SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Spring Health is a global mental health platform on a mission to eliminate barriers to mental health care. The company operates an AI-native platform delivering personalized support through self-guided tools, coaching, therapy, medication management, and specialty care, reaching over 170 million people worldwide through employers, health plans, and partners.
You will define and evolve Spring Health's AI security strategy to protect highly sensitive mental health data across product and corporate environments. Reporting to the Sr. Director of Engineering, Platform Infrastructure, you will lead secure design and threat modeling for AI systems including LLMs, agentic workflows, and retrieval pipelines. Key responsibilities include identifying and mitigating risks such as prompt injection, data exfiltration, model abuse, and privilege escalation.
You will build scalable AI security guardrails and tooling that enable safe experimentation across engineering and business teams, establish AI-specific governance frameworks covering identity, access control, auditability, and observability, and take ownership of the AI Red Team to proactively identify vulnerabilities. You will design and implement AI observability pipelines to detect anomalous model behavior and policy violations in near real-time, develop and operationalize AI incident response playbooks, and partner with product and engineering teams to enable responsible AI innovation.
Success metrics include: 80% of new AI product features threat modeled prior to GA, 80% of AI features tested by the AI Red Team before GA, ≥70% coverage of production AI features with automated LLM vulnerability testing, 10% YoY growth in AI Red Team participation, and development of AI incident response playbooks with at least one tabletop or live simulation per year.
You bring 10+ years of software engineering experience with at least 5+ years focused on security. You have hands-on experience securing AI/ML systems, including practical AI red teaming against LLMs, agentic workflows, or RAG systems. You have developed or implemented automated LLM vulnerability testing for prompt injection and data exfiltration, with a strong foundation in application security principles, threat modeling, secure design, and identity and access control. You demonstrate ability to build tools and automation with a developer mindset, influence senior engineers and cross-functional stakeholders, mentor engineers, and cultivate security culture. Strong working knowledge of modern developer tooling, CI/CD pipelines, and git-based collaboration required.
This is a hybrid role based in San Francisco with expectation to be in office 2–3 days per week at 44 Montgomery Street. Candidates must be based in the San Francisco metro area or able to relocate independently within 90 days of start date. Occasional travel required for team on-sites.