Skip to main content
Abridge

Staff Application Security Engineer

RemoteUnited States only
Published
Role
Security
Experience
Staff
Employment
Full-time
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Abridge is seeking an experienced Staff Application Security Engineer to join their security team. This role involves leading security initiatives, shaping product and infrastructure security, driving the secure software development lifecycle, and mentoring engineering teams on secure practices, with a focus on AI in healthcare.

Core skills

GCPKubernetesIAM

Required skills

PythonNext.jsAPIsapplied cryptography

What you'll do

  • Lead Threat Modeling and Design Reviews for complex systems, new products, and platform initiatives, providing expert guidance and requirements to meet Abridge’s security goals.
  • Define and implement the technical roadmap for the Application Security program, focusing on scalable assurance, proactive security measures, and setting clear standards and guardrails.
  • Act as a subject matter expert and trusted advisor to product and engineering teams, providing mentorship on security features, product defense, secure coding practices, application architecture, and vulnerability remediation strategies.
  • Perform and lead in-depth secure code reviews (both manual and tool-assisted) to identify complex security vulnerabilities and flaws, including logic and authorization vulnerabilities that automated tools often miss.
  • Lead internal penetration testing engagements for net new products and historical systems to identify security risks across our environment.

What they require

  • 10+ years of direct experience in an Application Security role, with a demonstrated history of designing and implementing security improvements at scale.
  • Deep proficiency in one or more major programming languages (Python and NextJS a big plus) and a solid background in software development principles.
  • Extensive experience securing applications deployed in Cloud environments (GCP a big plus) and knowledge of containerization technologies (Kubernetes).
  • Expert-level knowledge of web application security techniques and principles, APIs, IAM (including identity, authentication/authorization, RBAC, ABAC), applied cryptography, etc.
  • Deep understanding of the security of AI and ML models, agents, and associated systems.

Abridge was founded in 2018 with the mission of powering deeper understanding in healthcare. Our AI-powered platform was purpose-built for medical conversations, improving clinical documentation efficiencies while enabling clinicians to focus on what matters most—their patients. Our enterprise-grade technology transforms patient-clinician conversations into structured clinical notes in real-time, with deep EMR integrations. Powered by Linked Evidence and our purpose-built, auditable AI, we are the only company that maps AI-generated summaries to ground truth, helping providers quickly trust and verify the output. As pioneers in generative AI for healthcare, we are setting the industry standards for the responsible deployment of AI across health systems. We are a growing team of practicing MDs, AI scientists, PhDs, creatives, technologists, and engineers working together to empower people and make care make more sense. We have offices located in the Mission District in San Francisco, the SoHo neighborhood of New York, and East Liberty in Pittsburgh.

🇺🇸 United StatesHealthcareStartup
Salary not disclosed