Fabrichealth
Senior Application Security Engineer
USA · Senior
Sponsorship not specified$130k-$160kDetected 47 days ago
JavaScriptTypeScriptPythonRubyReactNode.jsRailsCode ReviewAWSCI/CDCybersecurityPenetration TestingComplianceHIPAAEpicCernerHL7/FHIREHR/EMR
About the role
- Fabric handles protected health information at scale across 75+ health systems and millions of patient encounters.
- Security is not a layer we add at the end.
- This is a new headcount reporting to the VP of Infrastructure.
Responsibilities
- As a Senior Application Security Engineer, you will be the driving force behind application security at Fabric, operating as a partner to engineering rather than a gatekeeper.
- Your primary responsibilities will include: Secure Development & Code Review: Partner with engineering teams to embed security throughout the SDLC across Fabric's Ruby on Rails, Python, React, and Node.js applications.
- Threat Modeling & Assessment: Lead threat modeling exercises for new features and architectural changes.
- Conduct application penetration testing and vulnerability assessments across the platform, prioritizing findings and working directly with engineering to drive remediation.
- DevSecOps & Tooling: Implement and manage SAST and DAST tooling integrated into CI/CD pipelines.
- Build security guardrails and automated checks that allow engineering to move fast without introducing risk to the platform or patient data.
- Serve as the internal subject matter expert on application security and lead response to application-layer security incidents.
- Why You Might Be a Good Fit You think like an attacker and build like an engineer.
- You prefer working in a mature, established security program over building and defining one.
- Partner with engineering teams to embed security throughout the SDLC across Fabric's Ruby on Rails, Python, React, and Node.js applications.
Requirements
- 5+ years of experience in application security with hands-on experience in security assessments, penetration testing, and secure code review.
- Proficiency in at least one language in Fabric's stack: Ruby, Python, JavaScript/TypeScript, or similar.
- Experience integrating SAST and DAST tooling into CI/CD pipelines.
- Experience with threat modeling methodologies.
- Familiarity with cloud security in AWS environments.
- Familiarity with EHR integration security including FHIR, HL7, Epic, or Cerner APIs.
- Experience with bug bounty program management.
- You are as comfortable in a codebase as you are writing a threat model.
- You are primarily a compliance or GRC-focused security professional and are not comfortable getting into the code.
Compensation
- $130k-$160k
Benefits
- About the Role Fabric handles protected health information at scale across 75+ health systems and millions of patient encounters.
- Bonus Points Experience securing healthcare applications or working with PHI.
- Security Education & Culture: Run secure coding training and awareness programs for engineering teams.
- You understand that in healthcare, a vulnerability is not just a technical problem.
- You prefer building guardrails and education programs over reactive patching.
- You are energized by building a security practice and shaping how a fast-growing company approaches application security.
Company info
- Run secure coding training and awareness programs for engineering teams.
- It is a patient safety and compliance problem.
- You can communicate security risk to engineering teams in a way that drives action, not defensiveness.
- This Might Not Be The Right Fit If...
- You are not comfortable working closely with engineering as a partner rather than an oversight function.
- You do not have experience in a regulated environment where security decisions carry direct compliance implications.
- Your Qualifications 5+ years of experience in application security with hands-on experience in security assessments, penetration testing, and secure code review.
Apply directly at Fabrichealth →Create a free account for alerts like thisView Fabrichealth immigration profile
This listing is sourced directly from Fabrichealth's careers page and normalized into a canonical job model.