Senior AI AppSec Engineer

Fabric

United States

On-site

USD 130,000 - 160,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Fabric Health is seeking a Senior AI AppSec Engineer to own the application security practice across our Ruby on Rails, Python, React, and Node.js stack. You will embed security throughout the development lifecycle and build tooling to keep our platform compliant and secure.

You will lead threat modeling, conduct penetration testing, implement SAST/DAST in CI/CD, and ensure HIPAA/SOC 2/HITRUST compliance while collaborating closely with engineering.

Qualifications

  • 5+ years of hands-on experience in application security.
  • Deep expertise in AI-native security and LLM-related threats.
  • Experience securing agentic coding workflows and guardrails for AI-generated code.
  • Proficiency in at least one Fabric stack language: Ruby, Python, or JavaScript/TypeScript.
  • Experience integrating SAST and DAST tooling into CI/CD pipelines.
  • Strong knowledge of OWASP Top 10 and threat modeling methodologies.
  • Familiarity with AWS cloud security and regulated environments (HIPAA).

Responsibilities

  • Design robust security architectures for features with protections against prompt injection and adversarial ML.
  • Establish guardrails and sandboxing for internal engineering teams.
  • Partner with engineering to embed security across SDLC for Rails, Python, React, and Node.js apps; conduct secure code reviews.
  • Lead threat modeling and perform penetration testing and vulnerability assessments across the platform.
  • Implement and manage SAST/DAST tooling integrated into CI/CD pipelines.
  • Ensure HIPAA, SOC 2, and HITRUST compliance; assess third-party integrations and APIs.
  • Provide secure coding training and act as internal security expert.

Skills

AI-native security
Agentic coding workflows
Hacker mindset
Secure coding practices

Tools

Ruby
Python
JavaScript/TypeScript
SAST tooling
DAST tooling
CI/CD security

Job description

About Fabric Health

At Fabric Health, we are powering boundless care by solving healthcare’s biggest challenge: clinical capacity. We aren’t here to disrupt healthcare; we’re here to fix it. We unify the care journey from intake to treatment, using intelligent automation to remove administrative burdens and make care delivery 2-10x more efficient. Our technology empowers clinicians to move faster and focus on what matters most: the patient.

We are a mission-driven team of brilliant minds trusted by leading organizations including Intermountain Health, OSF HealthCare, SSM Health, and MUSC Health. Our vision is backed by premier investors such as Thrive Capital, GV (Google Ventures), General Catalyst, and Salesforce Ventures. We move quickly for good reason, listen deeply to solve big challenges, and build products with the same care and quality we’d want for our own loved ones.

Learn more: About Us | News & Press | LinkedIn | Careers

About The Role

We handle protected health information at scale across health systems and millions of patient encounters. Security is not a layer we add at the end. It is built into how we work. As a Senior AI AppSec Engineer, you own the application security practice at Fabric, partnering directly with engineering to embed security throughout the development lifecycle, build the tooling and automation that keeps our platform secure, and ensure our applications meet the compliance standards our health system customers require. This role empowers you to leverage modern AI tools and automated workflows to accelerate threat modeling, streamline code reviews, and scale our security operations efficiently.

