Manager, Enterprise Security
Job description
About the role
Abridge was founded in 2018 with the mission of powering deeper understanding in healthcare. Our AI-powered platform was purpose-built for medical conversations, improving clinical documentation efficiencies while enabling clinicians to focus on what matters most - their patients. Our enterprise-grade technology transforms patient-clinician conversations into structured clinical notes in real-time, with deep EMR integrations. Powered by Linked Evidence and our purpose-built, auditable AI, we are the only company that maps AI-generated summaries to ground truth, helping providers quickly trust and verify the output. As pioneers in generative AI for healthcare, we are setting the industry standards for the responsible deployment of AI across health systems. We are a growing team of practicing MDs, AI scientists, PhDs, creatives, technologists, and engineers working together to empower people and make care make more sense. We have offices located in the Mission District in San Francisco, the SoHo neighborhood of New York, and East Liberty in Pittsburgh.
You will own the end-to-end strategy and execution of enterprise security programs, defining how the organization identifies, assesses, and mitigates risks to people, data, and systems. You will establish the foundational security controls that protect our critical assets while enabling the company to move at the speed of innovation. This role requires you to design and implement robust security architectures that scale reliably as we grow. You will act as the primary technical authority for enterprise security decisions and ensure alignment with industry best practices. You will foster a culture where security is viewed as an enabler of trust and business growth rather than a barrier. This is your opportunity to build security from the ground up and leave a lasting impact on the organization.
Key facts
What you'll do
Own Enterprise Security Strategy: Define and drive the vision, roadmap, and execution of Abridge's enterprise security program - spanning identity, endpoint, SaaS, email, and corporate network security - ensuring capabilities scale with the organization.
Build and Lead the
Team: Recruit, mentor, and develop a team of enterprise security engineers, setting the technical bar from day one and establishing engineering best practices that attract top talent.
Architect Identity and Access Management: Design, implement, and operate IAM and Zero Trust access controls, including SSO, MFA, authentication protocols, access lifecycle management, and identity governance across cloud and SaaS environments.
Secure the Endpoint Fleet: Own the strategy and tooling for endpoint detection and response (EDR), device management (MDM), and endpoint compliance, ensuring every device connecting to Abridge systems meets security standards.
Drive SaaS and Third-Party Security: Establish and operate programs for SaaS security posture management, shadow IT discovery, vendor security assessments, and third-party risk management to maintain control as the SaaS footprint grows.
Automate and Scale: Build production-grade automation for access reviews, onboarding/offboarding workflows, policy enforcement, and security operations - turning manual processes into reliable, code-driven systems.
Partner Cross-Functionally: Collaborate with IT, People, Legal, and Compliance teams to translate regulatory and business requirements into durable, automated technical controls that don't slow down the organization.
Lead Enterprise AI Security: Define and execute Abridge's strategy for securing corporate AI adoption end-to-end - from establishing governance frameworks and sanctioned tool inventories, to implementing technical controls around data loss prevention, prompt injection risks, and third-party AI vendor assessments - ensuring employees can leverage AI safely and at speed.
Define Build vs. Buy: Evaluate and select enterprise security tooling, making pragmatic build-vs-buy decisions that maximize coverage while minimizing complexity.
Requirements
Bring 8+ years of hands-on experience in enterprise security, identity security, corporate security, or adjacent security engineering domains, demonstrating a consistent track record of delivering secure and scalable solutions.
Demonstrate at least 2+ years of experience in a management or team-lead capacity, guiding engineers through complex technical decisions and cross-functional initiatives.
Show deep expertise in identity and access management, including SSO, OAuth/OIDC, SCIM, authentication protocols, and identity governance across hybrid cloud and SaaS environments.
Possess strong knowledge of endpoint security architectures, including EDR, MDM, and the principles of device compliance and hardening for modern distributed workforces.
Have proven experience with SaaS security and third-party risk management, including SSPM tools, vendor risk assessments, and strategies for discovering and governing shadow IT.
Exhibit fluency in security automation and infrastructure as code, with the ability to translate manual processes into scalable, repeatable workflows using scripts and configuration management.
Demonstrate a strong understanding of regulatory and compliance frameworks relevant to healthcare, including HIPAA and other applicable standards, ensuring security programs support auditability and governance.
Commit to building security practices grounded in Zero Trust principles, least privilege access, and continuous verification to protect sensitive data and clinical workflows.
Nice to have
Experience in AI and machine learning environments, including familiarity with model security, prompt injection mitigation, and data privacy considerations specific to generative AI systems.
Background working with clinical or healthcare technology products, where security and patient privacy intersect with rapid product development.
Practical notes
This is a hybrid role with a minimum of 3 days / week (MWF) in our San Francisco office. Please only apply if you are able to commit to this model and/or willing to relocate to San Francisco.