资深应用安全工程师
Staff Application Security Engineer
关于ABRIDGE
ABRIDGE成立于2018年,使命是推动医疗领域的更深入理解。我们的AI驱动平台专为医疗对话设计,提高临床文档效率的同时,让临床医生专注于最重要的事情——他们的患者。
我们的企业级技术能够实时将患者与临床医生的对话转化为结构化临床记录,并深度集成电子病历系统。由Linked Evidence和我们专为审计设计的AI提供支持,我们是唯一一家将AI生成的摘要映射到真实数据的公司,帮助医护人员快速信任并验证输出结果。作为生成式AI在医疗领域的先驱,我们正在为AI在医疗系统中的负责任部署设定行业标准。
我们是一支不断壮大的团队,成员包括执业医生、AI科学家、博士、创意人员、技术人员和工程师,大家共同努力赋能人们,让医疗更有意义。我们在旧金山的Mission District、纽约苏荷区和匹兹堡的East Liberty设有办公室。
职位描述
想要在全球医疗AI的最前沿构建安全体系吗?我们正在寻找一位经验非常丰富且高度积极的资深应用安全工程师加入我们的Abridge安全团队,成为该团队的首批工程师之一。在这个职位上,你将成为关键的技术领导者,推动塑造我们产品、基础设施和工程实践的关键项目。影响整个产品组合的安全软件开发生命周期(SDLC)的愿景和实际执行。你将与产品和工程团队跨职能合作,无缝集成安全功能,自动化安全能力和控制措施,并指导他人在AI时代大规模构建默认安全的系统。该职位需要深厚的技术专业知识、建设者思维以及出色的沟通能力,以在整个组织中影响安全文化。
你将负责的工作
安全开发与架构领导力
- 领导威胁建模和设计评审:从产品构思到代码上线生产环境,影响产品。对复杂系统、新产品和平台项目进行高级威胁建模和安全架构评审,提供专家指导和要求,以满足ABRIDGE的安全目标。
- 制定安全策略:制定并实施技术路线图
查看英文原文
ABOUT ABRIDGE
Abridge was founded in 2018 with the mission of powering deeper understanding in healthcare. Our AI-powered platform was purpose-built for medical conversations, improving clinical documentation efficiencies while enabling clinicians to focus on what matters most—their patients.
Our enterprise-grade technology transforms patient-clinician conversations into structured clinical notes in real-time, with deep EMR integrations. Powered by Linked Evidence and our purpose-built, auditable AI, we are the only company that maps AI-generated summaries to ground truth, helping providers quickly trust and verify the output. As pioneers in generative AI for healthcare, we are setting the industry standards for the responsible deployment of AI across health systems.
We are a growing team of practicing MDs, AI scientists, PhDs, creatives, technologists, and engineers working together to empower people and make care make more sense. We have offices located in the Mission District in San Francisco, the SoHo neighborhood of New York, and East Liberty in Pittsburgh.
THE ROLE
Want to work on building out security from the ground up at the leading edge of AI in healthcare globally? We're looking for a very experienced and highly motivated Staff Application Security Engineer to join our team as one of the first engineers on the Abridge Security team. In this role, you'll be a key technical leader, driving key initiatives that shape our product, infrastructure, and engineering practices. Impact both the vision and hands-on execution of our secure software development lifecycle (SDLC) across the entire product portfolio. You'll work cross-functionally with product and engineering teams to integrate security seamlessly, automate security capabilities and controls, and mentor others to build secure-by-default systems at scale in the age of AI. This position requires deep technical expertise, a builder's mindset, and excellent communication skills to influence security culture across the organization.
WHAT YOU’LL DO
SECURE DEVELOPMENT & ARCHITECTURE LEADERSHIP
- Lead Threat Modeling and Design Reviews: Impact the product from ideation through to code that is shipping to production. Conduct advanced threat modeling and security architecture reviews for complex systems, new products, and platform initiatives, providing expert guidance and requirements to meet Abridge’s security goals.
- Define Security Strategy: Define and implement the technical roadmap for the Application Security program, focusing on scalable assurance, proactive security measures, and setting clear standards and guardrails.
- Mentor and Enable: Act as a subject matter expert and trusted advisor to product and engineering teams, providing mentorship on security features, product defense, secure coding practices, application architecture, and vulnerability remediation strategies.
- Conduct Training & Awareness: Develop training materials for engineers to build a foundation of security best practices across the engineering organization.
VULNERABILITY MANAGEMENT & INCIDENT RESPONSE
- Code and Security Reviews: Perform and lead in-depth secure code reviews (both manual and tool-assisted) to identify complex security vulnerabilities and flaws, including logic and authorization vulnerabilities that automated tools often miss. Get hands on with assessing AI models, agents, and architectures.
