Senior Engineering Manager, Security
Leads a hands-on security engineering function spanning AI security, application and cloud security, detection and response, identity, and compliance controls. The role requires 8+ years of security engineering experience, deep AWS expertise, production code review ability, and experience operating in PCI DSS scope.
About the job
Responsibilities
- Own the security engineering foundation across AI security governance, application security, cloud infrastructure, detection and response, and identity management.
- Threat-model AI agent surfaces for prompt injection, tool misuse, and authorization boundaries.
- Build AI-native security capabilities, including detection triage, compliance evidence collection, and threat-modeling assistance.
- Lead application security through threat modeling, secure code review, SAST/SCA/DAST in CI, secure development lifecycle design, dependency management, and secrets management.
- Review production code in Go, TypeScript, Python, or similar languages.
- Secure AWS cloud infrastructure across IAM partitioning, least-privilege access, just-in-time elevation, cross-account trust, KMS boundaries, service control policies, Kubernetes pod security, egress filtering, and Terraform.
- Build SIEM/SOAR pipelines from log sources through triage, write correlation rules, enable AI-powered triage, establish on-call rotation, and create incident response runbooks.
- Drive SSO coverage, access reviews, and just-in-time elevation in partnership with IT.
- Design and implement controls supporting SOC 2, PCI DSS, and ISO evidence requirements.
- Lead technical responses to third-party questionnaires and partner security reviews.
- Set strategic direction while remaining hands-on with detection rules, pull-request reviews, hardening commits, and feature threat modeling.
Requirements
- 8+ years of experience in security engineering, including building a security function from an early stage.
- Experience building and shipping security controls rather than only identifying issues.
- Production code review experience in Go, TypeScript, Python, or similar languages.
- Detection engineering experience, including building a SIEM or SOAR pipeline from log sources through triage.
- Deep AWS security knowledge, including IAM policy design, multi-account strategies, and cloud privilege escalation.
- Experience operating within PCI DSS scope and shipping controls that withstand a real audit.
- Strong judgment about when to fix issues directly versus assigning them to responsible teams with SLAs.
- Comfort using AI tools to scale a small security team within established architecture and review processes.
Nice-to-Haves
- Experience as the first or an early security hire at a high-growth fintech or marketplace.
- Experience at a fast-scaling company such as Ramp, Mercury, Stripe, or Whatnot.
- Experience securing AI and ML systems, model pipelines, or AI-assisted development workflows.
- Familiarity with card issuing, payment processing, or financial services infrastructure.
- Terraform and Helm fluency, including hands-on CI/CD security integration.
- Open-source contributions, security research, or conference speaking.
Compensation and Benefits
- Competitive compensation and equity packages.
- Flexible paid time off.
- Fully covered healthcare, including dependent coverage.
- Access to One Medical and an optional FSA.
- 20 weeks of paid parental leave for primary caregivers and 8 weeks for all new parents.
- Choice of leading work computers.
- Access to industry-leading technology across business units.
Skills
AWS, IAM, Kubernetes, Terraform, Helm, Go, TypeScript, Python, SIEM, Soar, SAST, Sca, DAST, Pci Dss, SOC 2
Similar jobs
Security Engineering jobsOwns production-edge security for enterprise financial-institution connectivity, including PKI, mTLS, AWS networking, webhook security, and vulnerability remediation. Requires 6+ years of hands-on platform, infrastructure, or network security engineering experience.
Leads interpretation and productization of federal compliance controls for Vanta’s public-sector platform, translating FedRAMP and related frameworks into technically testable guidance, automated detectors, mappings, and machine-readable authorization workflows. Requires 8–10+ years of hands-on federal compliance experience, especially FedRAMP program and SSP work.
Build secure, large-scale platforms, controls, monitoring, and AI-augmented pipelines that improve Snowflake’s cloud security posture across hundreds of millions of assets and multiple cloud providers. Requires 5+ years of software engineering experience and expertise in secure distributed systems.
Leads enterprise network architecture, cloud connectivity, security, operations, and incident response across corporate and manufacturing environments. Requires 10+ years of network engineering experience, people leadership, AWS networking expertise, and strong network security knowledge.
Own detection engineering and lead incident response across corporate and production environments, building cloud, endpoint, runtime, and Kubernetes coverage. The role requires 6+ years in security, hands-on detection development, and end-to-end incident leadership.