Director of Product Security at Abridge, defining and driving product security strategy. Leading security assurance, proactive risk reduction, and maintaining world-class security posture in hybrid environment.
Responsibilities
Product Security Strategy: Define and continuously evolve the long-term Product Security strategy, ensuring alignment with Abridge.ai's business goals and technological advancements.
Security Roadmap Ownership: Own the creation and execution of the Product Security roadmap, including security features, SDLC enhancements, threat modeling initiatives, and overall risk reduction milestones.
Financial Oversight: Manage the Product Security budget, including forecasting security tool expenditures, vendor contracts, and personnel resource allocation.
Metric-Driven Management: Define, track, and report on key performance indicators (KPIs) and security metrics to measure the effectiveness of all security programs and provide data-driven insights to leadership.
Impact Analysis: Conduct regular impact analysis (ROI) of security investments and lead time/cost-reduction efforts. Translate complex security risks into clear business risk terms to justify strategic initiatives.
Lead and Mentor: Serve as a motivating people leader for a growing team of Security Engineers and Analysts, providing career development, mentorship, and regular performance feedback.
Strategy and Scaling: Define and execute on goals in a hypergrowth AI company, focusing on enabling secure AI development and deployment globally.
Security Industry Engagement: Actively participate in and be a thought leader for the security industry by giving talks at conferences, publishing papers, hosting forums, etc.
Multi-Cloud Strategy: Define the security architecture and strategy for our cloud environments (GCP, AWS, Azure, etc.).
Containerization Security: Lead the implementation of security controls for containerized applications, with a deep focus on securing Kubernetes clusters, including network policies and secrets management.
IaC Security: Implement security guardrails within Infrastructure as Code (e.g., Terraform) to ensure all cloud resources are provisioned securely.
Integrate Security: Partner with Engineering and Product leadership to embed security processes into the Software Development Lifecycle (SDLC).
Security Practices: Develop and oversee secure coding practices, security architecture reviews, and static/dynamic code analysis practices across all applications.
Vulnerability Management: Direct the vulnerability management and penetration testing programs, ensuring comprehensive coverage and rapid, prioritized remediation of findings.
Data Protection: Lead the data security program, focusing on the protection, encryption, and access controls for highly sensitive patient data (PII, PHI, AI models, etc.).
AI/ML Security: Establish security engineering practices for our AI/ML models and pipeline, including model integrity, adversarial attack prevention, model red-teaming, securing agentic AI, etc.
Requirements
Experience: 10+ years of progressive experience in security, with a minimum of 10 years leading security teams, programs, or large-scale initiatives in a senior leadership capacity.
Business Acumen: Demonstrated experience running security as a business unit, including budget management, strategic forecasting, and translating technical risk into business impact (ROI).
Engineering Proficiency: Must be proficient, at an engineering level, in at least one or more general-purpose programming languages. Experience with Python and/or NextJS is a significant plus.
Cloud Expertise: Deep technical expertise in securing at least one major cloud platform (GCP, AWS, or Azure) and demonstrable experience with modern cloud security principles and tools.
Containerization: Mandatory expertise in securing container orchestration technologies, specifically Kubernetes.
Industry Knowledge: Proven experience securing products (enterprise SaaS, cloud environments) handling highly sensitive data, such as Protected Health Information (PHI), with specific knowledge of NIST 800-53 / 800-171, FedRAMP, HIPAA, NIS2 and other relevant security and privacy regulations and frameworks.
Communication: Exceptional communication and presentation skills, with the ability to convey complex security issues and technical risks to both technical and non-technical audiences, including executives, customers, government agencies, and board members.
Benefits
Generous Time Off: 14 paid holidays, flexible PTO for salaried employees, and accrued time off for hourly employees
Comprehensive Health Plans: Medical, Dental, and Vision coverage for all full-time employees and their families.
Generous HSA Contribution: If you choose a High Deductible Health Plan, Abridge makes monthly contributions to your HSA.
Paid Parental Leave: Generous paid parental leave for all full-time employees.
Family Forming Benefits: Resources and financial support to help you build your family.
401(k) Matching: Contribution matching to help invest in your future.
Personal Device Allowance: Tax free funds for personal device usage.
Pre-tax Benefits: Access to Flexible Spending Accounts (FSA) and Commuter Benefits.
Lifestyle Wallet: Monthly contributions for fitness, professional development, coworking, and more.
Mental Health Support: Dedicated access to therapy and coaching to help you reach your goals.
Sabbatical Leave: Paid Sabbatical Leave after 5 years of employment.
Compensation and Equity: Competitive compensation and equity grants for full time employees.
Administrative Business Partner supporting leaders within Security function at Palantir Technologies. Managing diverse responsibilities to enhance productivity and support leadership teams.
Administrative Business Partner supporting leadership within Palantir’s Security function. Providing comprehensive administrative support while handling confidential matters in a fast - paced environment.
Providing security consultancy to technical and business stakeholders at Trendyol Tech. Driving improvements in security practices while assessing new projects and establishing security standards.
Entra ID Security Specialist developing identity and access management solutions focused on Microsoft Entra ID at cyberunity AG. Responsible for strategic development and compliance in security architecture.
Red Team Security Engineer at Xcel Energy performing authorized testing to expose security weaknesses. Collaborating with internal teams and external vendors for effective security technology implementation.
Manager I overseeing Cyber Security engineering functions at NFCU. Leading and supporting the Cybersecurity Technology Engineering team in implementing security protocols.
Security Officer responsible for maintaining safety and security at Hilton in Harrisburg, PA. Conducting patrols, responding to emergencies, and supervising housekeeping staff.
Information Security Engineer managing incident detection and response for Safe - Guard Products. Involves vulnerability management, data protection, and security engineering activities.
Work Student, Product Security at TeamViewer supporting security initiatives for product safety. Opportunity to gain hands - on experience in an international environment with a focus on cybersecurity.
Cyber Security Detection Engineer focusing on threat detection capabilities and security telemetry within complex environments. Collaborating across Security Operations, Cloud Engineering, and Compliance disciplines.