> Markdown version of [/jobs/ext/545775-staff-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/545775-staff-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Staff Application Security Engineer - **Company:** Abridge Partners, LLC - **Location:** San Francisco, CA, United States (Remote available) - **Experience:** Expert - **Salary:** $228,000.0 - $290,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Applications Architecture, Software System Penetration Testing, User Authentication, Cloud Computing, Cyber Security, Identity and Access Management, Open Source Technology, Role-Based Access Control, Secure Coding, Web Application Security, Software Engineering, Software Vulnerability Management, Cloud Platform System, Software Security, Containerization, Kubernetes, Data Analytics, Vulnerability Analysis - **Published:** June 14, 2026 - **Apply:** https://www.welcometothejungle.com/en/companies/abridge/jobs/staff-application-security-engineer_san-francisco_cavlhovx ## About the Role * Programming Fluency: Deep proficiency in one or more major programming languages (Python and NextJS a big plus) and a solid background in software development principles * Cloud & Containers: Extensive experience securing applications deployed in Cloud environments (GCP a big plus) and knowledge of containerization technologies (Kubernetes) * AI Security: Deep understanding of the security of AI and ML models, agents, and associated systems * Technical Depth: Expert-level knowledge of web application security techniques and principles, APIs, IAM (including identity, authentication/authorization, RBAC, ABAC), applied cryptography, etc * Experience: 10+ years of direct experience in an Application Security role, with a demonstrated history of designing and implementing security improvements at scale * Security Research: Proven experience contributing to or leveraging open-source security tools, publishing security research, managing bug bounty programs, and active engagement in the security industry * Cross-Functional Influence: Demonstrated ability to drive large, cross-functional technical projects that impact security posture across the entire organization * Data-Driven Security: Experience defining and utilizing security metrics to measure and report on the effectiveness of the AppSec program to both technical and executive audiences ## Description * Want to work on building out security from the ground up at the leading edge of AI in healthcare globally? * We're looking for a very experienced and highly motivated Staff Application Security Engineer to join our team as one of the first engineers on the Abridge Security team * In this role, you'll be a key technical leader, driving key initiatives that shape our product, infrastructure, and engineering practices * Impact both the vision and hands-on execution of our secure software development lifecycle (SDLC) across the entire product portfolio * You'll work cross-functionally with product and engineering teams to integrate security seamlessly, automate security capabilities and controls, and mentor others to build secure-by-default systems at scale in the age of AI * This position requires deep technical expertise, a builder's mindset, and excellent communication skills to influence security culture across the organization * Secure Development & Architecture Leadership * Lead Threat Modeling and Design Reviews: Impact the product from ideation through to code that is shipping to production. Conduct advanced threat modeling and security architecture reviews for complex systems, new products, and platform initiatives, providing expert guidance and requirements to meet Abridge's security goals * Define Security Strategy: Define and implement the technical roadmap for the Application Security program, focusing on scalable assurance, proactive security measures, and setting clear standards and guardrails * Mentor and Enable: Act as a subject matter expert and trusted advisor to product and engineering teams, providing mentorship on security features, product defense, secure coding practices, application architecture, and vulnerability remediation strategies * Conduct Training & Awareness: Develop training materials for engineers to build a foundation of security best practices across the engineering organization * Vulnerability Management & Incident Response * Code and Security Reviews: Perform and lead in-depth secure code reviews (both manual and tool-assisted) to identify complex security vulnerabilities and flaws, including logic and authorization vulnerabilities that automated tools often miss. Get hands on with assessing AI models, agents, and architectures * Internal Penetration Testing: Lead internal penetration testing engagements for net new products and historical systems identify security risks across our environment * Vulnerability Program Oversight: Design and enhance the end-to-end vulnerability management program for Abridge's products and applications, ensuring timely identification, prioritization, and remediation of critical security issues while doing so in as developer-friendly a way as possible * Security Incident Response: Serve as an expert on Abridge's products and applications for the security incident response team, assisting in investigating and resolving security events and incidents ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) - [How GitHub secures open source](https://www.wearedevelopers.com/videos/1450-how-github-secures-open-source) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) ## Related Articles - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)