Senior Manager, Security Engineering
Key Responsibilities
Security Monitoring - Security Tool Design and Development:
– Drives security strategy, ensuring that organizational goals are met.
– Oversees employees working on security assessments across a wide range of complex products and services.
– Guides the creation of testing tools and facilitates their integration into engineering workflows, ensuring the team is equipped to identify and address security-related weaknesses efficiently.
– Chairs security design and evaluation (e.g., traffic capturing, alerts), ensuring adherence to internal and external obligations, and strengthening security posturing.
Event Response:
– Establishes protocols for security violation escalation, managing communication with senior leadership and stakeholders.
– Develops and enforces protocols to contain and mitigate security events, coordinating cross-functional response efforts.
– Leads post-event review meetings to identify improvement areas, ensuring feedback is incorporated into ongoing security processes.
– Provides guidance to stakeholders who come to the security team with security events or concerns.
Compliance:
– Conducts compliance assessments and coaches employees providing compliance assessments.
– Ensures team's security compliance deliverables adhere to internal and external obligations.
– Oversees inventory, operability, and accountability of company assets, implementing robust tracking systems.
Business Continuity Support:
– Guides the development of business continuity and disaster recovery plans, processes, and procedures.
– Ensures the availability and resilience of critical systems and data, overseeing efforts to withstand disruptions.
– Directs readiness assessments for certifications and audits, implementing improvements to meet evolving standards.
Data Security and Privacy:
– Guides employees on using advanced tools and techniques for data security such as encryption, hashing, masking, and access management to ensure the confidentiality and integrity of sensitive information.
– Oversees the review of documentation and procedures, identifying and implementing improvements in data security practices.
Research and Innovation:
– Drives industry security knowledge advancement, fostering research and innovation efforts.
– Aligns the team on emerging trends, ensuring shared knowledge of evolving threats and vulnerabilities.
– Promotes novel techniques to solve unique security problems, encouraging creative and effective solutions.
Core Responsibilities
Planning & Execution:
– Manages multiple medium- to large-scale projects or initiatives across teams, ensuring timelines, deliverables, and budgets when applicable are monitored and met.
– Provides direction to teams on project work, setting priorities, and aligning with business needs.
– Guides teams on adjusting plans to accommodate resource or timeline changes.
Collaboration & Partnership:
– Drives cross-functional partnerships to align expectations and shared objectives across multiple teams.
– Coaches team members to develop strategic relationships with business leaders, stakeholders, and external partners to foster collaboration and long-term success.
– Promotes inclusivity by actively seeking and listening to diverse perspectives, ensuring others feel heard and respected.
Problem Solving:
– Provides direction to multiple teams on addressing complex operational and/or technical issues as well as providing guidance on analyzing complex data and/or information to identify solutions.
– Reviews and provides insights into unresolved or critical issues, helping the team to identify potential solutions.
Continuous Learning:
– Models engaging in continuous learning to deepen expertise and stay ahead of industry trends, integrating best practices into strategic planning.
– Leverages feedback to drive personal and team skill improvements.
– Identifies skill gaps across teams, and empowers team members to pursue learning and knowledge sharing opportunities that build their expertise in new areas and coaches them to apply learnings to advance the organization.
Continuous Improvement:
– Drives team to collaborate on, develop, and implement ideas to increase the efficiency and effectiveness of processes, protocols, and workflows within and across teams, providing oversight.
– Guides team to adopt new ideas for alternative approaches and methods and encourages feedback for continued improvement.
Performance and Development:
– Drives performance across teams by providing feedback and coaching in alignment with performance management processes, guidelines, and expectations.
– Discusses development goals with team members, shares opportunities to facilitate career development, and ensures individual goals are aligned with broader organizational goals.
– Develops and manages talent acquisition pipeline by leading candidate interviews, monitoring promotion eligibility, and/or orchestrating talent resources.
Minimum Job QualificationsEducation and/or Experience:
9 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field
OR
Bachelor's Degree in Computer Science, Information Technology, Computer Security, Engineering, or related field AND 5 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field
OR
Master's Degree in Computer Science, Information Technology, Computer Security, Engineering, or related field AND 3 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field.
Job Skills:
Same skills as prior level plus;
Incident Management and Response Demonstrated ability in or knowledge of incident management and response, including timely handling and escalation of incidents to minimize business impact.
Threat Modeling Demonstrated ability in or knowledge of threat modeling, including applying techniques to identify and mitigate security risks and vulnerabilities.
Cloud Security Demonstrated ability in or knowledge of cloud security, including protecting cloud infrastructure and data using risk management frameworks.
Preferred Job Qualifications
Education and/or Experience:
11 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field
OR
Bachelor's Degree in Computer Science, Information Technology, Computer Security, Engineering, or related field AND 7 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field
OR
Master's Degree in Computer Science, Information Technology, Computer Security, Engineering, or related field AND 5 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field.
Job Skills:
Same skills as prior level.
People Leadership / Management Experience:
3 years of experience in a leadership role with direct reports.
Budget Experience:
2 years of experience working with operating budgets and/or project financials.
Cloud or Internet Software Security Experience:
3 years of experience working on high-impact projects related to cloud or internet software security.
Programming/Scripting Experience:
3 years of experience working with one or more of the following programming or scripting languages (e.g., Go, Java, Python, or C/C++).
Cloud Experience:
6 months of experience with AWS Solution, Azure 900 Fundamentals, OCI Fundamentals, or equivalent cloud experience.
Information Security Certifications:
Information security or equivalent certifications (e.g., Certified Oracle Cloud Infrastructure Security Professional, Certificate of Cloud Security Knowledge [CCSK], Certified Information Security Manager [CISM], Certified Information Systems Security Professional [CISSP], Certified Ethical Hacker [CEH], Certified Cloud Security Professional [CCSP], Offensive Security Certified Professional [OSCP], Cisco Certified Network Associate [CCNA], Certified Information Systems Auditor [CISA], CompTIA Security+).