SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior AI AppSec Engineer

GYANT - Remote - Remote

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Fabric Health is a healthcare technology company that uses intelligent automation to solve clinical capacity challenges across health systems. They unify the care journey from intake to treatment, making care delivery 2-10x more efficient while empowering clinicians to focus on patient care. Backed by premier investors including Thrive Capital, GV (Google Ventures), General Catalyst, and Salesforce Ventures, Fabric Health is trusted by leading organizations like Intermountain Health, OSF HealthCare, SSM Health, and MUSC Health. As Senior AI AppSec Engineer, you will own the application security practice at Fabric, operating as a strategic partner to engineering rather than a gatekeeper. You will embed security throughout the development lifecycle, build tooling and automation to keep the platform secure, and ensure compliance with healthcare standards (HIPAA, SOC 2, HITRUST). The role leverages modern AI tools and automated workflows to accelerate threat modeling, streamline code reviews, and scale security operations. Key responsibilities include: designing and implementing robust security architectures for features with protections against prompt injection, adversarial machine learning, and data exfiltration; establishing safe boundaries and sandboxing for agentic coding harnesses; partnering with engineering to embed security across the SDLC for Ruby on Rails, Python, React, and Node.js applications; conducting security-focused code reviews and threat modeling; performing application penetration testing and vulnerability assessments; implementing and managing SAST/DAST tooling in CI/CD pipelines; building security guardrails that allow fast engineering velocity without risk; assessing third-party integrations and EHR APIs (Epic, Cerner) for security risk; running secure coding training; and serving as subject matter expert for application security incidents. You bring a hacker mindset, deep native understanding of AI security and LLM attack vectors, and genuine enthusiasm for collaborating with engineering teams. You actively use modern AI tools to accelerate your own workflows and understand that in healthcare, vulnerabilities are patient safety and compliance issues. You're energized by building and shaping a security practice at a fast-growing company. Required: 5+ years application security experience with hands-on security assessments, penetration testing, and secure code review; deep expertise in AI-native security including prompt injection defense, LLM production hardening, and adversarial machine learning; experience securing agentic coding workflows; proven track record finding and exploiting complex vulnerabilities; proficiency with modern AI assistants for code analysis and vulnerability remediation; proficiency in Ruby, Python, or JavaScript/TypeScript; experience integrating SAST and DAST tooling.

Similar roles