Job Closed
This listing is no longer active.
Build the future of communications.
Senior Manager, Security Risk
Location
United States
Posted
107 days ago
Salary
0
Seniority
Lead
Job Description
Senior Manager, Security Risk
Twilio
Who we are At Twilio, we’re shaping the future of communications, all from the comfort of our homes. We deliver innovative solutions to hundreds of thousands of businesses and empower millions of developers worldwide to craft personalized customer experiences. Our dedication to remote-first work, and strong culture of connection and global inclusion means that no matter your location, you’re part of a vibrant team with diverse experiences making a global impact each day. As we continue to revolutionize how the world interacts, we’re acquiring new skills and experiences that make work feel truly rewarding. Your career at Twilio is in your hands. We use Artificial Intelligence (AI) to help make our hiring process efficient. That said, every hiring decision is made by real Twilions! . See yourself at Twilio Join the team as Twilio’s next Senior Manager, Security Risk Management About the job Twilio is looking for a dynamic, hands-on Senior Manager of Security Risk Management to lead and evolve our global risk function. This role is designed for a strategic thinker who isn't afraid to roll up their sleeves and contribute as an individual performer while managing a high-performing, distributed team. You will be responsible for navigating a complex microservices environment of hybrid cloud and on-premise telecommunications infrastructure, ensuring our security risk approach is pragmatic, scalable, and deeply integrated into the R&D and IT lifecycles. Responsibilities In this role, you’ll: - Program Leadership & People Management: Lead, mentor, and grow a team of international and domestic risk analysts. - Foster a culture of excellence, accountability, and continuous professional development. - Hands-on Risk Assessment: Conduct and oversee complex risk assessments across microservices architectures, cloud-native environments, and legacy on-premise telecommunications systems. - Integrating compliance control requirements into the risk management process. Strategic Framework Implementation: Operationalize and mature the One Twilio Risk Management framework leveraging risk management frameworks (NIST RMF, ISO 27005, etc.) with a specific focus on emerging areas like AI Risk, Data Governance, Privacy, Reliability, and Observability. - Advanced Reporting: Develop and deliver high-impact, executive-level risk reporting. You must be able to translate technical vulnerabilities into business risk, providing leadership with the "so-what" and actionable insights to drive investment. - Workflow Optimization: Identify and design efficient process workflows within Jira and GRC tools to automate risk intake, tracking, and remediation, ensuring seamless integration with R&D and IT workstreams. - Pragmatic Problem Solving: Deliver "outside the box" based risk solutions that balance risk mitigation with business velocity. Ensure the security organization is viewed as an enabler, not a blocker. - Stakeholder Management: Act as a primary point of contact for external auditors and regulators, clearly articulating Twilio’s risk posture and the effectiveness of our controls. Qualifications Twilio values diverse experiences from all kinds of industries, and we encourage everyone who meets the required qualifications to apply. If your career is just starting or hasn't followed a traditional path, don't let that stop you from considering Twilio. We are always looking for people who will bring something new to the table! *Required - Experience: 8+ years in Cybersecurity or Information Security, with at least 4+ years in a people management role leading international teams. A "no-ego" approach to leadership; someone who is comfortable "taking the heat" for the program while giving credit to the team for successes. - Negotiation & Diplomacy: The ability to navigate high-tension situations finding the "win-win" middle ground. - Technical Domain Expertise: Deep understanding of hybrid cloud environments (AWS/GCP), on-premise infrastructure, and microservices. Experience in the Telecommunications sector is highly preferred. - Framework Fluency: Proven track record of implementing and maturing risk frameworks such as NIST RMF, ISO 3100. Specific experience in AI Risk Management or Data Governance frameworks is a significant plus. - Tooling Mastery: Power-user level proficiency in Jira (for workflow orchestration) and experience with security tooling (e.g., Wiz, Orca, Snyk) and GRC platforms (e.g., LogicGate, Jira, Archer, ServiceNow). - Strategic Mindset: Ability to pivot quickly between tactical "firefighting" and long-term strategic planning. You must be able to identify which risks are the most valuable to report on at any given time. - Communication: Exceptional written and verbal communication skills, with a proven ability to present complex risk topics to non-technical executive audiences. Ability to highlight and report on shared risk responsibility is key. - Adaptability: Proven ability to adapt to a specific company culture while driving necessary change and maturity. *Desired: - This role will have a deep fascination with how AI is changing the threat landscape and have ideas on how to govern it without stifling innovation. - Familiarity with the NIST AI RMF or ISO 42001 and the ability to assess the risks of data leakage and prompt injection in internal AI tools. - Risk Appetites & Tolerance Modeling: Ability to move beyond "High/Medium/Low" to help the business define and document specific risk appetite statements that guide engineering trade-offs. - Cost-Benefit Analysis: Skill in quantifying the cost of a security control versus the value of the risk it mitigates, ensuring pragmatic investment.This individual will understand that a perfect security score is impossible and instead focus on 'Intelligent Risk Taking' that keeps the company safe while it scales. - Threat Modeling: Experience integrating threat modeling into the early stages of a CI/CD pipeline rather than performing assessments after production. - Infrastructure as Code (IaC) Familiarity: Understanding how risk is managed in automated environments (Terraform, Pulumi) where "policy-as-code" can be implemented. - Product Security Mindset: Experience working with Product Managers to prioritize security features in a roadmap alongside revenue-generating features. Location This role will be remote, but is not eligible to be hired in CA, CT, NJ, NY, PA, WA. Travel We prioritize connection and opportunities to build relationships with our customers and each other. For this role, you may be required to travel occasionally to participate in project or team in-person meetings. What We Offer Working at Twilio offers many benefits, including competitive pay, generous time off, ample parental and wellness leave, healthcare, a retirement savings program, and much more. Offerings vary by location. Compensation *Please note the salary range information provided applies only to candidates residing in California, Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Washington D.C., and Washington State due to local requirements. Compensation for candidates in other locations will be discussed during the hiring process. Please note that hiring for this role is not restricted to the locations listed above. The estimated pay ranges for this role are as follows: - Based in Colorado, Hawaii, Illinois, Maryland, Massachusetts, Minnesota, Vermont or Washington D.C. : $207,200 - 259,000. - Based in New York, New Jersey, Washington State, or California (outside of the San Francisco Bay area): $219,360 - 274,200. - Based in the San Francisco Bay area, California: $243,680 - 304,600 - This role may be eligible to participate in Twilio’s equity plan and corporate bonus plan. All roles are generally eligible for the following benefits: health care insurance, 401(k) retirement account, paid sick time, paid personal time off, paid parental leave. The successful candidate’s starting salary will be determined based on permissible, non-discriminatory factors such as skills, experience, and geographic location. Applications for this role are intended to be accepted until May 20th, 2026, but may change based on business needs. Twilio thinks big. Do you? We like to solve problems, take initiative, pitch in when needed, and are always up for trying new things. That's why we seek out colleagues who embody our values — something we call Twilio Magic. Additionally, we empower employees to build positive change in their communities by supporting their volunteering and donation efforts. So, if you're ready to unleash your full potential, do your best work, and be the best version of yourself, apply now! If this role isn't what you're looking for, please consider other open positions. Twilio is proud to be an equal opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Additionally, Twilio participates in the E-Verify program in certain locations, as required by law.
Related Guides
Related Categories
Related Job Pages
More Security Operations Jobs
Senior Technical Consultant-Network Security Operations
AHEAD, Inc.AHEAD, Inc. is an IT services and consulting company that is on a mission to “accelerate the impact of technology on business.” As an employer, the company
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description The Technical Consultant, Network Security Operations, is a cybersecurity professional with knowledge around the Palo Alto XSIAM Platform, Cortex XDR, Cortex XSOAR and working knowledge around additional technologies. Responsible for the technical execution of XSIAM, XDR and XSOAR deployments with complex configurations. As a Technical Consultant, you will be a key player in implementing Security Operation tools for a diverse client base, helping them detect, respond and automate effectively. - Hands-on role in the end-to-end delivery of Palo Alto XSIAM, XSOAR, and XDR solutions to include deployment, configuration and customization to meet client requirements. - Develop and implement custom XSIAM, XSOAR and XDR content such as Correlations rules, data models, Automation Playbooks that streamline client SOC workflows. - Integrate a variety of data sources that ensure visibility across endpoint, network, cloud and identity. - Collaborate with clients to optimize and fine tune their deployment and provide guidance to assist with the optimization of the platform. - Act as a technical resource for troubleshooting and resolving complex XSIAM-related issues during and post-implementation. - Contribute to detection and Playbook strategies to enhance client security posture. - Contribute to project documentation, ensuring clarity and completeness of Solution Designs and As-Built configurations. - Mentor junior AHEAD consultants, sharing your XSIAM knowledge and fostering their technical development. Qualifications - 3-5 years of dedicated experience in cybersecurity, with a strong practical background in SIEM, SOAR, EDR/XDR, or SOC operations. - 2-4 years of demonstrated threat intelligence and/or Incident response experience. - Minimum of 2 years of direct experience implementing and configuring XSIAM or similar advanced SecOps Platforms. - Demonstrated expertise in SIEM and Soar development to include creating playbooks, log collection, parsing and normalization. - Demonstrated expertise in EDR/XDR deployment and management with CrowdStrike, Cortex and Cisco. - Proficient with XQL for data analysis and rule creation. - Solid Understanding of network security, cloud environments, Identity, Linux, Mac and Windows. - Strong analytical and troubleshooting capabilities. - Effective communication skills with the ability to engage with clients and Team members. - Palo Alto Network Certifications (PCNSE) or relevant industry certifications (CISSP, CYSA, CEH, Security+, Pentest+, OSCP) are a plus. Requirements - $130,000 - $200,000 a year Benefits - Medical, Dental, and Vision Insurance - 401(k) - Paid company holidays - Paid time off - Paid parental and caregiver leave - Plus more! See benefits here for additional details.
