Skip to content
CohereCohere

Manager, Security Engineering

Lead and grow a Security Engineering team responsible for vulnerability management, SAST/DAST, penetration testing, bug bounty, and secure SDLC integration across cloud platforms.

About the job

Key Responsibilities

  • Serve as trusted advisor to team's leadership and partner teams by clearly articulating business risks associated with security issues
  • Execute the long-term vision for the Security team in alignment with Cohere's product and business goals
  • Collaborate closely with leadership to prioritize high-impact initiatives and strategic customer engagements
  • Vulnerability Management: Develop and implement enterprise-wide vulnerability management processes and tooling, including identification, prioritization, remediation tracking, and reporting
  • Static Application Security Testing (SAST): Establish SAST programs, integrate tools into CI/CD pipelines, and analyze results to identify and remediate security flaws in source code
  • Dynamic Application Security Testing (DAST): Implement DAST methodologies, configure scanning tools, and conduct regular assessments of running applications
  • Penetration Testing: Lead and oversee internal and external penetration testing engagements, including web application, API, network and agentic AI platform; manage bug bounty program
  • Security Architecture Review: Collaborate with development teams to review and validate security architecture and design patterns
  • Secure SDLC Integration: Embed security practices throughout the software development lifecycle, working closely with engineering and product teams
  • Team Leadership: Lead and grow a high-performing team of Security engineers through hiring, coaching, and mentorship
  • Metrics and Reporting: Establish key security metrics, generate regular reports for leadership, and communicate security posture to stakeholders
  • Compliance and Standards: Ensure application security practices align with industry standards (OWASP Top10 for LLMs, ISO 27001) and regulatory requirements

Requirements

  • 8+ years of previous experience in Application Security / Security Engineering with a strong focus on vulnerability management, SDLC and bug bounty programs
  • Proven experience with SAST, DAST, and penetration testing methodologies and tools
  • Proficiency with programming languages (Python, GoLang) and web technologies
  • Experience with cloud platforms (AWS, GCP, Azure) and container security
  • Excellent communication and interpersonal skills with ability to influence technical and non-technical stakeholders
  • Experience building and managing high-performing security teams
  • Comfortable with ambiguity and able to make informed decisions with little data
  • Flexible and constructive approach when solving problems
  • Able to make trade-offs between build vs. buy decisions
  • Deep technical understanding of common security vulnerabilities and risks, as well as countermeasures and compensating controls

Nice-to-Haves

  • Understanding of secure engineering best practices and ability to articulate problem statements and propose solutions to both technical and non-technical audiences

Skills

Python, Go, SAST, DAST, Penetration Testing, Vulnerability Management, AWS, GCP, Azure, Container Security, CI/CD, ISO 27001, Owasp

Idme

Idme

McLean, VA

SOC Lead
$96k+/yrOn-site8+ YOESecurity Engineering

Leads cloud-native security operations, incident response, threat hunting, and forensic investigations while mentoring SOC analysts and improving detection processes. Requires 8+ years in information security, including hands-on cloud incident response and experience with Kubernetes, CI/CD, and advanced security tools.

ConductorOne

ConductorOne

San Francisco, CA
Senior Security Engineer
$100k+/yrRemote5+ YOESecurity Engineering

Senior Security Engineer responsible for application, cloud, and platform security, with a focus on automating security workflows, threat modeling, secure development, and remediation. Requires hands-on SaaS security, cloud infrastructure, code review, and agent or automation experience.

Mercor

Mercor

San Francisco, CA

Security GRC Lead
$350k+/yrOn-site7+ YOESecurity Engineering

Leads the company’s security GRC function, owning SOC 2, ISO 27001, enterprise audits, third-party risk, policy governance, and automated evidence workflows. Requires 7+ years of GRC or audit experience, end-to-end SOC 2 and ISO 27001 ownership, and strong security tooling expertise.

Anthropic

Anthropic

San Francisco, CA
Lead, Security Controls Assurance - SOX
$410k+/yrHybridSecurity Engineering

Leads technical SOX controls assurance for financially significant systems, translating audit requirements into engineering acceptance criteria and continuous monitoring. Requires ITGC and SOX 404 expertise, strong engineering fluency, programming ability, and cross-functional collaboration with Finance, Engineering, and auditors.

Discord

Discord

United States

Senior Platform Security Engineer
$196k+/yrOn-site5+ YOESecurity Engineering

Senior platform security engineer responsible for building identity and access management systems, Zero Trust architecture, cloud security baselines, and secure developer platforms. Requires 5+ years operating production systems and strong software development and security experience.