Director of Product Security (San Francisco) Job at Abridge, San Francisco, CA

Y0s2bFVGOVpFQTNyRitaREs5M1dLcWdwaVE9PQ==
  • Abridge
  • San Francisco, CA

Job Description

About Abridge

Abridge was founded in 2018 with the mission of powering deeper understanding in healthcare. Our AI-powered platform was purpose-built for medical conversations, improving clinical documentation efficiencies while enabling clinicians to focus on what matters mosttheir patients. Our enterprise-grade technology transforms patientclinician conversations into structured clinical notes in realtime, with deep EMR integrations. Powered by Linked Evidence and our purpose-built, auditable AI, we are the only company that maps AI-generated summaries to ground truth, helping providers quickly trust and verify the output. As pioneers in generative AI for healthcare, we are setting the industry standards for the responsible deployment of AI across health systems. We are a growing team of practicing MDs, AI scientists, PhDs, creatives, technologists, and engineers working together to empower people and make care make more sense. We have offices located in the Mission District in San Francisco, the SoHo neighborhood of New York, and East Liberty in Pittsburgh.

Base pay range

$306,000.00/yr - $360,000.00/yr

Role

Director of Product Security will be responsible for defining and driving the overall Product Security strategy, focusing on security assurance, proactive risk reduction, secure AI innovation, and maintaining a world-class security posture across all product offerings and our multicloud infrastructure. You will lead and scale highimpact programs, manage teams of talented security professionals, and serve as a strategic partner to the CISO and executive leadership. You will report directly to the Chief Information Security Officer (CISO).

What You'll Do

  • Strategic Leadership & Security as a Business
  • Product Security Strategy: Define and continuously evolve the longterm Product Security strategy, ensuring alignment with Abridge.ai's business goals and technological advancements.
  • Security Roadmap Ownership: Own the creation and execution of the Product Security roadmap, including security features, SDLC enhancements, threat modeling initiatives, and overall risk reduction milestones.
  • Financial Oversight: Manage the Product Security budget, including forecasting security tool expenditures, vendor contracts, and personnel resource allocation.
  • MetricDriven Management: Define, track, and report on key performance indicators (KPIs) and security metrics to measure the effectiveness of all security programs and provide datadriven insights to leadership.
  • Impact Analysis: Conduct regular impact analysis (ROI) of security investments and lead time/costreduction efforts. Translate complex security risks into clear business risk terms to justify strategic initiatives.
  • People & Program Leadership
  • Lead and Mentor: Serve as a motivating people leader for a growing team of Security Engineers and Analysts, providing career development, mentorship, and regular performance feedback.
  • Strategy and Scaling: Define and execute on goals in a hypergrowth AI company, focusing on enabling secure AI development and deployment globally.
  • Security Industry Engagement: Actively participate in and be a thought leader for the security industry by giving talks at conferences, publishing papers, hosting forums, etc.
  • Cloud Security (CloudSec) and Infrastructure
  • MultiCloud Strategy: Define the security architecture and strategy for our cloud environments (GCP, AWS, Azure, etc.).
  • Containerization Security: Lead the implementation of security controls for containerized applications, with a deep focus on securing Kubernetes clusters, including network policies and secrets management.
  • IaC Security: Implement security guardrails within Infrastructure as Code (e.g., Terraform) to ensure all cloud resources are provisioned securely.
  • Application Security (AppSec) & Secure SDLC
  • Integrate Security: Partner with Engineering and Product leadership to embed security processes into the Software Development Lifecycle (SDLC).
  • Security Practices: Develop and oversee secure coding practices, security architecture reviews, and static/dynamic code analysis practices across all applications.
  • Vulnerability Management: Direct the vulnerability management and penetration testing programs, ensuring comprehensive coverage and rapid, prioritized remediation of findings.
  • Data Security, AI/ML Model Security, & Cryptography
  • Data Protection: Lead the data security program, focusing on the protection, encryption, and access controls for highly sensitive patient data (PII, PHI, AI models, etc.).
  • AI/ML Security: Establish security engineering practices for our AI/ML models and pipeline, including model integrity, adversarial attack prevention, model redteaming, securing agentic AI, etc.

What Youll Bring

  • Experience: 10+ years of progressive experience in security, with a minimum of 10 years leading security teams, programs, or largescale initiatives in a senior leadership capacity.
  • Business Acumen: Demonstrated experience running security as a business unit, including budget management, strategic forecasting, and translating technical risk into business impact (ROI).
  • Engineering Proficiency: Must be proficient, at an engineering level, in at least one or more generalpurpose programming languages. Experience with Python and/or NextJS is a significant plus.
  • Cloud Expertise: Deep technical expertise in securing at least one major cloud platform (GCP, AWS, or Azure) and demonstrable experience with modern cloud security principles and tools.
  • Containerization: Mandatory expertise in securing container orchestration technologies, specifically Kubernetes.
  • Industry Knowledge: Proven experience securing products (enterprise SaaS, cloud environments) handling highly sensitive data, such as Protected Health Information (PHI), with specific knowledge of NIST 80053 / 800171, FedRAMP, HIPAA, NIS2 and other relevant security and privacy regulations and frameworks.
  • Communication: Exceptional communication and presentation skills, with the ability to convey complex security issues and technical risks to both technical and nontechnical audiences, including executives, customers, government agencies, and board members.

