Senior Enterprise Security Engineer
Job description
About the role
Abridge is building the foundational security architecture for a rapidly scaling AI healthcare platform, and this role is central to that effort. The Senior Enterprise Security Engineer will own the design and execution of enterprise security programs from the ground up, focusing on identity, endpoints, and SaaS ecosystems. You will be responsible for implementing controls that protect sensitive healthcare data and clinical workflows while enabling clinician productivity. This position requires a builder who can translate complex security requirements into reliable, automated systems that scale with the business. You will partner closely with cross-functional teams to embed security into every layer of the technology stack. Success in this role will be measured by reduced risk, strengthened compliance, and an empowered workforce that can move quickly without compromising security.
Key facts
What you'll do
Implement and Operate Identity and Access Management: Design, deploy, and manage IAM and Zero Trust access controls - including SSO, MFA, authentication protocols, access lifecycle management, and identity governance - across cloud and SaaS environments. Ensure every identity is accounted for and every access decision is defensible.
Secure the Endpoint Fleet: Engineer and operate endpoint detection and response (EDR), device management (MDM), and endpoint compliance tooling, ensuring every device connecting to Abridge systems meets security standards across macOS, Windows, and Linux.
Drive SaaS and Third-Party Security: Build and operate programs for SaaS security posture management, shadow IT discovery, and third-party risk assessment to maintain control as the SaaS footprint grows.
Automate and Scale: Build production-grade automation for access reviews, onboarding/offboarding workflows, policy enforcement, and security operations - turning manual processes into reliable, code-driven systems.
Engineer Corporate Network Security: Design and maintain secure corporate network architectures, including VPN, ZTNA, network segmentation, and Wi-Fi security, ensuring robust protection for both on-premises and remote work environments.
Support Enterprise AI Security: Help implement Abridge's strategy for securing corporate AI adoption - from enforcing governance frameworks and sanctioned tool inventories to deploying technical controls around data loss prevention and third-party AI vendor risk.
Partner Cross-Functionally: Collaborate with IT, People, Legal, and Compliance teams to translate regulatory and business requirements into durable, automated technical controls that don't slow down the organization.
Champion Security Culture: Influence security behaviors and practices across the organization by partnering with engineers, product teams, and leadership to embed security into day-to-day workflows.
Operate in a Fast-Paced Environment: Prioritize and execute on security initiatives in a growing startup, balancing urgent requests with long-term architectural improvements.
Own Tooling and Processes: Evaluate, deploy, and optimize security tooling for cloud, identity, endpoint, and network environments while maintaining a focus on usability and scalability.
Requirements
7+ years in enterprise security, identity security, corporate security, or adjacent security engineering domains, with a demonstrated track record of hands-on implementation and operational ownership.
Strong hands-on depth in identity and access management, including SSO, OAuth/OIDC, SCIM, authentication protocols, access lifecycle management, and identity governance. You understand how to design and operate Zero Trust architectures in modern enterprise environments.
Experience designing and operating endpoint security programs at scale, including EDR, MDM, device compliance, and fleet management across macOS, Windows, and Linux.
Deep familiarity with securing cloud-native environments (GCP or AWS) and managing the security posture of a large, evolving SaaS estate. You understand the identity and access challenges unique to cloud platforms and how to address them securely.
Proven ability to work with stakeholders at all levels, including legal, compliance, IT, and executive leadership, to align security controls with business objectives.
Strong understanding of regulatory and compliance frameworks relevant to healthcare data, including HIPAA and other applicable standards.
Experience with security automation and infrastructure as code, using tools and practices that enable repeatable, auditable, and scalable security operations.
Commitment to building and maintaining auditable, defensible security programs that enable business growth without compromising risk management.
Practical notes
Hours: Full-time
Travel: None stated
Visa: Not stated
Deadlines: Not stated
LENGTH: 700-900 words. No HTML, no markdown, no em dashes.
Output the page only.