Senior Engineering Manager, Security
Job description
About the role
You will own the end-to-end security engineering foundation for Imprint, defining strategy and execution across AI security governance, application security, cloud infrastructure, detection and response, and identity management. You will leverage AI tooling to scale the impact of a small, talent-dense team while staying hands-on enough to write detection rules, review pull requests, and file hardening commits. You will threat-model new agent surfaces for prompt injection, tool misuse, and authorization boundaries, and build AI-native workflows for detection triage and compliance automation. This role blends full-stack security ownership with the freedom to set long-term direction for a regulated fintech operating at product-market fit. You will partner closely with engineering and product teams to embed security into the development lifecycle from day one, ensuring that co-branded credit card programs and AI features can launch safely and quickly.
Key facts
What you'll do
- Define and drive a security strategy that scales with AI-first product development while maintaining strict compliance for co-branded credit card programs.
- Build and operate an AI security governance framework, including threat modeling for agentic workflows, prompt injection defenses, and authorization boundaries for AI tools.
- Use AI to multiply team leverage, creating AI-powered detection triage, automated compliance evidence collection, and AI-assisted threat modeling across the engineering organization.
- Own application security practices, including secure code review, SAST/SCA/DAST in CI, dependency management, secrets management, and secure design reviews for new features.
- Architect and manage cloud security across multiple AWS accounts, enforcing least-privilege access, JIT elevation, cross-account trust hardening, KMS boundaries, SCP guardrails, and Kubernetes pod security.
- Establish detection and response capabilities, building the SIEM/SOAR pipeline from log ingestion through alert triage, incident response runbooks, and on-call rotation management.
- Drive identity and access management initiatives, including SSO coverage, access reviews, and JIT elevation in collaboration with IT and security stakeholders.
- Partner with compliance and risk teams to design, implement, and audit controls for PCI DSS, SOC 2, ISO 27001, and other relevant frameworks.
- Read and review Go and TypeScript code to catch security vulnerabilities early, reducing reliance on external audits and costly rework.
- Set operational baselines for egress filtering, Terraform security reviews, KMS key policies, and CI security gates to prevent regressions.
- Lead incident response for security events, owning runbooks, communication plans, and post-incident reviews with actionable follow-ups.
- Mentor engineers on secure coding practices, threat modeling techniques, and the responsible use of AI in security-sensitive contexts.
Requirements
- You have 8+ years of professional experience in software engineering, security engineering, or a related technical role with a strong track record of delivering secure systems.
- You hold a Bachelor's degree in Computer Science, Engineering, or a related technical field, or an equivalent combination of education and relevant experience.
- You possess deep expertise in cloud security, identity and access management, application security, and detection engineering across modern distributed systems.
- You are proficient in reading and reviewing code written in Go and TypeScript, with the ability to identify security flaws during code review.
- You have hands-on experience with CI/CD pipelines, SAST, SCA, DAST, and secrets management tools used in production environments.
- You understand regulatory frameworks relevant to financial services, including PCI DSS, SOC 2, and ISO 27001, and have implemented controls aligned with these standards.
- You have experience designing and operating SIEM and SOAR platforms, writing correlation rules, and conducting incident response in a 24/7 on-call model.
- You are comfortable making decisions in a fast-paced, product-driven environment where strategy evolves through execution and feedback.
Practical notes
The role is full-time based in San Francisco. There is no specified relocation assistance, visa sponsorship, or travel requirements in the provided source. The position reports to the Director of Engineering for Trust & Security, and hours are standard full-time during Imprint business operations.