Our mission is to detect cancer early, when it can be cured. We are working to change the trajectory of cancer mortality and bring stakeholders together to adopt innovative, safe, and effective technologies that can transform cancer care.
We are a healthcare company, pioneering new technologies to advance early cancer detection. We have built a multi-disciplinary organization of scientists, engineers, and physicians and we are using the power of next-generation sequencing (NGS), population-scale clinical studies, and state-of-the-art computer science and data science to overcome one of medicineβs greatest challenges.
GRAIL is headquartered in the bay area of California, with locations in Washington, D.C., North Carolina, and the United Kingdom. It is supported by leading global investors and pharmaceutical, technology, and healthcare companies.
For more information, please visit grail.com
Responsibilites
β’
Agentic Security Development: Build and maintain a secure reasoning layer for GRAIL data strategy, moving security from a concept to a functional necessity within business workflows.
β’
Domain-Specific Model Engineering: Develop and refine healthcare-specific security detection models (e.g., Content Safety Classifiers, Behavioral / Alignment Monitoring Models) that outperform generic models by minimizing domain-specific blind spots.
β’
Privacy-Preserving and Data Leakage Computation: Implement and manage cryptographic Private Information Retrieval (PIR) systems (such as SealPIR, XPIR, or CPIR) to protect access patterns over large-scale patient record datasets. Detects and prevents exposure of sensitive data (PII, secrets, enterprise data).
β’
Integrity & Tamper Detection: Design data-layer protections, including bilinear pairing checks and cryptographic receipts, to ensure any server-side tampering is detected instantly.
β’
Cloud Infrastructure Security: Deploy and maintain Terraform IaC across AWS multi-cloud environments, ensuring VPC isolation and continuous threat exposure monitoring.
β’
Security Observability: Utilize XAI tools like LIME and SHAP to analyze model failure modes, ensuring that security controls do not inadvertently cause HIPAA availability violations or disrupt care coordination.
Key responsibilities include:
β’
Design, build, and support AI/ML solutions and integrations across the enterprise
β’
Evaluate and secure AI platforms, LLMs, Claude, Gemini, ChatGPT and AI-powered development tools (e.g., GitHub, OKTA, PaloAlto) in AWS Bedrock.
β’
Lead development of AI security controls, guardrails, and governance frameworks
β’
Perform threat modeling and risk assessments for AI/ML systems and integrations
β’
Partner with engineering teams to enable secure AI development practices, including prompt engineering, API security, and data protection
β’
Assess and mitigate risks related to LLMs, including prompt injection, model leakage, and data exposure
β’
Contribute to secure architecture patterns for AI-enabled applications and services
β’
Support security reviews, testing, and validation of AI use cases and implementations
β’
Collaborate with cloud, data, and application teams to ensure secure deployment of AI capabilities
β’
Evaluate and onboard AI vendors and tools, ensuring alignment with security, privacy, and compliance requirements
β’
Promote awareness and adoption of secure AI usage practices across the organization
β’
Remain current on emerging AI and security risks, trends, and technologies
β’
Ensure alignment and compliance with industry standards (NIST AI-RMF, ISO 42001, OWASP Top 10 for LLMs) and advanced security architectures (Agentic, MCP).
GRAIL Core Values & Expected Behaviors
Demonstrate GRAILβs values in every engagement:
β’
Be Courageous
Challenge the status quo, step up to address difficult issues, and support others who do the same.
β’
Solve Problems Together
Collaborate across boundaries, bring in diverse skillsets, and work with rigor, speed, and a data-driven mindset.
β’
Think BIG!
Pursue ambitious goals with focused execution and bring in external perspectives to shape future solutions.
β’
Embrace Change
Navigate ambiguity, anticipate the future, and turn complexity into opportunity.
β’
Bring an Open Mind
Cultivate curiosity, listen actively to diverse voices, and challenge assumptions to unlock innovation.
Required Qualifications
β’
Strong hands-on experience with AI/ML technologies, LLMs, or AI development tools
β’
3β5+ years of experience in security engineering, application security, or cloud security
β’
Experience performing threat modeling, security architecture design, and secure code review or testing
β’
Experience developing AI solutions within IDEs, utilizing AI code assistants
β’
Experience working with LLM APIs (OpenAI, Anthropic, etc.)
β’
Familiarity with AI frameworks such as LangChain, LlamaIndex, or similar
β’
Understanding of AI/ML lifecycle and prompt engineering
β’
Familiarity with AI security risks such as prompt injection, data leakage, and model misuse
β’
Experience working in cloud environments (AWS, Azure, or GCP)
β’
Familiarity with secure development practices (DevSecOps)
β’
Working knowledge of OWASP Top 10 and application security principles
β’
Strong collaboration and communication skills
Preferred Qualifications
β’
Experience with agentic and Model Context Protocol (MCP) architectures.
β’
Expertise in Python, R, Java, or similar programming languages.
β’
Experience in GCP or AWS cloud-native services, architectures, and tools.
β’
Advanced knowledge of security and governance frameworks (NIST AI-RMF, ISO 42001, OWASP Top 10 for LLM).
This role may be eligible for other forms of compensation, including an annual bonus and/or incentives, subject to the terms of the applicable plans and Company discretion. This range reflects a good-faith estimate of the range that the Company reasonably expects to pay for the position upon hire; the actual compensation offered may vary depending on factors such as the candidateβs qualifications. Employees in this role are also eligible for GRAILβs comprehensive and competitive benefits package, offered in accordance with our applicable plans and policies. This package currently includes flexible time-off or vacation; a 401(k) retirement plan with employer match; medical, dental, and vision coverage; and carefully selected mindfulness programs.
GRAIL is an equal employment opportunity employer, and we are committed to building a workplace where every individual can thrive, contribute, and grow. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, sex, gender, gender identity, sexual orientation, age, disability, status as a protected veteran, , or any other class or characteristic protected by applicable federal, state, and local laws. Additionally, GRAIL will consider for employment qualified applicants with arrest and conviction records in a manner consistent with applicable law and provide reasonable accommodations to qualified individuals with disabilities. Please contact us at [Upgrade to PRO to see contact] if you require an accommodation to apply for an open position.
GRAIL maintains a drug-free workplace. We welcome job-seekers from all backgrounds to join us!