Miro logo
Miro

We’re a visual workspace for innovation, built for distributed teams of any size.

Senior Manager – Application Security

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 1,001-5,000H1B SponsorCompany SiteLinkedIn

Location

Netherlands

Posted

54 days ago

Salary

0

Seniority

Senior

Bachelor Degree10 yrs expEnglishAWSSDLC

Job Description

Senior Manager – Application Security

Miro

• Lead and mentor a globally distributed team of security engineers focused on application security, offensive testing, secure architecture, and vulnerability remediation. • Lead and coordinate the team's initiatives and help provide project management leadership to the team members. • Coordinate cross function and cross stream initiatives and projects. • Drive integration of security into Miro’s Discover, Define, Deliver lifecycle through the lens of the AMPED Ways of Working and Operating Model. • Collaborate with Product, Engineering, and Design to ensure security is considered at the earliest stages of ideation—via threat modeling, risk reviews, and abuse-case analysis. • Shape and evolve Miro’s Secure SDLC practices, integrating security seamlessly into CI/CD pipelines, infrastructure-as-code, and developer tooling. • Oversee execution of bug bounty and third-party testing programs, ensuring vulnerabilities are triaged, communicated, and remediated effectively. • Build and scale Miro’s Security Champions program to embed security ownership within each engineering team. • Guide secure adoption of AI-augmented software development tools, including LLMs used for code generation, reviews, or architectural assistance. • Help envision and safely operationalize Agentic AI-driven developer and security workflows, including policy-driven autonomous agents supporting security automation and decision-making. • Provide structured guidance, patterns, and reference architectures that support developers in implementing secure, scalable, and privacy-respecting features. • Define and report on KPIs and success metrics for secure development adoption, vulnerability resolution, and developer engagement. • Collaborate with Privacy, Legal, and Compliance teams to ensure alignment with regulatory requirements (ISO 27001, SOC 2, GDPR, and emerging AI regulations). • Foster a strong team culture based on collaboration, learning, and continuous improvement.

Job Requirements

  • 10+ years of experience in software, application, or product security, including significant experience in secure software development.
  • 3+ years of technical leadership or management experience in a security-focused role.
  • Extensive experience with threat modeling methodologies (e.g., STRIDE, PASTA) and risk assessment, particularly within a SaaS or product-centric organization.
  • Deep expertise in Secure Software Development Lifecycles (SSDLC), including integrating security into agile and custom development frameworks.
  • Demonstrated experience running Security Champions programs and scaling developer engagement.
  • Experience leading offensive security programs (penetration testing, red teaming, bug bounty).
  • Practical understanding of governance and assurance frameworks such as ISO 27001, SOC 2, and OWASP SAMM.
  • Familiarity with AI/LLM tooling (e.g., Cursor, GitHub Copilot, custom LLM integrations) and the associated security and governance considerations.
  • Experience working with AWS and securing API-driven, microservice-based architectures.
  • Ability to manage distributed teams and communicate effectively across technical and business stakeholders.

Benefits

  • equity
  • wellbeing benefit
  • WFH equipment allowance
  • annual Learning & Development stipend

Related Categories

Related Job Pages

More Security Engineer Jobs

Head of Cyber Defense

Mitiga

Mitiga preemptively detects and stops attacks before damage is done. Mitiga moves your security beyond configuration-focused prevention. In today’s cloud-first, AI-driven world, attackers inevitably get in. Mitiga promptly stops them. Our platform connects Cloud, SaaS, AI, and Identity into one panoramic forensic system that gives SecOps total awareness, attack decoding, and autonomous containment. The result: attacks stop mid-flight, investigations are instant, and impact disappears. We replace the false promise of “zero breach” with a promise we can keep - Zero Impact. When attackers get in, Mitiga ensures they get nothing.

