Security Engineer – Agentic AI Security
Must-have:AIHealthTechSecurity
The team is hiring a hands-on security engineer to build and security-test a realistic clinical agentic AI system. The target system is a clinical assistant that retrieves and reasons over synthetic patient records and clinical guidelines, drafts clinical documentation, and answers clinician queries. Human confirmation will be required before any action that writes back or sends information. The engineer will build the prototype and conduct a structured security assessment covering the key attack surfaces of agentic AI, with a focus on practical security assurance for healthcare deployment.
What the role involves
Build the clinical agent
- Implement a clinical agent using LangGraph , with MCP , RAG and synthetic patient records
- Implement basic access controls, data protection and human-in-the-loop action gating
- Document the architecture, trust boundaries and security assumptions
Threat model and red-team
- Develop a threat model covering the agent, tools, memory and data flows
- Conduct structured security testing covering: indirect prompt injection; malicious/poisoned MCP tools; memory poisoning; action-gate bypass and unauthorised tool use; sensitive-data exfiltration; code-execution risks, where applicable
- Adapt existing agentic-AI security benchmarks and tools where appropriate
Findings and mitigation
- Document security findings, severity and attack paths
- Recommend and, where feasible, validate practical mitigations
- Provide deployment recommendations for secure use of agentic AI in clinical settings
Key Deliverables
- Working clinical agent security testbed (LangGraph + MCP + RAG + synthetic data)
- Threat model and documented attack surface
- Reusable red-team/security evaluation harness
- Security assessment report with findings, mitigations and deployment recommendations
- Practical security testing guidelines for future healthcare agentic-AI systems