Senior/Staff Infrastructure Security Engineer
AbridgeSFFull Time1mo ago
Job description
About the role
Abridge is building foundational security infrastructure for its AI-powered healthcare platform at enterprise scale. The Senior or Staff Infrastructure Security Engineer will own the design and operation of core security platforms and automation. This role focuses on establishing secure-by-default practices across cloud and infrastructure ecosystems. You will mentor engineers and influence security culture while working on high-impact greenfield initiatives. The position requires deep technical leadership and the ability to translate security needs into automated platform services. You will play a key role in enabling rapid, safe innovation across the organization.
Key facts
What you'll do
- Engineer Internal Security Platforms: Develop and maintain self-service platforms that allow security teams to manage secrets, identity perimeters, and security guardrails at scale.
- Automation and DevSecOps: Write production-grade services to automate complex security workflows, turning manual interventions into reliable, code-driven processes.
- Infrastructure-as-Code (IaC): Establish automated security guardrails and golden path modules that ensure our cloud resources are secure by default. Codify infrastructure including networking, IAM, Kubernetes, databases, streaming and pubsub platforms, storage, distribution, and more.
- Build the Security Data Backbone: Design, build, and operate high-scale data pipelines to ingest, normalize, and enrich security telemetry for our detection and response functions.
- Enable Cross-Functional Teams: Partner with platform and product engineering to integrate security requirements into the developer lifecycle without introducing friction.
- Greenfield Leadership: Influence the selection of our security stack, evaluating build vs. buy for core security tooling, and establishing the engineering standards for a growing team.
- Operate and Optimize Security Platforms: Monitor, troubleshoot, and iterate on existing security services to improve reliability, performance, and developer experience.
- Drive Zero Trust Initiatives: Implement and scale identity-aware controls, micro-segmentation, and least-privilege access patterns across critical systems.
- Support Incident Response: Collaborate with engineering and operations to build playbooks and tooling that accelerate detection, investigation, and remediation.
- Mentor and Enable Teams: Provide hands-on guidance and training to engineers, helping them adopt secure development practices and use security platforms effectively.
- Partner with Product Teams: Work closely with product and engineering to embed security into design reviews, sprint planning, and release processes.
- Maintain Compliance and Risk Posture: Contribute to audits, assessments, and policy documentation to ensure alignment with industry standards and best practices.
- Contribute to Open Source and Internal Tools: Build reusable components and libraries that abstract security complexity for internal consumers.
- Define and Track Security Metrics: Establish KPIs and dashboards that measure security posture, platform adoption, and operational health.
- Explore Emerging Technologies: Evaluate new security tools, techniques, and research relevant to AI-driven environments and cloud-native platforms.
Requirements
- 8+ years of software engineering experience, including 5+ years of infrastructure-as-code experience in a cloud-first organization.
- Extensive experience with Infrastructure-as-Code tools such as Terraform, CloudFormation, Pulumi, or similar.
- Deep understanding of cloud security principles, identity and access management, and network security on major cloud platforms.
- Strong proficiency in at least one modern general-purpose programming language such as Python, Go, or Java.
- Experience designing, building, and operating data pipelines for high-volume telemetry and log processing.
- Familiarity with container orchestration platforms such as Kubernetes and related security tools.
- Proven ability to work cross-functionally and influence engineering organizations without direct authority.
- Comfort with ambiguity and a track record of delivering security initiatives in fast-paced, evolving environments.
Nice to have
- Experience founding and growing a security organization in a startup or early-stage environment.
- Background in AI or data-intensive systems and related security challenges.
- Contributions to open source security tools or public-facing platforms.
- Hands-on experience with zero trust architectures, secrets management, and automated compliance.
Practical notes
- Office location in San Francisco.
- Full-time employment.
- No visa sponsorship or relocation details provided in SOURCE.
- No official apply page referenced in SOURCE.
- No compensation details provided in SOURCE.
- No travel requirements specified in SOURCE.
- No application deadlines mentioned in SOURCE.
- No remote or hybrid work options described in SOURCE.
- No mention of specific hours beyond full-time expectations in SOURCE.