Senior Manager, Enterprise Security

Abridge · Vertical AI · San Francisco, CA · Builder

This role is for a Senior Manager of Enterprise Security at Abridge, a healthcare AI company. The primary focus is on building and leading the enterprise security program from the ground up, covering identity, endpoint, SaaS, and corporate infrastructure. A key responsibility includes leading the strategy for securing corporate AI adoption, including governance, data loss prevention, and prompt injection risks. The role requires significant experience in enterprise security, IAM, endpoint security, and cloud/SaaS environments, with a strong engineering and automation mindset. While the company is AI-focused, this role is about securing the enterprise and corporate AI usage, not directly building AI models or products.

What you'd actually do

  1. Own Enterprise Security Strategy: Define and drive the vision, roadmap, and execution of Abridge's enterprise security program—spanning identity, endpoint, SaaS, email, and corporate network security—ensuring capabilities scale with the organization
  2. Build and Lead the Team: Recruit, mentor, and develop a team of enterprise security engineers, setting the technical bar from day one and establishing engineering best practices that attract top talent
  3. Architect Identity and Access Management: Design, implement, and operate IAM and Zero Trust access controls, including SSO, MFA, authentication protocols, access lifecycle management, and identity governance across cloud and SaaS environments
  4. Secure the Endpoint Fleet: Own the strategy and tooling for endpoint detection and response (EDR), device management (MDM), and endpoint compliance, ensuring every device connecting to Abridge systems meets security standards
  5. Lead Enterprise AI Security: Define and execute Abridge's strategy for securing corporate AI adoption end-to-end—from establishing governance frameworks and sanctioned tool inventories, to implementing technical controls around data loss prevention, prompt injection risks, and third-party AI vendor assessments—ensuring employees can leverage AI safely and at speed

Skills

Required

  • 8+ years in enterprise security, identity security, corporate security, or adjacent security engineering domains
  • 5+ years in a management capacity
  • Strong hands-on depth in identity and access management, including SSO, OAuth/OIDC, SCIM, authentication protocols, access lifecycle management, and identity governance
  • Experience designing and operating endpoint security programs at scale, including EDR, MDM, device compliance, and fleet management across macOS, Windows, and Linux
  • Deep familiarity with securing cloud-native environments (GCP or AWS) and managing the security posture of a large, evolving SaaS estate
  • Strong scripting and automation skills (Python, Go, or similar)
  • Experience with infrastructure-as-code
  • Demonstrated ability to partner with IT, HR, Legal, and Compliance
  • Exceptional communicator

Nice to have

  • AI security governance
  • Zero Trust security architectures
  • Prompt injection risks
  • Third-party AI vendor assessments

What the JD emphasized

  • greenfield opportunity
  • building 0 → 1
  • enterprise security should reduce risk while empowering employees
  • Own Enterprise Security Strategy
  • Build and Lead the Team
  • Architect Identity and Access Management
  • Secure the Endpoint Fleet
  • Drive SaaS and Third-Party Security
  • Automate and Scale
  • Partner Cross-Functionally
  • Lead Enterprise AI Security
  • Define Build vs. Buy
  • Depth of Experience
  • Identity and Access Expertise
  • Endpoint Security Proficiency
  • Cloud and SaaS Fluency
  • Engineering Mindset
  • Cross-Functional Leadership
  • Communication and Executive Presence