Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
View Full Job Details on LinkedInAbout SCAN
SCAN Group, also known as SCAN Health Plan, is a not-for-profit organization based in Long Beach, California. Founded in 1977, SCAN is dedicated to promoting the health and independence of seniors through Medicare Advantage health plans and community services. It launched its first Medicare health plan in 1984 and has since become one of the largest not-for-profit Medicare Advantage plans in the United States, serving over 440,000 members across multiple states, including California, Arizona, New Mexico, Nevada, Texas, and Washington. The organization offers a range of services, including Medicare Advantage health plans that provide healthcare coverage to Medicare beneficiaries. SCAN also runs community services like Independence at Home, which delivers essential support to seniors and caregivers, regardless of membership status. Additionally, SCAN operates four subsidiary medical groups focused on various aspects of senior care and invests in initiatives that promote healthier aging, educational programs, and community support.
Security at SCAN
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- No standalone public AppSec mission statement was identified.
- The Cloud/App Security role prioritizes securing Azure infrastructure, applications, integrations, and patient data while addressing HIPAA and HITRUST requirements.
- The developer model combines enablement and control: the AI-security role defines an embedded security-advisor function, secure-by-default configurations, reference architectures, templates, checklists, and secure code review, while also assigning security-gatekeeper responsibilities and AI-infrastructure sign-off through the Change Advisory Board.
- The stated risk model uses risk classifications, risk ratings, compensating controls, AI risk registers, least privilege, Zero Trust, threat modeling, red-team exercises, data-flow review, and regulatory context.
- Stated goals include responsible enterprise AI adoption, scaling AI applications, establishing secure implementation standards, maintaining an AI technology registry, and training technical and business users.
- Public evidence of scanner-noise reduction, remediation SLAs, security KPIs, or traditional AppSec success metrics was not identified.
Security Team
Company identity: SCAN is SCAN Group/SCAN Health Plan, a Long Beach, California, not-for-profit healthcare organization. Its public company profile lists 2,144 employees company-wide; an AppSec-specific headcount is Information not publicly available. Key public security leaders: Huy T., Director of Information Security , and Natasha Gupta, Director of InfoSec—Governance, Risk & Compliance . A public CISO title, AppSec reporting line, and centralized-versus-embedded organizational model were not identified. As of, 3 security-specific postings were identified: Sr Staff AI Security Engineer (JR3161), AI Security Engineer (GRC) (JR2887), and Senior Cyber Security Engineer (JR3189). Common patterns are Azure/cloud and application security, APIs, IAM and least privilege, CI/CD or secure implementation, healthcare compliance, and AI governance/security.
Key Initiatives
- Security champions: No Evidence Found.
- Shift-left and SDLC evidence: Azure DevOps CI/CD and IaC, secure implementation guidance, secure code review for AI integrations, reference architectures, secure configuration templates, implementation checklists, architecture/data-flow review, and AI-specific threat modeling.
- Vulnerability management: SAST and DAST are named, and security solutions are to be designed, implemented, and tested.
- Public evidence of vulnerability intake sources, ticket ownership, triage queues, remediation SLAs, or MTTR targets was not identified.
- Secure-SDLC and governance ceremonies: AI vendor security assessments, Vendor Security Assessment Reports, an AI technology registry, AI risk register maintenance, AI governance committee participation, Change Advisory Board security sign-off, red-team exercises, and policy development.
- Recent six-month initiatives: SCAN announced its first Chief AI Officer on.
- Official communications describe enterprise AI and advanced-analytics expansion, workforce training, and AI-enabled operational and care-delivery tools.
- The AI-security job postings describe planned role responsibilities and governance artifacts, not confirmed production rollouts.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.
Interested in this role?
Apply on LinkedIn