Senior AI Application Security Engineer
Summary
Build and lead the application-security practice for a healthcare AI platform, hardening LLM features against prompt injection and adversarial attacks while embedding security into Ruby/Python/React/Node.js pipelines.
Senior AI AppSec Engineer
Location: United States
Department: Infrastructure & Security
Location Type: REMOTE
Employment Type: FULL_TIME
About the Role
What You'll Do
- Designing and implementing robust security architectures for our features, ensuring strict protections against prompt injection, adversarial machine learning, and data exfiltration.
- Establishing safe boundaries, sandboxing, and security guardrails for internal engineering teams utilizing agentic coding harnesses to write our codebase.
- Partner with engineering teams to embed security throughout the SDLC across Fabric's Ruby on Rails, Python, React, and Node.js applications. Conduct security-focused code reviews and provide actionable guidance on secure coding practices.
- Lead threat modeling exercises for new features and architectural changes. Conduct application penetration testing and vulnerability assessments across the platform, prioritizing findings and working directly with engineering to drive remediation.
- Implement and manage SAST and DAST tooling integrated into CI/CD pipelines. Build security guardrails and automated checks that allow engineering to move fast without introducing risk to the platform or patient data.
- Ensure application security practices meet HIPAA, SOC 2, and HITRUST requirements. Assess third-party integrations and APIs for security risk, including EHR integrations with Epic and Cerner.
- Run secure coding training and awareness programs for engineering teams. Serve as the internal subject matter expert on application security and lead response to application-layer security incidents.
Why You Might Be a Good Fit
- You bring a true hacker mindset to your work, constantly thinking about how to break complex systems in order to build more resilient defenses.
- You possess a deep, native understanding of AI security, specifically around the unique attack vectors introduced by large language models and agentic workflows.
- You are highly collaborative and enjoy partnering directly with engineering teams to solve security challenges, rather than acting as an isolated gatekeeper.
- You actively use modern AI tools to accelerate your own daily workflows, treating AI-assisted code analysis and vulnerability remediation as table stakes.
- You understand that in healthcare, a vulnerability is not just a technical problem. It is a patient safety and compliance issue.
- You are energized by building a security practice and shaping how a fast-growing company approaches both product and AI security.
This Might Not Be The Right Fit If...
- Your AI security experience has mostly been high-level, and you haven't yet had the opportunity to dive deeply into production LLM hardening or structural red-teaming.
- You have limited experience securing agentic pipelines and LLM-driven features.
- You are primarily a compliance or GRC-focused security professional and are not comfortable getting directly into the code.
- You prefer manual vulnerability remediation workflows over leveraging AI to accelerate your daily tasks.
- You prefer working in a mature, established security program over building and defining one.
- You are not comfortable working closely with engineering as a partner rather than an oversight function.
- You do not have experience in a regulated environment where security decisions carry direct compliance implications.
Your Qualifications
- 5+ years of experience in application security with hands-on experience in security assessments, penetration testing, and secure code review.
- Deep expertise in AI-native security, including advanced defense mechanisms against prompt injection, LLM production hardening, and adversarial machine learning.
- Experience securing agentic coding workflows and establishing robust guardrails for AI-generated code.
- A true "hacker" mindset with a proven track record of finding and exploiting complex vulnerabilities to build stronger defenses.
- Proficiency in utilizing modern AI assistants to accelerate your own daily workflows, including code analysis and vulnerability remediation.
- Proficiency in at least one programming language in Fabric's stack, such as Ruby, Python, or JavaScript/TypeScript.
- Experience integrating SAST and DAST tooling into CI/CD pipelines.
- Deep understanding of the OWASP Top 10, threat modeling methodologies, and common application vulnerabilities.
- Familiarity with cloud security in AWS environments and an understanding of HIPAA or other regulated industry security requirements.
Bonus Points
- Experience securing healthcare applications or working with PHI.
- Familiarity with EHR integration security including FHIR, HL7, Epic, or Cerner APIs.
- Security certifications such as OSCP, GWEB, or BSCP.
- Experience with bug bounty program management.
- SOC 2 or HITRUST audit support experience.