Why Work at Abridge?

At Abridge, were transforming healthcare delivery experiences with generative AI, enabling clinicians and patients to connect in deeper, more meaningful ways. Our mission is clear: to power deeper understanding in healthcare. Were driving real, lasting change, with millions of medical conversations processed each month. Joining Abridge means stepping into a fastpaced, highgrowth startup where your contributions truly make a difference. Our culture requires extreme ownershipevery employee has the ability to (and is expected to) make an impact on our customers and our business. Beyond individual impact, you will have the opportunity to work alongside a team of curious, highachieving people in a supportive environment where success is shared, growth is constant, and feedback fuels progress. At Abridge, its not just what we doits how we do it. Every decision is rooted in empathy, always prioritizing the needs of clinicians and patients. Were committed to supporting your growth, both professionally and personally. Whether it's flexible work hours, an inclusive culture, or ongoing learning opportunities, we are here to help you thrive and do the best work of your life. If you are ready to make a meaningful impact alongside passionate people who care deeply about what they do, Abridge is the place for you.

How we take care of Abridgers?

  • Generous Time Off: 14 paid holidays, flexible PTO for salaried employees, and accrued time off for hourly employees
  • Comprehensive Health Plans: Medical, Dental, and Vision coverage for all fulltime employees and their families.
  • Generous HSA Contribution: If you choose a High Deductible Health Plan, Abridge makes monthly contributions to your HSA.
  • Paid Parental Leave: Generous paid parental leave for all fulltime employees.
  • Family Forming Benefits: Resources and financial support to help you build your family.
  • 401(k) Matching: Contribution matching to help invest in your future.
  • Personal Device Allowance: Tax free funds for personal device usage.
  • Pretax Benefits: Access to Flexible Spending Accounts (FSA) and Commuter Benefits.
  • Lifestyle Wallet: Monthly contributions for fitness, professional development, coworking, and more.
  • Mental Health Support: Dedicated access to therapy and coaching to help you reach your goals.
  • Sabbatical Leave: Paid Sabbatical Leave after 5 years of employment.
  • Compensation and Equity: Competitive compensation and equity grants for full time employees.
  • and much more!

Equal Opportunity Employer

Abridge is an equal opportunity employer and considers all qualified applicants equally without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, or disability.

Staying safe - Protect yourself from recruitment fraud

We are aware of individuals and entities fraudulently representing themselves as Abridge recruiters and/or hiring managers. Abridge will never ask for financial information or payment, or for personal information such as bank account number or social security number during the job application or interview process. Any emails from the Abridge recruiting team will come from an @abridge.com email address. You can learn more about how to protect yourself from these types of fraud by referring to this article. Please exercise caution an]]> <

Job Tags

Hourly pay, Full time, Flexible hours,

Similar Jobs

First Placement Services

Bobcat Operator (Recycling Center) Job at First Placement Services

 ...Position Overview: We are seeking an experienced Bobcat and Sit-Down Forklift Operator to join our recycling center team. This role requires strong equipment-handling skills, the ability to work safely in tight and narrow spaces, and previous outdoor/yard-work experience... 

Aya Healthcare, Inc.

Travel LVN/LPN: Top-Pay 26-Week Assignments Job at Aya Healthcare, Inc.

A healthcare staffing company has an immediate opening for a LTC LVN / LPN in Denton, TX. The role offers a competitive pay range of $1490/week - $1682/week, along with a 26-week assignment, comprehensive benefits starting from day one, and expert career guidance. Candidates... 

Labcorp

Phlebotomist Job at Labcorp

 ...include administrative duties and travel to additional sites. This position offers opportunities for professional growth and requires phlebotomy certification or training along with strong communication skills. At Labcorp we have a passion in helping people live happy... 

Atlassian

Senior Data Scientist Remote, Strategy & Insights (San Francisco) Job at Atlassian

 ...A global software company is seeking a Data Scientist to join their world-class Data Science team in San Francisco. In this role, you will collaborate cross-functionally to analyze data, influence product development, and drive strategic decisions. Candidates should have... 

ProKatchers LLC

Credentialing Specialist Job at ProKatchers LLC

 ...Job Description Job Title : Credentialing Specialist Location : New York, NY 10004 Duration : 3+ months contract Education : Bachelors degree- Required Shift Details : 9:00 AM-5:00 PM Job Description: Responsible for all aspects of provider credentialing...