Role Description We’re looking for an exceptional Head of Cyber Defense to join our growing global team at Mitiga. This is a senior player-coach role - combining deep technical expertise in cloud, SaaS and AI security with a strong customer-facing presence. You'll lead Mitiga's managed CDR service, drive intelligence-led threat hunting, and conduct forensic investigations across cloud, SaaS, AI and identity environments. Sitting within Engineering, you'll work closely with R&D and Product to drive automation and AI adoption, building detection and response capabilities that scale beyond manual operations. US-based leadership is intentional: Mitiga's enterprise customers require direct engagement, rapid escalation, and executive-level communication in their time zones. What You'll Do: - Managed CDR: Monitor, triage, and respond to detections across cloud, SaaS, AI and identity; own customer-facing communication during active events within defined SLAs; maintain 24/7 team readiness. - Threat Hunting & Research: Design and lead intelligence-driven proactive hunting campaigns (MITRE ATT&CK, CISA, vendor intel); translate findings into platform-native automated detections; contribute published research and threat reports. - Incident Response: Personally lead S1/S2 forensic investigations end-to-end: scoping, evidence collection, analysis using Mitiga's Helios AI platform, attribution, and executive-quality reporting. - Customer & Commercial Engagement: Serve as the primary technical authority for enterprise customers; support sales cycles, QBRs, and EBRs; surface field-observed detection gaps to Engineering with context and accountability. - Automation & AI: Identify toil across CDR, hunting, and IR workflows; partner with Engineering to systematically automate; champion agentic SOC tooling and LLM-assisted triage. - Team & Thought Leadership: Hire, develop, and retain a global team of 5 analysts, responders, and hunters; represent Mitiga at industry events; author blog posts and threat intelligence content grounded in real operational depth. Qualifications - 8+ years of hands-on experience in cloud incident response, threat hunting, or security operations. - Deep cloud and SaaS expertise: AWS, Azure, GCP, Salesforce, GitHub, Okta, Microsoft 365, Google Workspace. - Strong command of attacker TTPs (MITRE ATT&CK for Cloud/SaaS), forensic analysis, and log-based investigation methodology. - Experience designing detection logic, hunting playbooks, or automation workflows — not only executing them. - Proven track record of direct, high-quality customer engagement with both technical practitioners and C-suite stakeholders. - Experience managing and mentoring a team; ability to build operational process and culture from an early foundation. Requirements - Conference presentations, published research, or media coverage in cloud/AI/SaaS security. - Hands-on experience with Python, KQL, SPL, or Databricks for investigative data analysis. - Experience implementing AI-assisted tooling or agentic workflows in a security operations context. - Background working within or alongside a high-growth security vendor. Benefits - Benefits package including health insurance (medical, dental, vision). - 401k plan with match. - Unlimited PTO. - Cell phone charges reimbursement. - Top-of-the-line equipment. - And more. Company Description Mitiga preemptively detects and stops attacks before damage is done. Mitiga moves your security beyond configuration-focused prevention. In today’s cloud-first, AI-driven world, attackers inevitably get in. Mitiga promptly stops them. Our platform connects Cloud, SaaS, AI, and Identity into one panoramic forensic system that gives SecOps total awareness, attack decoding, and autonomous containment. The result: attacks stop mid-flight, investigations are instant, and impact disappears. We replace the false promise of “zero breach” with a promise we can keep - Zero Impact. When attackers get in, Mitiga ensures they get nothing.

United States
Job Closed
Digital Career Institute & Social Impact School logo

DCI: Security Dozent §34a GewO (m/w/d) - voll remote

Digital Career Institute & Social Impact School

Are you looking for a job with a strong social impact? At the Digital Career Institute and the Social Impact School, we offer various training courses. We have already helped thousands of people make a fresh start and find a job in the digital world within Germany. The Digital Career Institute has been offering training in digital professions in the tech and business environment since 2016. From the initial initiative to create new future perspectives for refugees, we have developed into an established tech institute for people of all nationalities and backgrounds. Together with a highly qualified team of over 100 employees, we all work towards one mission: to provide the best possible education for interested individuals to enable them to enter the digital industry. The Impact School is an innovative education provider with a clear mission: Since our founding in 2025, we have opened new professional perspectives for people, especially where traditional educational paths do not apply. Our focus is on qualification, permeability, and genuine participation in the labor market in the fields of education, care, and support. Do you want to help even more people find attractive, future-oriented jobs with us? As a team, we celebrate successes together, and you can be a part of it. Help us shape the digital future! We look forward to your application!

