Senior Manager, Security Engineering
Leads a distributed security engineering organization responsible for application/product security, cloud and infrastructure security, vulnerability operations, and AI security for a cloud-native SaaS platform. Requires 8+ years in information security and at least 3 years leading security engineering teams.
About the job
Responsibilities
- Lead, coach, and develop managers and security engineers across the United States and India.
- Build an integrated operating model spanning application/product security, infrastructure/cloud security, and vulnerability management.
- Own security strategy for AI-enabled product capabilities, including threat modeling, architecture reviews, secure development standards, testing, monitoring, and release readiness.
- Address AI security risks such as prompt injection, insecure agent or tool access, sensitive-data exposure, model and data-pipeline integrity, excessive agency, abuse, and third-party dependencies.
- Advance secure software development lifecycle practices, code and design reviews, application security testing, penetration testing, security champions, and vulnerability disclosure or bug bounty programs.
- Own vulnerability discovery, prioritization, remediation governance, exception management, and validation across applications, cloud infrastructure, containers, endpoints, operating systems, and third-party components.
- Manage software supply-chain risk across open-source dependencies, build systems, artifacts, secrets, and CI/CD pipelines.
- Own AWS security guardrails across infrastructure as code, containers, identity and access, networks, workloads, secrets, logging, and data services.
- Drive least privilege, secure administrative access, workload identity, segmentation, configuration assurance, and continuous cloud risk reduction.
- Translate business, product, AI, threat, customer, and audit priorities into a multi-quarter security engineering roadmap.
- Define objectives, key performance indicators, and key risk indicators; communicate risks and tradeoffs to technical leaders and executives.
- Maintain policies, standards, control evidence, inventories, and procedures supporting SOC 2, ISO 27001, privacy, and customer assurance obligations.
- Evaluate security tools and services based on risk reduction, coverage, integration, engineer experience, and total cost.
Requirements
- 8+ years of experience in information security, including significant experience in product or application security, cloud security, vulnerability management, or security engineering.
- 3+ years leading security engineering teams, including distributed or cross-region teams.
- Experience building and maturing security programs in a cloud-native SaaS environment, preferably on AWS.
- Practical experience securing modern software delivery, including secure development lifecycle practices, application security testing, cloud-native infrastructure, containers, and infrastructure as code.
- Strong technical judgment, program ownership, stakeholder influence, executive communication, and people leadership skills.
Nice-to-haves
- Experience leading managers.
- Experience securing AI/ML models, agents, retrieval-augmented generation, APIs, data access, and human approval controls.
- Experience with SOC 2, ISO 27001, privacy, customer assurance, or related compliance obligations.
- Experience with vulnerability management automation, threat intelligence, penetration testing, software supply-chain security, and coordinated vulnerability disclosure.
Skills
AWS, Application Security, Cloud Security, Vulnerability Management, Threat Modeling, Application Security Testing, Penetration Testing, Containers, Infrastructure As Code, CI/CD, Identity And Access Management, Software Supply Chain Security, Ai Security, Secure Sdlc, SOC 2
Similar jobs
Engineering Management jobsLeads a remote-first team of SDETs responsible for product quality, test strategy, automation, and release reliability across SaaS and customer-managed environments. Requires 10+ years of industry experience, technical leadership, and strong expertise in testing, CI/CD, observability, and quality metrics.
Leads multiple service-infrastructure engineering teams and managers, shaping architecture, developer platforms, reliability, and cross-functional delivery. Requires substantial management experience, including managing managers, critical distributed systems, incident response, and geographically distributed teams.
Leads and develops the App Traffic engineering team building reliable, scalable service-mesh and networking infrastructure across multiple clouds. Requires 9+ years of software engineering experience, including engineering leadership and distributed-systems or infrastructure expertise.
Leads the mortgage engineering organization, owning platform architecture, delivery, business-line outcomes, and team development. Requires senior engineering management experience, extensive software engineering experience, large-team leadership, business ownership, and expertise in scalable systems and AI.
Leads a hands-on Shared Services Engineering team building and operating reusable services, SDKs, APIs, and customer-facing systems. Requires 7+ years of software engineering experience, engineering management experience, and strong technical judgment across distributed and full-stack systems.