Staff Application Security Engineer
Remote • SF Office • FullTime
Posted 1mo ago
Remote Work Policy
Fully remote
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
Abridge is seeking a highly experienced and motivated Staff Application Security Engineer to join their growing team. This role is a key technical leadership position focused on building security from the ground up at the forefront of AI in healthcare. You will shape product, infrastructure, and engineering practices by impacting the vision and execution of the secure software development lifecycle across the entire product portfolio. This involves working cross-functionally to integrate security seamlessly, automate security capabilities, and mentor others in building secure-by-default systems at scale in the age of AI. The ideal candidate possesses deep technical expertise, a builder's mindset, and excellent communication skills to influence security culture.
Responsibilities
- Lead threat modeling and security architecture reviews for complex systems and new products.
- Define and implement the technical roadmap for the Application Security program.
- Mentor product and engineering teams on security features, secure coding practices, and vulnerability remediation.
- Develop training materials for engineers on security best practices.
- Perform and lead in-depth secure code reviews, including assessing AI models, agents, and architectures.
- Lead internal penetration testing engagements for new and existing systems.
- Design and enhance the vulnerability management program for products and applications.
- Serve as an expert for the security incident response team, assisting in investigations and resolutions.
Requirements
- 10+ years of direct experience in an Application Security role with a history of implementing security improvements at scale.
- Deep proficiency in one or more major programming languages (Python and NextJS are a plus).
- Solid background in software development principles.
- Extensive experience securing applications in Cloud environments (GCP is a plus).
- Knowledge of containerization technologies (Kubernetes).
- Expert-level knowledge of web application security techniques, APIs, IAM, and applied cryptography.
- Deep understanding of the security of AI and ML models, agents, and associated systems.