Senior Manager, Information Security Architecture & Engineering
Job description
About the role
This position is a senior leadership role focused on establishing and maintaining comprehensive security strategies across the company's platform, applications, and data systems. You will be responsible for designing, implementing, and overseeing security controls and frameworks that protect organizational assets and ensure compliance with relevant standards. The role involves working closely with engineering, operations, and governance teams to embed security principles into all phases of system development and operational processes. You will act as a key second line of defense, guiding technical teams and influencing security practices organization-wide. The ideal candidate will possess a blend of technical expertise, strategic thinking, and leadership skills to foster a security-conscious culture and drive continuous improvement in security posture.
Key facts
What you'll do
- Develop, implement, and maintain security frameworks and policies that ensure secure application and infrastructure design, embedding security principles early in the development lifecycle.
- Collaborate with engineering, DevOps, and other technology teams to integrate security controls into development pipelines, deployment processes, and data flows, ensuring security is a foundational element rather than an afterthought.
- Lead the vulnerability management program, overseeing the identification, prioritization, and remediation of security vulnerabilities across systems and applications.
- Enhance and scale the security design review process for new and existing systems, ensuring security considerations are thoroughly evaluated and addressed before deployment.
- Design and develop security services and tools that facilitate rapid development cycles while maintaining strong security controls and compliance standards.
- Provide expert security guidance and best practices to engineering, operations, and product teams, aligning security initiatives with business objectives and operational needs.
- Work closely with Governance, Risk, and Compliance (GRC) teams to ensure technical security controls meet regulatory requirements and industry standards such as NIST CSF, PCI-DSS, and GLBA.
- Promote a security-aware culture by conducting training sessions, awareness campaigns, and providing ongoing education to technical staff and stakeholders.
- Lead efforts to design security controls for distributed computing environments, data movement, and cloud-based systems, ensuring data integrity and confidentiality.
- Stay informed about emerging security threats, vulnerabilities, and technological advancements to proactively adapt security strategies and defenses.
- Participate in incident response planning, investigations, and post-incident reviews to improve security resilience.
- Conduct security assessments, audits, and risk analyses to identify gaps and recommend improvements.
- Advocate for security best practices across the organization, influencing product development, system architecture, and operational procedures.
- Manage and mentor a team of security engineers and architects, fostering professional development and ensuring high-quality security deliverables.
- Communicate complex security concepts effectively to technical teams and executive leadership, ensuring alignment and understanding of security risks and mitigation strategies.
Requirements
- A minimum of 10 years of experience in security architecture, application security, or infrastructure security roles.
- Extensive hands-on experience with cloud security platforms such as AWS, Azure, or GCP, including designing and implementing security controls in cloud environments.
- Proven ability to lead and develop geographically distributed security teams, fostering collaboration and professional growth.
- Deep understanding of secure software development practices, security testing methodologies, and threat modeling techniques.
- Strong knowledge of security controls for distributed systems, data security, and secure data movement.
- Excellent communication skills, capable of conveying security risks and strategies to both technical and executive audiences.
- Familiarity with security standards and regulatory frameworks including NIST CSF, PCI-DSS, and GLBA.
- Bachelor's degree in Computer Science, Information Security, or a related technical field.
Nice to have
- Experience with application security testing, threat modeling, bug bounty programs, and security assessments.
- Knowledge of identity and access management (IAM), encryption, authentication mechanisms, and logging and monitoring architectures.
- Hands-on experience with tools such as GitHub, Wiz, Sentinel One, and Okta.
- Relevant security certifications like CISSP, CISM, OSCP, or AWS Security Specialty.
- An advanced degree in Computer Science, Information Security, or related fields.
Skills & tools
- Cloud Security (AWS, Azure, GCP)
- DevSecOps practices and tools
- Data Security and encryption techniques
- Secure Software Development Lifecycle (SDLC) practices
- Threat modeling methodologies
- Vulnerability management processes
- Identity & Access Management (IAM) systems
- Security frameworks such as NIST CSF, PCI-DSS, GLBA
Practical notes
- Visa sponsorship is not available for this role.
- The salary range listed is for base compensation only and does not include other benefits.
- This position is on-site in the specified location; it is not remote unless explicitly stated.
- The role requires working within a security team that collaborates closely with engineering, operations, and compliance functions.
- Candidates should be prepared to demonstrate their experience through technical interviews, case studies, or assessments.
- The organization values diversity and encourages candidates from all backgrounds to apply.