Senior Application Security Engineer
Abridge · San Francisco, United States
About The Role
Join Abridge, a leading AI healthcare company, as a Senior Application Security Engineer. In this role, you'll drive key initiatives that shape our product, infrastructure, and engineering practices. You'll work cross-functionally with product and engineering teams to integrate security seamlessly, automate security capabilities and controls, and mentor others to build secure-by-default systems at scale. You'll also lead threat modeling and design reviews, define security strategy, mentor and enable teams, build security pipelines, manage tools, drive proactive security, conduct code and security reviews, oversee the vulnerability program, and assist in security incident response. Enjoy a remote work environment, equity for all new employees, generous parental leave, flexible working hours, unlimited PTO, and a generous equipment budget for your home office setup.
- Conduire des initiatives clés qui façonnent notre produit, notre infrastructure et nos pratiques d'ingénierie en matière de sécurité.
- Définir et mettre en œuvre la feuille de route technique pour le programme de sécurité des applications, en mettant l'accent sur l'assurance évolutive et les mesures de sécurité proactives.
- Agir en tant qu'expert en la matière et conseiller de confiance pour les équipes produit et ingénierie, en fournissant des conseils sur les fonctionnalités de sécurité, la défense des produits, les pratiques de codage sécurisé.
- This position requires deep technical expertise, a builder's mindset, and excellent communication skills to influence security culture across the organization
- Technical Depth: Expert-level knowledge of web application security techniques and principles, APIs, IAM (including identity, authentication/authorization, RBAC, ABAC), applied cryptography, etc
- AI Security: Deep understanding of the security of AI and ML models, agents, and associated systems
- Cloud & Containers: Extensive experience securing applications deployed in Cloud environments (GCP a big plus) and knowledge of containerization technologies (Kubernetes)
- Experience: 7+ years of direct experience in an Application Security role, with a demonstrated history of designing and implementing security improvements at scale
- Programming Fluency: Deep proficiency in one or more major programming languages (Python and NextJS a big plus) and a solid background in software development principles
- Cross-Functional Influence: Demonstrated ability to drive large, cross-functional technical projects that impact security posture across the entire organization
- Security Research: Proven experience contributing to or leveraging open-source security tools, publishing security research, managing bug bounty programs, and active engagement in the security industry
- Data-Driven Security: Experience defining and utilizing security metrics to measure and report on the effectiveness of the AppSec program to both technical and executive audiences
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring