# Senior Engineering Manager, Security & IT

**Company:** [Fingerprint](https://hotfix.jobs/companies/fingerprint)
**Location:** Remote
**Role:** Security Engineering
**Experience:** 7+ years
**Skills:** Application Security, owasp, Vulnerability Management, snyk, SOC 2, GRC, ISO 27001, GDPR, HIPAA, Okta, SCIM, SAML, endpoint management, identity and access management, Cloudflare
**Posted:** 2026-08-05

> Leads Fingerprint’s security, IT operations, and compliance function, managing a team and owning application security, SOC 2, identity governance, and enterprise security communications. Requires 7+ years across security, IT, or GRC, team management experience, and demonstrated SOC 2 and application security ownership.

## Job Description

## Mission

- Unify security, IT operations, and compliance under a coherent strategy with shared standards, risk language, and a scalable roadmap.
- Own Fingerprint's security posture, including application security, zero-trust principles, vulnerability management, and security-by-default practices.
- Scale the compliance program, mature evidence collection, and prepare for expanding enterprise requirements.
- Run reliable IT operations for a globally distributed, fully remote organization.
- Represent security and compliance posture to enterprise customers, prospects, partners, auditors, and leadership.

## Responsibilities

### Security Strategy & Application Security

- Define and own the application security roadmap, including vulnerability management, penetration testing, and security reviews for new features and architectural changes.
- Build security-by-default practices into engineering workflows.
- Own vendor security assessments and ensure third parties meet security standards.
- Define zero-trust security principles and embed them across the Cloud Platform and engineering organization.

### Compliance & GRC

- Own the SOC 2 Type 2 annual audit cycle, including evidence collection, auditor management, and control maturation.
- Drive compliance expansion, evaluating frameworks such as ISO 27001, GDPR, and customer-specific enterprise requirements.
- Manage and develop the Compliance Lead.
- Support enterprise sales cycles through security questionnaires, customer due diligence calls, and contractual security requirements.
- Maintain and embed the company's policy framework.

### IT Operations

- Manage the Lead IT Engineer and provide strategic direction for day-to-day IT operations.
- Own IT strategy, including tooling, access management, Okta, SCIM/SAML provisioning, endpoint management, and identity governance.
- Scale IT operations with engineering headcount growth through proactive capacity planning.
- Define and enforce IT security policies covering device management, access reviews, and offboarding.

### Cross-functional Leadership & Communication

- Communicate security posture, compliance status, and IT health to the VP of Engineering with actionable recommendations.
- Partner with Cloud Platform leadership on infrastructure security, network security, IAM standards, security logging, and alerting.
- Embed security practices across product engineering teams.
- Represent security and compliance posture to customers, prospects, and auditors.

## Requirements

- 7+ years of experience in security, IT, or GRC, including at least 3 years managing a team.
- Broad fluency across application security, IT operations, and compliance/GRC.
- Experience owning a SOC 2 audit cycle, including evidence collection, auditor relationships, and sustainable control operations.
- Application security expertise, including OWASP, vulnerability management programs such as Snyk, and engineering security reviews.
- IT operations leadership experience, including identity and access management, Okta or equivalent, endpoint management, and remote workforce IT at scale.
- Strong strategic communication skills, translating security and compliance topics into business language for leadership and customers.

## Nice-to-haves

- Experience with ISO 27001, GDPR, or HIPAA.
- Familiarity with Snyk, Wiz, Cloudflare, and Okta.
- Experience answering enterprise security questionnaires for financial institutions or other demanding enterprise customers.
- Experience in a high-growth SaaS company where security scaled with rapid product and customer growth.

## Benefits & Compensation

- The company operates as a globally distributed, 100% remote organization.
- Fingerprint has achieved SOC 2 Type 2 and HIPAA compliance.

## Similar roles

- [Senior Product Security Engineer - QRA](https://hotfix.jobs/jobs/016d868c-3522-4a9b-a8fc-6de7e3855a4a) - Zoox - Foster City, CA - $217k – $307k/yr
- [Security Engineer - Threat Detection](https://hotfix.jobs/jobs/43718920-68b7-4e4a-8adf-20703e2271c3) - Snowflake - Remote - $211k – $304k/yr
- [Senior Information Security Engineer](https://hotfix.jobs/jobs/ce08603c-ef42-46b3-9e93-601ca9a1e56f) - Zoox - Foster City, CA - $190k – $228k/yr
- [Safety Operations Lead](https://hotfix.jobs/jobs/c83ceda2-d7a3-405c-ae10-b680f0dd7577) - Thinking Machines Lab - San Francisco, CA - $190k – $300k/yr
- [Product Security Lead](https://hotfix.jobs/jobs/7b9403f9-6255-49aa-9489-3a9d385b4596) - Forterra - Clarksburg, MD - $175k – $200k/yr

**Apply:** https://hotfix.jobs/jobs/b26070cd-790f-4fd6-a569-bf791d46913a
**Canonical:** https://hotfix.jobs/jobs/b26070cd-790f-4fd6-a569-bf791d46913a