Cyber Operations Intern
American SystemsHeadquartered in Chantilly, Virginia, American Systems is a government contractor that provides professional, technical, and Information Technology services. Established in 1975, A
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description We are looking for an entry level IT Security Analyst summer intern to perform the day-to-day operations of the security solutions and use these solutions to identify, investigate and resolve security incidents on the network. This is a great opportunity for someone who likes to dig in and understand the intricacies of cyber defense, has a technical hands-on mindset, and exhibits good work ethic and a positive attitude to learning the ins and outs of information security operations for an enterprise environment. - Co-Op / Interns typically represent college students trying to gain related work experience while pursuing an undergraduate degree. - Under direct supervision, performs various tasks and assignments for the organization's professional staff in such disciplines as Engineering, Software Development, Database Management, Security Threat Analysis. - Maintain in-place security tools and processes. - Evaluate, test and implement new security tools & technologies. - Respond to computer security incidents. - Research system and network logs and alerts as they relate to incidents. - Identify gaps in cyber operations capabilities and assist in developing those capabilities. - Develop technical summary information for presentation to management. Qualifications - High School diploma and 1-2 years of college or related work experience. - Understanding of incident response process in an enterprise operations environment. - Understanding of cyber threats and defenses against those threats. - Knowledge of Windows, Linux, and networking. - Knowledge of enterprise security technologies such as web filtering, endpoint protection and forensics, sandbox, threat intel integration, firewalls, SIEM, patch and vulnerability management etc. - Familiarity with using scripting languages for security automation. - Ability to juggle multiple tasks and projects with varying priorities. - Ability to document findings for audiences with various levels of technical expertise. - MUST BE A US CITIZEN. - Cyber Defense Club membership a plus! Benefits AMERICAN SYSTEMS is committed to pay transparency for our applicants and employee-owners. The salary range for this position is USD $43,200.00/Yr. - USD $72,100.00/Yr. Actual compensation will be determined based on several factors permitted by law. AMERICAN SYSTEMS provides for the welfare of its employees and their dependents through a comprehensive benefits program by offering healthcare benefits, paid leave, retirement plans, insurance programs, and education and training assistance. EEO Statement EEO Race/Sex/Disability Status/Veteran Status
Member of the Technical Staff, Security Operations
Anchorage DigitalTrusted institutional partner in crypto and first federally chartered crypto bank
Founded in 2017, Anchorage Digital is a regulated crypto platform that provides institutions with integrated financial services and infrastructure solutions. With the first federally chartered crypto bank in the US, Anchorage Digital offers institutions an unparalleled combination of secure custody, regulatory compliance, product breadth, and client service. We’re looking to diversify our team with people who are humble, creative, and eager to learn. We are a remote friendly, global team, but provide the option of working in-office in New York City, Sioux Falls, Porto, Lisbon, and Singapore. For our colleagues not located near our beautiful offices, we encourage and sponsor quarterly in-person collaboration days to work together and further deepen our Village The Security Operations team develops hardware and software solutions designed to establish and test security guardrails across the code, cloud resources, and hardware infrastructure of the Anchorage platform. By managing vulnerabilities in both in-house and third-party components, the team partners with service owners to secure networking and infrastructure while continuously monitoring for anomalies or unexpected configuration changes. To enhance efficiency, they strategically automate investigation tasks, threat isolation, inventory management, and assurance provision for regulated entities, all while conducting rigorous static and dynamic testing of application interfaces throughout the organization. We have created the Factors of Growth & Impact to help Villagers better measure impact and articulate coaching, feedback, and the rich and rewarding learning that happens while exploring, developing, and mastering the capabilities and contributions within and outside of the Security Operations position. Technical Skills: - Build and maintain security automation and tooling to detect vulnerabilities through static and dynamic analysis across code and live systems. - Conduct application security assessments, penetration tests, and code reviews to identify high-risk security issues and provide secure development guidance. - Develop and operate vulnerability management workflows, partnering with engineering