIGHT, individuals can find their way to the best care, resources, and support they need to get back to life. 

If this sounds like you, we would love to connect to speak further about career opportunities at Lantern.

Please apply to our role & someone from our Talent Acquisition Team will reach out to help you navigate our interview process.

Lantern does not discriminate on the basis of race, sex, color, religion, age, national origin, marital status, disability, veteran status, genetic information, sexual orientation, gender identity or any other reason prohibited by law in provision of employment opportunities and benefits.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
671,804 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
New York
$111k – $240k per year (Estimated) • Remote • 5+ years exp
Python
JavaScript
Python
Flask
FastAPI
AI/ML
Copilot
Claude Code
AI Agents
LLM
OpenAI Codex
LLM Guardrails
Frontend
Next.js
React.js
DevOps
CI/CD
Git
Docker
Apply
$16k – $32k per year (Estimated) • In office • 1+ year exp • Moscow
Java
SQL
Java
Maven
Databases
PostgreSQL
Apache Kafka
AI/ML
AI Agents
DevOps
OpenShift
Istio
CI/CD
Jenkins
Git
Kubernetes
QA
TestNG
Selenium
Rest-Assured
Apply
$160k – $240k per year • Equity • In office • Full-Time • 10+ years exp • Bachelor's Degree • Sunnyvale
Python
Java
Kotlin
SQL
Scala
Java
Spring Boot
Databases
MySQL
AI/ML
LangChain
Claude
LlamaIndex
Model Context Protocol
Vertex AI
Multimodal AI
AI Agents
Llama
Gemini
LLM
RAG
LLM Evaluation
LLM Guardrails
Multi-Agent Systems
DevOps
Rest API
Kubernetes
Apply
$29k – $63k per year (Estimated) • In office • 5+ years exp • Moscow
Python
SQL
C++
Bash
C++
CMake
Databases
PostgreSQL
DevOps
Debian
CI/CD
Proxmox VE
Apply
$64k – $138k per year (Estimated) • Remote • Full-Time • 2+ years exp
Python
JavaScript
TypeScript
AI/ML
Anthropic
DevOps
GitHub Actions
Vercel
CircleCI
CI/CD
Jenkins
Grafana
GitHub
Design
Figma
Management
Slack
Apply
$175k – $225k per year • Remote/Hybrid • 8+ years exp • Bachelor's Degree • New York
Python
PowerShell
DevOps
Terraform
Azure
Platform Engineering
SLI/SLO/SLA
GitHub
IAM
Cybersecurity
SOC 2
HIPAA
Zero Trust
Least Privilege
Microsoft Entra ID
Apply
$88k – $165k per year (Estimated) • Remote/Hybrid • 5+ years exp • Bachelor's Degree • Dallas
Management
Monday.com
Microsoft Project
Jira
Outlook
Apply
$40k – $48k per year • In office • 1+ year exp • High School Diploma • Dallas
Apply
$128k – $228k per year (Estimated) • Remote/Hybrid • 5+ years exp • New York
SQL
Apex
AI/ML
AI Agents
Apply
$100k – $194k per year (Estimated) • Remote/Hybrid • 5+ years exp • Dallas
Python
SQL
Databases
Databricks
MS SQL
AI/ML
Spark
Interpretability
DevOps
Terraform
GCP
Azure
AWS
Analytics
Power BI
Apply
$275k per year • In office • Full-Time • 10+ years exp • New York • Reston
Apply
$115k – $214k per year • Equity • Remote/Hybrid • Full-Time • 7+ years exp • Frisco • New York • Toronto • Ann Arbor
AI/ML
Agentic Workflows
Apply
$115k – $214k per year • Equity • Remote/Hybrid • Full-Time • 7+ years exp • Frisco • New York • Toronto • Ann Arbor
AI/ML
Agentic Workflows
Apply
$181k – $337k per year • Equity • Remote/Hybrid • Full-Time • 5+ years exp • New York • Frisco • Toronto • Ann Arbor
Apply
$158k – $294k per year • Equity • Remote/Hybrid • Full-Time • 10+ years exp • Frisco • New York • Ann Arbor
AI/ML
Agentic Workflows
Apply
See all jobs
This is one of many
671,804 more open roles from verified company boards, updated every day.