What You'll Do
  • Designing and implementing robust security architectures for our features, ensuring strict protections against prompt injection, adversarial machine learning, and data exfiltration.
  • Establishing safe boundaries, sandboxing, and security guardrails for internal engineering teams utilizing agentic coding harnesses to write our codebase.
  • Partner with engineering teams to embed security throughout the SDLC across Fabric's Ruby on Rails, Python, React, and Node.js applications. Conduct security-focused code reviews and provide actionable guidance on secure coding practices.
  • Lead threat modeling exercises for new features and architectural changes. Conduct application penetration testing and vulnerability assessments across the platform, prioritizing findings and working directly with engineering to drive remediation.
  • Implement and manage SAST and DAST tooling integrated into CI/CD pipelines. Build security guardrails and automated checks that allow engineering to move fast without introducing risk to the platform or patient data.
  • Ensure application security practices meet HIPAA, SOC 2, and HITRUST requirements. Assess third-party integrations and APIs for security risk, including EHR integrations with Epic and Cerner.
  • Run secure coding training and awareness programs for engineering teams. Serve as the internal subject matter expert on application security and lead response to application-layer security incidents.
Why You Might Be a Good Fit
  • You bring a true hacker mindset to your work, constantly thinking about how to break complex systems in order to build more resilient defenses.
  • You possess a deep, native understanding of AI security, specifically around the unique attack vectors introduced by large language models and agentic workflows.
  • You are highly collaborative and enjoy partnering directly with engineering teams to solve security challenges, rather than acting as an isolated gatekeeper.
  • You actively use modern AI tools to accelerate your own daily workflows, treating AI-assisted code analysis and vulnerability remediation as table stakes.
  • You understand that in healthcare, a vulnerability is not just a technical problem. It is a patient safety and compliance issue.
  • You are energized by building a security practice and shaping how a fast-growing company approaches both product and AI security.
This Might Not Be The Right Fit If...
  • Your AI security experience has mostly been high-level, and you haven't yet had the opportunity to dive deeply into production LLM hardening or structural red-teaming.
  • You have limited experience securing agentic pipelines and LLM-driven features.
  • You are primarily a compliance or GRC-focused security professional and are not comfortable getting directly into the code.
  • You prefer manual vulnerability remediation workflows over leveraging AI to accelerate your daily tasks.
  • You prefer working in a mature, established security program over building and defining one.
  • You are not comfortable working closely with engineering as a partner rather than an oversight function.
  • You do not have experience in a regulated environment where security decisions carry direct compliance implications.
Your Qualifications
  • 5+ years of experience in application security with hands-on experience in security assessments, penetration testing, and secure code review.
  • Deep expertise in AI-native security, including advanced defense mechanisms against prompt injection, LLM production hardening, and adversarial machine learning.
  • Experience securing agentic coding workflows and establishing robust guardrails for AI-generated code.
  • A true "hacker" mindset with a proven track record of finding and exploiting complex vulnerabilities to build stronger defenses.
  • Proficiency in utilizing modern AI assistants to accelerate your own daily workflows, including code analysis and vulnerability remediation.
  • Proficiency in at least one programming language in Fabric's stack, such as Ruby, Python, or JavaScript/TypeScript.
  • Experience integrating SAST and DAST tooling into CI/CD pipelines.
  • Deep understanding of the OWASP Top 10, threat modeling methodologies, and common application vulnerabilities.
  • Familiarity with cloud security in AWS environments and an understanding of HIPAA or other regulated industry security requirements.
Bonus Points
  • Experience securing healthcare applications or working with PHI.
  • Familiarity with EHR integration security including FHIR, HL7, Epic, or Cerner APIs.
  • Security certifications such as OSCP, GWEB, or BSCP.
  • Experience with bug bounty program management.
  • SOC 2 or HITRUST audit support experience.
Recruitment Fraud Alert: Protect Yourself
  • Verify the Domain: Official recruitment emails will only come from addresses ending in @fabrichealth.com or @gem.com. No other domain names are legitimate.
  • Official Interview Tools: We use Gem for our recruitment process and Google Meet for all video interviews. Google Meet is always the platform used for your first interview; you will never be sent a Zoom link to set up or conduct an initial interview. All interviews are conducted via video unless specifically stated by our team as an audio call. We never conduct interviews via chat, social media, Skype, or WhatsApp.
  • Zoom Usage: Zoom is utilized only for specific meetings set directly by our team for purposes outside of the standard interview process (e.g., coordination or onboarding discussions). It is never the first link you will receive from us.
  • Authorized Contact & Texting: Fabric will only contact you if you have submitted an application or if you are connected to a current employee who shared your information with us. We will only send text messages if you have provided explicit authorization and consent, either through your application or while communicating directly with our team. If you have not explicitly authorized us to reach out, treat any SMS or unsolicited outreach as fraudulent and do not respond.
  • Sensitive Data: We will never ask you for sensitive personal or financial documents (ID, banking info, SSN) during the application, interview, or candidacy stages. All sensitive data is handled through secure internal systems post-offer.
  • Verify the Team: You can reference LinkedIn to verify members of our recruiting team; however, please remain vigilant as scammers may create fraudulent profiles. Always cross-reference the sender's email domain with our official @fabrichealth.com address.