teams to prioritize and remediate findings. - Establish and test security guardrails for code, cloud resources, and infrastructure components throughout the Anchorage platform. Complexity and Impact of Work: - Monitor and respond to security events and configuration anomalies across the organization, leading investigation and containment efforts. - Manage the full vulnerability lifecycle from discovery through remediation, tracking progress and ensuring timely closure of findings. - Lead or substantially contribute to Security Operations initiatives with minimal oversight, coordinating across team boundaries to drive projects to completion. - Break complex security problems into manageable workstreams with accurate scope and time estimates. Present options clearly and provide well-reasoned priority recommendations. - Deliver assurance artifacts and evidence for regulated entity requirements, supporting audit and compliance efforts. - Balance speed of response with thoroughness of investigation, adapting approach based on risk and business impact. Organizational Knowledge: - Understand and help implement the company's security strategy by participating in planning and defining Security Operations goals in alignment with Anchorage Digital's overall objectives. - Stay alert to emerging threats, vulnerabilities, and industry trends that could affect organizational security posture. - Consider security holistically across the product ecosystem—applications, infrastructure, and third-party integrations—while fostering a security-first culture. - Collaborate cross-functionally with Engineering, Infrastructure, and Compliance teams to embed security into development and operational processes. Communication and Influence - Share knowledge broadly across the team through documentation, runbooks, and post-incident reviews, preventing single points of failure. - Partner with engineering teams to explain security risks and remediation approaches, translating technical findings into actionable guidance. - Collaborate across teams to review security configurations, triage findings, and engage in technical discussions. Communicate insights and recommendations clearly to improve processes. - Demonstrate empathy by understanding others' context, priorities, and constraints—adapting communication style to maximize effectiveness with both technical and non-technical audiences. You may be a fit for this role if you have: - Security Operations or AppSec experience: You have 3+ years of hands-on experience in security engineering, application security, penetration testing, or security operations. - Security tooling and automation: You have built or maintained security tools, integrations, or automation workflows using Python, Go, or similar languages. - Vulnerability assessment: You can identify and assess security vulnerabilities in applications, APIs, and cloud infrastructure, and effectively communicate remediation strategies. - Static and dynamic analysis: You have experience with tools like Semgrep, CodeQL, Burp Suite, or equivalent for identifying security issues in code and running systems. - Cloud security: You understand AWS security fundamentals including IAM, VPCs, security groups, and CloudTrail/logging. - Incident response: You can investigate security events, perform root cause analysis, and coordinate response efforts. - You have developed "computer science fundamentals," i.e. concurrency, algorithms, and data structures. - You genuinely care about code quality and operational excellence. - You prioritize security outcomes, end-user experience, and business value over "cool tech." - You self-describe as some combination of the following: creative, humble, ambitious, detail-oriented, hardworking, trustworthy, eager to learn, methodical, action-oriented, and tenacious. Although not a requirement, bonus points if: - You have experience running or participating in bug bounty programs (HackerOne, Bugcrowd, etc.). - You have worked in a regulated financial services, fintech, or crypto environment. - You have exposure to blockchain security, smart contract auditing, or Web3 technologies. - You have built or contributed to open-source security tools. - You hold relevant certifications (OSCP, GWAPT, GCIH, AWS Security Specialty, etc.). - You read blockchain protocol white papers for fun, and stay up to date with the proliferation of crypto-asset innovations. - You were emotionally moved by the soundtrack to Hamilton, which chronicles the founding of a new financial system. :) We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Cyber Operations Intern
AMERICAN SYSTEMSSupporting national priority programs since 1975. We know what's at stake.®
• Perform day-to-day operations of security solutions • Identify, investigate and resolve security incidents on the network • Maintain in-place security tools and processes • Evaluate, test and implement new security tools & technologies • Respond to computer security incidents • Research system and network logs and alerts as they relate to incidents • Identify gaps in cyber operations capabilities and assist in developing those capabilities • Develop technical summary information for presentation to management



