This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We're looking for a very experienced and highly motivated Senior or Staff Application Security Engineer to join our team as one of the first engineers on the Abridge Security team. In this role, you'll be a key technical leader, driving key initiatives that shape our product, infrastructure, and engineering practices. Impact both the vision and hands-on execution of our secure software development lifecycle (SDLC) across the entire product portfolio. You'll work cross-functionally with product and engineering teams to integrate security seamlessly, automate security capabilities and controls, and mentor others to build secure-by-default systems at scale in the age of AI.
Job Responsibility:
Lead Threat Modeling and Design Reviews
Conduct advanced threat modeling and security architecture reviews for complex systems, new products, and platform initiatives
Define and implement the technical roadmap for the Application Security program
Act as a subject matter expert and trusted advisor to product and engineering teams
Design, implement, and maintain advanced security automation tools and services
Own the deployment, configuration, and maintenance of AppSec tooling
Develop custom scripts and tooling to automate repetitive security tasks
Perform and lead in-depth secure code reviews
Oversee the end-to-end vulnerability management program
Serve as an expert for the security incident response team
Requirements:
7+ years of direct experience in an Application Security role
Demonstrated history of designing and implementing security improvements at scale
Deep proficiency in one or more major programming languages (Python and NextJS a big plus)
Solid background in software development principles
Extensive experience securing applications deployed in Cloud environments (GCP a big plus)
Knowledge of containerization technologies (Kubernetes)
Expert-level knowledge of web application security techniques and principles, APIs, IAM (including identity, authentication/authorization, RBAC, ABAC), applied cryptography
Hands-on experience integrating security testing and tooling (SAST, DAST, SCA, IaC, WAF, etc.) and gates into modern development workflows and CI/CD systems
Nice to have:
Deep understanding of the security of AI and ML models, agents, and associated systems
Proven experience contributing to or leveraging open-source security tools, publishing security research, managing bug bounty programs, and active engagement in the security industry
Demonstrated ability to drive large, cross-functional technical projects that impact security posture across the entire organization
Experience defining and utilizing security metrics to measure and report on the effectiveness of the AppSec program to both technical and executive audiences
What we offer:
Generous Time Off: 14 paid holidays, flexible PTO for salaried employees
Comprehensive Health Plans: Medical, Dental, and Vision coverage
Generous HSA Contribution
Paid Parental Leave
Family Forming Benefits
401(k) Matching
Personal Device Allowance
Pre-tax Benefits: Access to Flexible Spending Accounts (FSA) and Commuter Benefits
Lifestyle Wallet: Monthly contributions for fitness, professional development, coworking