If you question the validity of a contact or receive a suspicious message, do not click any links. Please submit a report via this link: https://forms.gle/N1AGAiXcAL2W57H9A

The national pay range for this role is $130,000.00 – $160,000.00 per year. Actual compensation will be determined by factors such as the candidate's geographic market, experience, skills, and qualifications. Certain roles may also be eligible for additional compensation, including a comprehensive benefits package such as medical, dental, vision, unlimited PTO, and a 401(k) plan, stock options and bonuses. If your compensation requirement is greater than our posted range, please still consider applying; a determination can be made based on unique qualifications. Expected compensation ranges for this role may change over time.

At Fabric, we believe that a diverse workforce is essential to our success. We are an equal opportunity employer and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, national origin, age, disability, veteran status, or any other legally protected characteristic. We actively encourage individuals from all backgrounds to apply.

Please note: The security inbox is for reporting fraudulent activity only. Do not email this address for application status updates or to share application materials, as these will not be reviewed. Applications are only accepted and reviewed if submitted through our official application portal, and no application status information will be provided via the security email.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior AI AppSec Engineer
Senior AI AppSec Engineer

Fabric Labs, Inc. • Northern (KY)

Hybrid
USD 130,000 - 160,000
Medical benefits
Dental benefits
Vision benefits
+4
Senior Software Engineer, Virtual Care Platform
Senior Software Engineer, Virtual Care Platform

Fabric • United States

On-site
USD 140,000 - 170,000
Medical, dental, vision
Unlimited PTO
401(k) plan
+1
Senior Product Designer
Senior Product Designer

Fabric • New York (NY)

On-site
USD 110,000 - 130,000
Medical benefits
Dental benefits
Vision benefits
+4
Manager of Security & IT
Manager of Security & IT

Fabric • United States

On-site
USD 160,000 - 175,000
Medical, dental, vision insurance
Stock options
401(k) plan
Senior Software Engineer (Provider Directory & Scheduling)
Senior Software Engineer (Provider Directory & Scheduling)

Remote Jobs • United States

Remote
USD 140,000 - 170,000
Medical, dental, and vision benefits
Unlimited PTO
401(k) plan
+1
Senior Software Engineer, Artificial Intelligence
Senior Software Engineer, Artificial Intelligence

Fabric • United States

On-site
USD 150,000 - 175,000
Medical, dental, vision coverage
Unlimited PTO
401(k) plan
+1
Senior Security Engineer - Application Security
Senior Security Engineer - Application Security

K Health • New York (NY)

On-site
USD 150,000 - 185,000
Hybrid work schedule
18 vacation days
Stock options
+2
Application Security Analyst
Application Security Analyst

FSAStore.com • United States

On-site
USD 75,000 - 95,000
Medical, Dental, Vision
401K with company match
Flexible PTO
+2
Senior Security Engineer
Senior Security Engineer

Candid Health • San Francisco (CA)

On-site
USD 120,000 - 150,000
Senior Security Engineer Remote (United States)
Senior Security Engineer Remote (United States)

Pair Team • California (MO)

Hybrid
USD 170,000 - 190,000
Equity compensation package
Flexible vacation policy
Comprehensive medical, dental, and vision coverage
+3