Fabric Health logo
Fabric HealthPosted 2 weeks ago

Senior AI AppSec Engineer

$130,000–$160,000 year

RemoteUnited States

Full TimeSenior LevelStartup

Job Summary

Design and implement robust security architectures for features, establishing safe boundaries and sandboxing for agentic coding harnesses. Partner with engineering teams to embed security throughout the SDLC across Ruby on Rails, Python, React, and Node.js applications, conducting security-focused code reviews and leading threat modeling exercises. Implement and manage SAST and DAST tooling integrated into CI/CD pipelines, while ensuring application security practices meet HIPAA, SOC 2, and HITRUST requirements. Conduct application penetration testing and vulnerability assessments, prioritizing findings and working directly with engineering to drive remediation. Run secure coding training and awareness programs, serving as the internal subject matter expert on application security and leading response to application-layer security incidents.

Required Qualifications

  • 5+ years of experience in application security with hands-on experience in security assessments, penetration testing, and secure code review
  • Deep expertise in AI-native security, including advanced defense mechanisms against prompt injection, LLM production hardening, and adversarial machine learning
  • Experience securing agentic coding workflows and establishing robust guardrails for AI-generated code
  • A true hacker mindset with a proven track record of finding and exploiting complex vulnerabilities to build stronger defenses
  • Proficiency in utilizing modern AI assistants to accelerate your own daily workflows, including code analysis and vulnerability remediation
  • Proficiency in at least one programming language in Fabric's stack, such as Ruby, Python, or JavaScript/TypeScript
  • Experience integrating SAST and DAST tooling into CI/CD pipelines
  • Deep understanding of the OWASP Top 10, threat modeling methodologies, and common application vulnerabilities
  • Familiarity with cloud security in AWS environments and an understanding of HIPAA or other regulated industry security requirements

Desired Qualifications

  • Experience securing healthcare applications or working with PHI
  • Familiarity with EHR integration security including FHIR, HL7, Epic, or Cerner APIs
  • Security certifications such as OSCP, GWEB, or BSCP
  • Experience with bug bounty program management
  • SOC 2 or HITRUST audit support experience

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce