Director of Product Security (San Francisco) Job at Abridge, San Francisco, CA

NUZKMUtWV1Q4WkxXb0VUWWp5ZWNuTXRrK3c9PQ==
  • Abridge
  • San Francisco, CA

Job Description

About Abridge

Abridge was founded in 2018 with the mission of powering deeper understanding in healthcare. Our AI-powered platform was purpose-built for medical conversations, improving clinical documentation efficiencies while enabling clinicians to focus on what matters mosttheir patients. Our enterprise-grade technology transforms patientclinician conversations into structured clinical notes in realtime, with deep EMR integrations. Powered by Linked Evidence and our purpose-built, auditable AI, we are the only company that maps AI-generated summaries to ground truth, helping providers quickly trust and verify the output. As pioneers in generative AI for healthcare, we are setting the industry standards for the responsible deployment of AI across health systems. We are a growing team of practicing MDs, AI scientists, PhDs, creatives, technologists, and engineers working together to empower people and make care make more sense. We have offices located in the Mission District in San Francisco, the SoHo neighborhood of New York, and East Liberty in Pittsburgh.

Base pay range

$306,000.00/yr - $360,000.00/yr

Role

Director of Product Security will be responsible for defining and driving the overall Product Security strategy, focusing on security assurance, proactive risk reduction, secure AI innovation, and maintaining a world-class security posture across all product offerings and our multicloud infrastructure. You will lead and scale highimpact programs, manage teams of talented security professionals, and serve as a strategic partner to the CISO and executive leadership. You will report directly to the Chief Information Security Officer (CISO).

What You'll Do

  • Strategic Leadership & Security as a Business
  • Product Security Strategy: Define and continuously evolve the longterm Product Security strategy, ensuring alignment with Abridge.ai's business goals and technological advancements.
  • Security Roadmap Ownership: Own the creation and execution of the Product Security roadmap, including security features, SDLC enhancements, threat modeling initiatives, and overall risk reduction milestones.
  • Financial Oversight: Manage the Product Security budget, including forecasting security tool expenditures, vendor contracts, and personnel resource allocation.
  • MetricDriven Management: Define, track, and report on key performance indicators (KPIs) and security metrics to measure the effectiveness of all security programs and provide datadriven insights to leadership.
  • Impact Analysis: Conduct regular impact analysis (ROI) of security investments and lead time/costreduction efforts. Translate complex security risks into clear business risk terms to justify strategic initiatives.
  • People & Program Leadership
  • Lead and Mentor: Serve as a motivating people leader for a growing team of Security Engineers and Analysts, providing career development, mentorship, and regular performance feedback.
  • Strategy and Scaling: Define and execute on goals in a hypergrowth AI company, focusing on enabling secure AI development and deployment globally.
  • Security Industry Engagement: Actively participate in and be a thought leader for the security industry by giving talks at conferences, publishing papers, hosting forums, etc.
  • Cloud Security (CloudSec) and Infrastructure
  • MultiCloud Strategy: Define the security architecture and strategy for our cloud environments (GCP, AWS, Azure, etc.).
  • Containerization Security: Lead the implementation of security controls for containerized applications, with a deep focus on securing Kubernetes clusters, including network policies and secrets management.
  • IaC Security: Implement security guardrails within Infrastructure as Code (e.g., Terraform) to ensure all cloud resources are provisioned securely.
  • Application Security (AppSec) & Secure SDLC
  • Integrate Security: Partner with Engineering and Product leadership to embed security processes into the Software Development Lifecycle (SDLC).
  • Security Practices: Develop and oversee secure coding practices, security architecture reviews, and static/dynamic code analysis practices across all applications.
  • Vulnerability Management: Direct the vulnerability management and penetration testing programs, ensuring comprehensive coverage and rapid, prioritized remediation of findings.
  • Data Security, AI/ML Model Security, & Cryptography
  • Data Protection: Lead the data security program, focusing on the protection, encryption, and access controls for highly sensitive patient data (PII, PHI, AI models, etc.).
  • AI/ML Security: Establish security engineering practices for our AI/ML models and pipeline, including model integrity, adversarial attack prevention, model redteaming, securing agentic AI, etc.

What Youll Bring

  • Experience: 10+ years of progressive experience in security, with a minimum of 10 years leading security teams, programs, or largescale initiatives in a senior leadership capacity.
  • Business Acumen: Demonstrated experience running security as a business unit, including budget management, strategic forecasting, and translating technical risk into business impact (ROI).
  • Engineering Proficiency: Must be proficient, at an engineering level, in at least one or more generalpurpose programming languages. Experience with Python and/or NextJS is a significant plus.
  • Cloud Expertise: Deep technical expertise in securing at least one major cloud platform (GCP, AWS, or Azure) and demonstrable experience with modern cloud security principles and tools.
  • Containerization: Mandatory expertise in securing container orchestration technologies, specifically Kubernetes.
  • Industry Knowledge: Proven experience securing products (enterprise SaaS, cloud environments) handling highly sensitive data, such as Protected Health Information (PHI), with specific knowledge of NIST 80053 / 800171, FedRAMP, HIPAA, NIS2 and other relevant security and privacy regulations and frameworks.
  • Communication: Exceptional communication and presentation skills, with the ability to convey complex security issues and technical risks to both technical and nontechnical audiences, including executives, customers, government agencies, and board members.

