Senior Manager, Information Security Architecture & Engineering
OportunRemote (USA)5d ago
SecurityEngineeringremotecurated-jd
Job description
Senior Manager, Information Security Architecture & Engineering
About the role
This position is for a key security leader responsible for defining and implementing robust platform, application, and data security strategies. You will ensure security principles are integrated from the design phase through development and operations, acting as a crucial second line of defense. The role requires both technical depth and strong leadership to guide a team and influence cross-functional initiatives.
Key facts
What you'll do
- Establish and maintain frameworks for secure application and infrastructure design, embedding security early in the lifecycle.
- Collaborate with engineering, DevOps, and technology teams to integrate security into development pipelines and data flows.
- Manage and advance the vulnerability management program, prioritizing remediation efforts.
- Enhance and scale the security design review process for new and evolving systems.
- Develop security services that enable rapid development while maintaining strong controls.
- Provide security guidance to engineering and operations teams, aligning with business objectives.
- Work with Governance, Risk, and Compliance teams to ensure technical security meets regulatory needs.
- Promote a security-conscious culture, educating teams on risks and best practices.
Requirements
- A minimum of 10 years in security architecture, application security, or infrastructure security.
- Significant experience with cloud security (AWS, Azure, GCP), DevSecOps, or data security.
- Proven ability to lead and develop globally distributed teams, fostering professional growth and collaboration.
- Experience designing security controls for distributed computing and data movement.
- Hands-on knowledge of secure software development, security testing, and threat modeling.
- Strong leadership skills with the ability to communicate security risks to diverse stakeholders.
- Familiarity with security frameworks and regulations such as NIST CSF, PCI-DSS, and GLBA.
- A Bachelor's degree in Computer Science, Information Security, or a related field.
Nice to have
- Expertise in application security testing, threat modeling, bug bounty programs, and software security assessments.
- Deep understanding of identity and access management (IAM), encryption, authentication, logging, and monitoring architectures.
- Experience with GitHub, Wiz, Sentinel One, and Okta.
- Security certifications like CISSP, CISM, OSCP, or AWS Security Specialty.
- An advanced degree in Computer Science, Information Security, or a related field.
Skills & tools
- Cloud Security (AWS, Azure, GCP)
- DevSecOps
- Data Security
- Secure Software Development Practices
- Threat Modeling
- Vulnerability Management
- Identity & Access Management (IAM)
- NIST CSF, PCI-DSS, GLBA
Practical notes
- Visa sponsorship is not available for this role.
- The salary range listed is for base compensation only and does not include other benefits.