AI Platform & Security Engineer
Beghou brings over three decades of experience helping life sciences companies optimize their commercialization through strategic insight, advanced analytics, and technology. From developing go-to-market strategies and building foundational data analytics infrastructures to leveraging artificial intelligence to improve customer insights and engagement, Beghou helps life sciences companies maximize performance across their portfolios. Beghou also deploys proprietary and third-party technology solutions to help companies forecast performance, design territories, manage customer data, organize, and report on medical and commercial data, and more. Headquartered in Evanston, Illinois, we have 10 global offices.
Our mission is to bring together analytical minds and innovative technology to help life sciences companies navigate the complexity of health care and improve patient outcomes.
What this is and why it matters
Beghou is standing up an AI-native operating model: enterprise Claude and ChatGPT, a growing library of internal skills and tools, an MCP server ecosystem, an internal AI Lab site, and firm-wide cost and governance obligations. Every one of these has an AI-specific platform, security, and configuration layer underneath it – managed policy files, connector and MCP governance, security reviews, token controls, admin and access management, deployment infrastructure.
This role owns that layer. It exists so the platform runs as managed infrastructure with a clear standard and owner as Beghou’s AI footprint scales.
This is a distinct profile from the AI builders on the team. Builders ship skills and automations. This person secures, configures, governs, and deploys the platform those skills run on.
What you will own
This is the current scope. It will evolve as the technology and our adoption change.
Managed configuration and policy
Author and maintain managed settings for Claude, ChatGPT, and Codex across the fleet, and keep them current as the tools change
Enforce org policy through configuration: connector governance, deny-lists, permitted capabilities, model and feature controls
Coordinate rollout of configuration changes with IT and endpoint management so they land consistently on every user’s setup
MCP and integration governance
Stand up and secure the MCP server ecosystem: evaluate and operate supply-chain controls, decide hosting and data-residency, maintain the approved MCP catalog
Review MCP and agent permissions on a set cadence; approve or reject new server requests against a security bar
Decide where MCP servers are hosted and run (client-provided versus Beghou-hosted) and own the hosting posture
Security reviews and GRC partnership
Run security reviews for new AI tools, agents, and MCPs, and produce the artifacts GRC needs to approve or approve-with-conditions
Maintain the approved AI tool and agent catalog and the conditions attached to each
Support HIPAA/GxP and audit posture for AI tooling, and act as the technical counterpart to GRC
Cost and token governance (technical side)
Implement usage and token visibility, per-user attribution, budgets, soft caps, and alerting that back the firm’s cost-management framework
Build or operate the dashboards and controls that turn governance policy into enforced reality
Access and admin
Own the admin consoles for the AI platforms: seat and entitlement provisioning, analytics and API access, SSO and identity coordination with IT
Resolve the recurring access and admin requests across the AI toolset
Deployment and infrastructure for AI tools
Package and deploy internal skills and tools, and operate the AI Lab site and its hosting infrastructure
Set up the CI/CD and environments internal AI tooling needs to ship reliably
What makes someone great at this
Security-minded by default. You think about data exposure, permissions, and audit posture before shipping, and you can hold a defensible line with a vendor or a reviewer.
Hands-on platform and DevOps depth. You are comfortable with cloud (Azure), identity and SSO, endpoint or configuration management, and policy-as-code. You configure and deploy; you don’t just advise.
You move fast without breaking compliance. You find the path that satisfies GRC and still ships this quarter, rather than stalling on either side.
You partner across boundaries. This work touches AI Innovation, IT, Cloud, and GRC, and you keep threads moving to closure across all of them.
You own ambiguity. Much of this is greenfield at Beghou, and you define the standard where none exists yet.
Background that fits well
4–8 years in platform engineering, security engineering, DevOps, cloud infrastructure, or IT engineering
Hands-on with cloud (Azure preferred), identity and SSO, and configuration or endpoint management
Experience running or supporting security reviews, audit, or compliance tooling (HIPAA/GxP exposure a plus)
Familiarity with LLM tooling, agents, or MCP is a strong plus, and the ability to learn it fast is a requirement
Comfortable being the technical face to a governance and risk function and to external vendors
At Beghou Consulting, you'll join a highly collaborative, values-driven team where technical excellence, analytical rigor, and personal growth converge. Whether you're passionate about AI innovation, building commercialization strategies, or shaping the next generation of data-first solutions in life sciences, this is a place to make an impact!