Senior/staff Threat Detection Engineer

Abridge · Vertical AI · San Francisco, CA · Builder

Abridge is seeking a Senior/Staff Threat Detection and Response Engineer to build security from the ground up for their AI in healthcare platform. This role involves leading investigations, designing threat detection roadmaps, architecting incident response processes, driving automation, and conducting security research. The ideal candidate has extensive experience in detection engineering and incident response, a builder's mindset, and strong technical and communication skills.

What you'd actually do

  1. Leading investigations of complex, organization-wide security events and establishing best practices across multiple security domains (log analysis, digital forensics, malware analysis)
  2. Designing and implementing the strategic roadmap for threat detection capabilities, creating high-fidelity detection systems based on deep understanding of advanced threat actor TTPs
  3. Architecting scalable incident response processes and driving automation across the entire IR lifecycle, establishing patterns for the organization
  4. Serving as incident commander for critical, cross-organizational security incidents and mentoring others in effective incident management practices
  5. Driving security research initiatives, discovering novel detection mechanisms and presenting findings to internal teams, executive leadership, and external audiences

Skills

Required

  • 9+ years in Detection Engineering, Incident Response, Advisory Emulation, Offensive Security and/or Threat Intelligence
  • Experience in high-growth environments where you've scaled security capabilities alongside rapid organizational expansion, managing evolving threat landscapes and increasing complexity
  • Exceptional communicator who can influence technical strategy across all organizational levels, from engineers to executive leadership
  • Proven track record leading critical, multi-week incident response efforts and driving post-incident strategic improvements
  • Deep technical expertise with demonstrated ability to architect scalable security systems and drive innovation in detection capabilities
  • History of moving forward ambiguous, organization-wide initiatives through influence, technical vision, and cross-functional collaboration
  • Expert-level knowledge of attacker tactics, techniques, and procedures across multiple threat actor groups
  • Systems thinker who navigates complexity pragmatically while building toward elegant, maintainable solutions
  • Strong experience with cloud security architecture and building production-grade automation and tooling
  • Strong scripting skills in multiple scripting/programming languages (Python, Go, etc.)

Nice to have

  • Experience applying Generative AI to operational security problems.
  • Participation in the Security community via talks, papers, or blogs
  • Experience leading or managing Technical Security functions or building technical security functions from 0 1
  • Experience on a code first/automation first security team

What the JD emphasized

  • greenfield opportunity
  • building 0 1
  • large-scale data and automation challenge
  • architect the way forward
  • deep technical expertise
  • building production-grade automation and tooling
  • building technical security functions from 0 1