Fabrichealth

Fabrichealth

Senior Application Security Engineer

USA · Senior

Sponsorship not specified$130k-$160kDetected 47 days ago
JavaScriptTypeScriptPythonRubyReactNode.jsRailsCode ReviewAWSCI/CDCybersecurityPenetration TestingComplianceHIPAAEpicCernerHL7/FHIREHR/EMR

About the role

  • Fabric handles protected health information at scale across 75+ health systems and millions of patient encounters.
  • Security is not a layer we add at the end.
  • This is a new headcount reporting to the VP of Infrastructure.

Responsibilities

  • As a Senior Application Security Engineer, you will be the driving force behind application security at Fabric, operating as a partner to engineering rather than a gatekeeper.
  • Your primary responsibilities will include: Secure Development & Code Review: Partner with engineering teams to embed security throughout the SDLC across Fabric's Ruby on Rails, Python, React, and Node.js applications.
  • Threat Modeling & Assessment: Lead threat modeling exercises for new features and architectural changes.
  • Conduct application penetration testing and vulnerability assessments across the platform, prioritizing findings and working directly with engineering to drive remediation.
  • DevSecOps & Tooling: Implement and manage SAST and DAST tooling integrated into CI/CD pipelines.
  • Build security guardrails and automated checks that allow engineering to move fast without introducing risk to the platform or patient data.
  • Serve as the internal subject matter expert on application security and lead response to application-layer security incidents.
  • Why You Might Be a Good Fit You think like an attacker and build like an engineer.
  • You prefer working in a mature, established security program over building and defining one.
  • Partner with engineering teams to embed security throughout the SDLC across Fabric's Ruby on Rails, Python, React, and Node.js applications.

Requirements

  • 5+ years of experience in application security with hands-on experience in security assessments, penetration testing, and secure code review.
  • Proficiency in at least one language in Fabric's stack: Ruby, Python, JavaScript/TypeScript, or similar.
  • Experience integrating SAST and DAST tooling into CI/CD pipelines.
  • Experience with threat modeling methodologies.
  • Familiarity with cloud security in AWS environments.
  • Familiarity with EHR integration security including FHIR, HL7, Epic, or Cerner APIs.
  • Experience with bug bounty program management.
  • You are as comfortable in a codebase as you are writing a threat model.
  • You are primarily a compliance or GRC-focused security professional and are not comfortable getting into the code.

Compensation

  • $130k-$160k

Benefits

  • About the Role Fabric handles protected health information at scale across 75+ health systems and millions of patient encounters.
  • Bonus Points Experience securing healthcare applications or working with PHI.
  • Security Education & Culture: Run secure coding training and awareness programs for engineering teams.
  • You understand that in healthcare, a vulnerability is not just a technical problem.
  • You prefer building guardrails and education programs over reactive patching.
  • You are energized by building a security practice and shaping how a fast-growing company approaches application security.

Company info

  • Run secure coding training and awareness programs for engineering teams.
  • It is a patient safety and compliance problem.
  • You can communicate security risk to engineering teams in a way that drives action, not defensiveness.
  • This Might Not Be The Right Fit If...
  • You are not comfortable working closely with engineering as a partner rather than an oversight function.
  • You do not have experience in a regulated environment where security decisions carry direct compliance implications.
  • Your Qualifications 5+ years of experience in application security with hands-on experience in security assessments, penetration testing, and secure code review.

This listing is sourced directly from Fabrichealth's careers page and normalized into a canonical job model.