Why Work at Abridge?

At Abridge, were transforming healthcare delivery experiences with generative AI, enabling clinicians and patients to connect in deeper, more meaningful ways. Our mission is clear: to power deeper understanding in healthcare. Were driving real, lasting change, with millions of medical conversations processed each month. Joining Abridge means stepping into a fastpaced, highgrowth startup where your contributions truly make a difference. Our culture requires extreme ownershipevery employee has the ability to (and is expected to) make an impact on our customers and our business. Beyond individual impact, you will have the opportunity to work alongside a team of curious, highachieving people in a supportive environment where success is shared, growth is constant, and feedback fuels progress. At Abridge, its not just what we doits how we do it. Every decision is rooted in empathy, always prioritizing the needs of clinicians and patients. Were committed to supporting your growth, both professionally and personally. Whether it's flexible work hours, an inclusive culture, or ongoing learning opportunities, we are here to help you thrive and do the best work of your life. If you are ready to make a meaningful impact alongside passionate people who care deeply about what they do, Abridge is the place for you.

How we take care of Abridgers?

  • Generous Time Off: 14 paid holidays, flexible PTO for salaried employees, and accrued time off for hourly employees
  • Comprehensive Health Plans: Medical, Dental, and Vision coverage for all fulltime employees and their families.
  • Generous HSA Contribution: If you choose a High Deductible Health Plan, Abridge makes monthly contributions to your HSA.
  • Paid Parental Leave: Generous paid parental leave for all fulltime employees.
  • Family Forming Benefits: Resources and financial support to help you build your family.
  • 401(k) Matching: Contribution matching to help invest in your future.
  • Personal Device Allowance: Tax free funds for personal device usage.
  • Pretax Benefits: Access to Flexible Spending Accounts (FSA) and Commuter Benefits.
  • Lifestyle Wallet: Monthly contributions for fitness, professional development, coworking, and more.
  • Mental Health Support: Dedicated access to therapy and coaching to help you reach your goals.
  • Sabbatical Leave: Paid Sabbatical Leave after 5 years of employment.
  • Compensation and Equity: Competitive compensation and equity grants for full time employees.
  • and much more!

Equal Opportunity Employer

Abridge is an equal opportunity employer and considers all qualified applicants equally without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, or disability.

Staying safe - Protect yourself from recruitment fraud

We are aware of individuals and entities fraudulently representing themselves as Abridge recruiters and/or hiring managers. Abridge will never ask for financial information or payment, or for personal information such as bank account number or social security number during the job application or interview process. Any emails from the Abridge recruiting team will come from an @abridge.com email address. You can learn more about how to protect yourself from these types of fraud by referring to this article. Please exercise caution an]]> <

Job Tags

Hourly pay, Full time, Flexible hours,

Similar Jobs

Wipro Givon USA

Quality Supervisor Job at Wipro Givon USA

 ...insurance ~ Health insurance ~ Paid time off ~ Training & development ~ Vision insurance Company Benefits Why work with Wipro Givon ~ Competitive Base Pay 90,000 - 110,000/year DOE ~ Excellent Health, Dental, and Vision options ~ Paid Time Off and... 

Vertiv

Field Service Technician (Electrical / Electronic Equipment) Job at Vertiv

 ...Field Service Technician (Electrical / Electronic Equipment) at Vertiv summary: The Field Service Technician at Vertiv performs scheduled...  ...equipment such as UPS and power distribution units in data centers and commercial environments. The role requires technical skills... 

TradeJobsWorkforce

American Airlines Customer Service Agent Job at TradeJobsWorkforce

 ...Step into American Airlines Customer Service Agent and support smooth travel and on-time operations. In this role, youll assist passengers, coordinate ground tasks, and follow safety procedures, staying on schedule and working with care. Success comes from people who bring... 

Milked Media

Paid Social + Email Graphic Designer Job at Milked Media

 ...Milked Media is a female-led creative agency that specializes in paid social + search, email marketing and content creation for fashion, jewelry, beauty, and home e-commerce brands. Job Description **MUST INCLUDE EXAMPLES OF DESIGN WORK WITH APPLICATION IN ORDER... 

Sioux Falls School District

Community Relations Clerical - Class III... Job at Sioux Falls School District

 ...paid is $23.23 per hour. Pay Day Last working day of each month. Hours Monday through Friday, 8:00am to 5:00pm with a 1 hour unpaid break Summer hours: Monday through Thursday: 7:00am to 5:30pm with a 30-minute lunch break FTE 1.0 FTE, 40 hours/week,...