Senior Manager, Enterprise Security
Job description
About the role
Abridge is building the foundational infrastructure for healthcare conversations, and this role is central to securing that mission from the ground up. You will own the end-to-end strategy and execution of enterprise security for a rapidly scaling AI healthcare company. This position requires you to operate at the intersection of technical depth and cross-functional leadership. You will establish the security posture for identities, endpoints, and SaaS platforms that underpin our global operations. The role demands a builder who can translate abstract risk into concrete, scalable controls. You will be one of the first security leaders shaping the culture and architecture of our security program. Success in this role means enabling the business to move fast while maintaining rigorous security standards.
Key facts
What you'll do
- Own Enterprise Security Strategy: Define and drive the vision, roadmap, and execution of Abridge's enterprise security program - spanning identity, endpoint, SaaS, email, and corporate network security - ensuring capabilities scale with the organization.
- Build and Lead the
Team: Recruit, mentor, and develop a team of enterprise security engineers, setting the technical bar from day one and establishing engineering best practices that attract top talent.
- Architect Identity and Access Management: Design, implement, and operate IAM and Zero Trust access controls, including SSO, MFA, authentication protocols, access lifecycle management, and identity governance across cloud and SaaS environments.
- Secure the Endpoint Fleet: Own the strategy and tooling for endpoint detection and response (EDR), device management (MDM), and endpoint compliance, ensuring every device connecting to Abridge systems meets security standards.
- Drive SaaS and Third-Party Security: Establish and operate programs for SaaS security posture management, shadow IT discovery, vendor security assessments, and third-party risk management to maintain control as the SaaS footprint grows.
- Automate and Scale: Build production-grade automation for access reviews, onboarding/offboarding workflows, policy enforcement, and security operations - turning manual processes into reliable, code-driven systems.
- Partner Cross-Functionally: Collaborate with IT, People, Legal, and Compliance teams to translate regulatory and business requirements into durable, automated technical controls that don't slow down the organization.
- Lead Enterprise AI Security: Define and execute Abridge's strategy for securing corporate AI adoption end-to-end - from establishing governance frameworks and sanctioned tool inventories, to implementing technical controls around data loss prevention, prompt injection risks, and third-party AI vendor assessments - ensuring employees can leverage AI safely and at speed.
- Define Build vs. Buy: Evaluate and select enterprise security tooling, making pragmatic build-vs-buy decisions that maximize coverage while minimizing complexity.
Requirements
- Depth of Experience: 8+ years in enterprise security, identity security, corporate security, or adjacent security engineering domains, with at least 5+ years in a management capacity.
- Identity and Access Expertise: Strong hands-on depth in identity and access management, including SSO, OAuth/OIDC, SCIM, authentication protocols, and provisioning/deprovisioning workflows.
- Enterprise Endpoint and OS Security: Significant background in endpoint security, including EDR and MDM, across diverse operating systems and environments.
- SaaS and Cloud Security Acumen: Demonstrated experience securing SaaS environments, including CSPM, third-party risk, and security posture management.
- Practical Automation Skills: Ability to operationalize security controls using infrastructure as code, scripting, and integration with IT service management platforms.
- Cross-Functional Leadership: Track record of influencing and managing stakeholders without direct authority, aligning security with business priorities.
- Regulatory Awareness: Understanding of compliance frameworks relevant to healthcare and sensitive data, including HIPAA and related standards.
- Communication and Mentorship: Clear communication skills to articulate risk and strategy to both technical and executive audiences, with a commitment to mentoring junior team members.
Nice to have
- Experience in the healthcare or life sciences sector, particularly in roles requiring strict compliance and data sensitivity.
- Background building security programs in high-growth startups or scale-ups.
- Familiarity with AI/ML model security risks and emerging AI governance frameworks.
Practical notes
This is a hybrid role with a minimum of 3 days / week (MWF) in our San Francisco office. Please only apply if you are able to commit to this model and/or willing to relocate to San Francisco.