- Internal Penetration Testing: Lead internal penetration testing engagements for net new products and historical systems identify security risks across our environment.
- Vulnerability Program Oversight: Design and enhance the end-to-end vulnerability management program for Abridge’s products and applications, ensuring timely identification, prioritization, and remediation of critical security issues while doing so in as developer-friendly a way as possible.
- Security Incident Response: Serve as an expert on Abridge’s products and applications for the security incident response team, assisting in investigating and resolving security events and incidents.
WHAT YOU’LL BRING
- Experience: 10+ years of direct experience in an Application Security role, with a demonstrated history of designing and implementing security improvements at scale.
- Programming Fluency: Deep proficiency in one or more major programming languages (Python and NextJS a big plus) and a solid background in software development principles.
- Cloud & Containers: Extensive experience securing applications deployed in Cloud environments (GCP a big plus) and knowledge of containerization technologies (Kubernetes).
- Technical Depth: Expert-level knowledge of web application security techniques and principles, APIs, IAM (including identity, authentication/authorization, RBAC, ABAC), applied cryptography, etc.
- AI Security: Deep understanding of the security of AI and ML models, agents, and associated systems.
BONUS POINTS IF…
- Security Research: Proven experience contributing to or leveraging open-source security tools, publishing security research, managing bug bounty programs, and active engagement in the security industry.
- Cross-Functional Influence: Demonstrated ability to drive large, cross-functional technical projects that impact security posture across the entire organization.
- Data-Driven Security: Experience defining and utilizing security metrics to measure and report on the effectiveness of the AppSec program to both technical and executive audiences.
WHY WORK AT ABRIDGE?
At Abridge, we’re transforming healthcare delivery experiences with generative AI, enabling clinicians and patients to connect in deeper, more meaningful ways. Our mission is clear: to power deeper understanding in healthcare. We’re driving real, lasting change, with millions of medical conversations processed each month.
Joining Abridge means stepping into a fast-paced, high-growth startup where your contributions truly make a difference. Our culture requires extreme ownership—every employee has the ability to (and is expected to) make an impact on our customers and our business.
Beyond individual impact, you will have the opportunity to work alongside a team of curious, high-achieving people in a supportive environment where success is shared, growth is constant, and feedback fuels progress. At Abridge, it’s not just what we do—it’s how we do it. Every decision is rooted in empathy, always prioritizing the needs of clinicians and patients.
We’re committed to supporting your growth, both professionally and personally. Whether it's flexible work hours, an inclusive culture, or ongoing learning opportunities, we are here to help you thrive and do the best work of your life.
If you are ready to make a meaningful impact alongside passionate people who care deeply about what they do, Abridge is the place for you.
HOW WE TAKE CARE OF ABRIDGERS:
- Generous Time Off: 14 paid holidays, flexible PTO for salaried employees, and accrued time off for hourly employees
- Comprehensive Health Plans: Medical, Dental, and Vision coverage for all full-time employees and their families.
- Generous HSA Contribution: If you choose a High Deductible Health Plan, Abridge makes monthly contributions to your HSA.
- Paid Parental Leave: Generous paid parental leave for all full-time employees.
- Family Forming Benefits: Resources and financial support to help you build your family.
- 401(k) Matching: Contribution matching to help invest in your future.
- Personal Device Allowance: Tax free funds for personal device usage.
- Pre-tax Benefits: Access to Flexible Spending Accounts (FSA) and Commuter Benefits.
- Lifestyle Wallet: Monthly contributions for fitness, professional development, coworking, and more.
- Mental Health Support: Dedicated access to therapy and coaching to help you reach your goals.
- Sabbatical Leave: Paid Sabbatical Leave after 5 years of employment.
- Compensation and Equity: Competitive compensation and equity grants for full time employees.
- ... and much more!
EQUAL OPPORTUNITY EMPLOYER
Abridge is an equal opportunity employer and considers all qualified applicants equally without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, or disability.
We're committed to providing reasonable accommodations throughout the interview process. Once you submit your application, we'll follow up with details on how to request an accommodation for interviewing, completing any assessments, or otherwise participating in the selection process.
STAYING SAFE - PROTECT YOURSELF FROM RECRUITMENT FRAUD
We are aware of individuals and entities fraudulently representing themselves as Abridge recruiters and/or hiring managers. Abridge will never ask for financial information or payment, or for personal information such as bank account number or social security number during the job application or interview process. Any emails from the Abridge recruiting team will come from an @abridge.com http://abridge.com email address. You can learn more about how to protect yourself from these types of fraud by referring to this article https://consumer.ftc.gov/consumer-alerts/2023/05/scammers-are-hijacking-job-ads-heres-how-spot-fakes. Please exercise caution and cease communications if something feels suspicious about your interactions.