Senior Application Security Engineer
Remote • SF Office • FullTime
Posted 1y ago
Remote Work Policy
Fully remote
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
Abridge is seeking a highly experienced and motivated Senior Application Security Engineer to join their growing team. This is a key technical leadership role focused on building security from the ground up at the forefront of AI in healthcare. You will shape product, infrastructure, and engineering practices by impacting the vision and execution of the secure software development lifecycle (SDLC) across the entire product portfolio. The role involves collaborating with product and engineering teams to integrate security seamlessly, automate security controls, and foster a secure-by-default culture. This position demands deep technical expertise, a builder's mindset, and strong communication skills to influence security across the organization.
Responsibilities
- Lead threat modeling and security architecture reviews for complex systems and new products.
- Define and implement the technical roadmap for the Application Security program.
- Mentor product and engineering teams on security features, secure coding, and vulnerability remediation.
- Develop and deliver security best practices training for engineers.
- Perform and lead in-depth secure code reviews, including for AI models, agents, and architectures.
- Lead internal penetration testing engagements for new and existing systems.
- Design and enhance the end-to-end vulnerability management program.
- Serve as an expert for the security incident response team, assisting in investigations and resolutions.
Requirements
- 7+ years of direct experience in an Application Security role.
- Demonstrated history of designing and implementing security improvements at scale.
- Deep proficiency in one or more major programming languages (Python and NextJS are a plus).
- Solid background in software development principles.
- Extensive experience securing applications in Cloud environments (GCP is a plus).
- Knowledge of containerization technologies (Kubernetes).
- Expert-level knowledge of web application security techniques and principles.
- Expert-level knowledge of APIs, IAM (identity, authentication/authorization, RBAC, ABAC).
- Expert-level knowledge of applied cryptography.
- Deep understanding of the security of AI and ML models, agents, and associated systems.