Senior/Enterprise Security Engineer
Listed on 2026-01-12
-
IT/Tech
Cybersecurity, Systems Engineer
Location: New York
Senior/Staff Enterprise Security Engineer
Base pay range: $/yr - $/yr
About AbridgeAbridge was founded in 2018 with the mission of powering deeper understanding in healthcare. Our AI‑powered platform was purpose‑built for medical conversations, improving clinical documentation efficiencies while enabling clinicians to focus on what matters most—their patients.
Our enterprise‑grade technology transforms patient‑clinician conversations into structured clinical notes in real‑time, with deep EMR integrations. Powered by Linked Evidence and our purpose‑built, auditable AI, we are the only company that maps AI‑generated summaries to ground truth, helping providers quickly trust and verify the output. As pioneers in generative AI for healthcare, we are setting the industry standards for the responsible deployment of AI across health systems.
We are a growing team of practicing MDs, AI scientists, PhDs, creatives, technologists, and engineers working together to empower people and make care more sense. We have offices located in the Mission District in San Francisco, the SoHo neighborhood of New York, and East Liberty in Pittsburgh.
The RoleWant to work on building out security from the ground up at the leading edge of AI in healthcare globally? We’re looking for an experienced and highly motivated Senior or Staff Enterprise Security Engineer to join our team as one of the first engineers on the Abridge Security team. In this role, you’ll be a key technical leader, driving large initiatives that shape our company, infrastructure, SaaS ecosystem, and business practices.
You’ll impact both the vision and hands‑on execution of securing our enterprise infrastructure and systems across the entire company. You’ll work cross‑functionally with both technical and business teams to integrate security seamlessly, automate security capabilities and controls, and mentor others to build secure‑by‑default solutions across the business. This position requires deep technical expertise, a builder’s mindset, and excellent communication skills to influence security culture across the organization.
You’ll Do
- Identity & Access Management (IAM) and SaaS Security
- IAM Architecture:
Architect and implement enterprise‑wide Identity and Access Management (IAM) and Privileged Access Management (PAM) solutions. - Federation & SSO:
Own the implementation and maintenance of authentication standards, including Single Sign‑On (SSO), phishing‑resistant Multi‑Factor Authentication (MFA), and identity federation protocols (SAML, OIDC, OAuth2). - SaaS Security Posture:
Design and enforce security policies for critical SaaS applications using tools like SSPM (SaaS Security Posture Management) to ensure secure configurations and access controls. - Lifecycle Management:
Develop and automate the full identity lifecycle (joiner, mover, leaver) process, leveraging SCIM and other APIs for streamlined user provisioning and de‑provisioning.
- IAM Architecture:
- Security Automation and Tooling
- Automation Strategy:
Lead the development of the security automation roadmap for Enterprise Security, identifying key areas for efficiency gains. - Build & Integrate:
Design and build custom automation scripts and integrations using languages like Python to connect security tools (SIEM, EDR, IAM, Ticketing). - Policy Enforcement:
Utilize Infrastructure as Code (IaC) tools (e.g., Terraform) to manage the secure configuration of enterprise tools and enforce security policies at scale across code repos, MDM, and cloud environments.
- Automation Strategy:
- Endpoint, Network, and Email Security
- Endpoint Protection:
Engineer, deploy, and manage our Endpoint Detection and Response (EDR) and Mobile Device Management (MDM) platforms to ensure full coverage, policy compliance, and timely incident response across a fleet of various operating systems (primarily MacOS). - Network Security Controls:
Design, configure, and maintain enterprise network security controls, including next‑generation firewalls, secure web gateways, VPNs, and micro‑segmentation strategies. - Email Security:
Own and optimize the email security stack, DMARC/DKIM/SPF enforcement, and anti‑phishing controls to mitigate social engineering attacks. - Zero Trust…
- Endpoint Protection:
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).