Join the Digital Career Institute & Social Impact School Das Digital Career Institute (DCI) ist einer der führenden Anbieter für digitale Weiterbildungen in Deutschland. Wir helfen Menschen, neue berufliche Wege zu gehen – und vernetzen Bildung, Arbeitsmarkt und Unternehmen. Du bist Experte im Sicherheitsgewerbe und hast Freude daran, dein Wissen an angehende Sicherheitskräfte weiterzugeben? Wir suchen dich, um unsere Teilnehmenden sicher durch die Sachkundeprüfung nach §34a GewO zu führen. Deine Aufgaben - Durchführung von Online-Live-Sessions zur gezielten Vorbereitung auf die Sachkundeprüfung gemäß §34a GewO (Fokus: Recht der öffentlichen Sicherheit, Gewerberecht, BGB, Strafrecht) - Methodische Schulung der Teilnehmenden hinsichtlich aller relevanten schriftlichen und mündlichen IHK-Prüfungsanforderungen - Anwendung digitaler Vermittlungsmethoden zur verständlichen Darstellung komplexer Rechtsgrundlagen und praktischer Sicherheits-Szenarien - Kontinuierliche Evaluation der Lernergebnisse sowie eigenständige Optimierung der digitalen Lehrformate - Individuelle fachliche Begleitung, Prüfungsvorbereitung und Motivierung der Lernenden über die gesamte Kursdauer der Sicherheits-Weiterbildung Deine Skills - Erfolgreicher Abschluss der Sachkundeprüfung nach §34a GewO (oder höherwertig, z. B. Fachkraft für Schutz und Sicherheit) sowie mehrjährige einschlägige Praxiserfahrung - Idealerweise Nachweis pädagogischer Vorerfahrung in der Erwachsenenbildung oder im Bereich der Sicherheitsausbildung - Sicherer Umgang mit digitalen Tools und ausgeprägte Affinität zum Remote-Arbeiten - Sehr gute Deutsch- und Englischkenntnisse - Hohe pädagogische Kompetenz, didaktisches Geschick, Geduld und Begeisterung für die Arbeit mit Menschen in Weiterbildung Deine Benefits - Kein Arbeitsweg dank 100 % Homeoffice - Unterricht nach deinem persönlichen Stil gestalten, Hauptsache lernförderlich und angenehm für die Teilnehmenden - Ein Job mit Social Impact, der das Berufsleben von Menschen nachhaltig beeinflusst - Arbeiten in einem modernen digitalen Unternehmen, in dem KI, Gleitzeit, Workation und Homeoffice zum Standard gehören - Eine Kultur der Offenheit, in der unterschiedliche Perspektiven nicht nur willkommen sind, sondern bereits von Anfang an Teil unseres Auftrags waren

Germany
Zensar logo

Senior Security Specialist

Zensar

At Zensar, we’re “experience-led everything”. We are committed to conceptualizing, designing, engineering, marketing, and managing digital solutions and experiences for over 130 leading enterprises. We are a company driven by a bold purpose: Together, we shape experiences for better futures. Whether for our clients, our people, or the world around us, this belief powers everything we do. At the heart of our culture is ONE with Client - a set of four core values that reflect who we are and how we work: One Zensar, Nurturing, Empowering, and Client Focus. Part of the $4.8 billion RPG Group, we’re a community of 10,000+ innovators across 30+ global locations, including Milpitas, Seattle, Princeton, Cape Town, London, Zurich, Singapore, and Mexico City. We believe the best work happens when individuality is celebrated, growth is encouraged, and well-being is prioritized. We are an equal employment opportunity (EEO) and affirmative action employer, committed to creating an inclusive workplace. All qualified applicants will be considered without regard to race, creed, color, ancestry, religion, sex, national origin, citizenship, age, sexual orientation, gender identity, disability, marital status, family medical leave status, or protected veteran status.

Full TimeRemoteTeam 10,001

Role Description We are currently looking for an experienced Senior Security Specialist (m/w/d) to drive our Securities Finance Trading & Collateral technology and services roadmap to the global Securities Finance & Collateral industry. Working closely with the Product Development management to deliver on our mission to deliver future state cloud-native solution together with simplifying the integrations with open API’s and provide seamless integrations. As a Senior Security Specialist, you are part of the Securities Finance Trading and Collateral core development team. You will be responsible for ensuring the security aspects of the platform. You will be required to investigate any potential security finding by automated tools, based on dependencies as well as other sources such as penetration testing. You will be interacting with central security teams to explain false positives and ensure vulnerabilities are resolved. Qualifications - At least 7+ year’s hands-on professional experience in the Java enterprise environment. - Experience building enterprise financial solutions. - Experience with Agile and test-driven development. - Experience in working in a distributed global environment. - Experience in investigating and resolving security related findings. - Experience in upgrading and working with 3rd party open source dependencies. - Very good expertise in Java SE/JEE, TypeScript. - Very good expertise in software design patterns, integration patterns and enterprise architectural concepts. - Hands-on experience with Spring Framework and Middleware, JMS and JPA/Hibernate. - Good understanding of web frontend technologies: Angular v2+, Observables, Redux. - Experience integrating with Identity and Access Management (IAM) systems, with good understanding of concepts like OAuth, OpenID Connect and Single Sign-on. - Adapting and integrating open-source frameworks and technologies. - Very strong communication skills and fluent in English. - Team player, Willingness to take responsibility. - Passionate about software development. Requirements - Investigate and resolve security findings across multiple versions of SFTC. - Ensure false positives are properly explained to central security team and approved as false positives. - Upgrade dependencies both Java as well as Typescript/Javascript libraries. - Resolve security vulnerabilities in no longer supported open source libraries. - Ensure any security related changes will not break existing functionality. Benefits - A varied, responsible job with a wide range of opportunities to contribute and to be innovative. - A modern, international working environment in committed and motivated teams.

United Kingdom
OLX Group logo

Security Engineer

OLX Group

Together we're building a more sustainable world through trade.

Full TimeRemoteTeam 10,001+H1B No Sponsor

• Support the OLX Security Operations Center (SOC) by assisting with the incident response and its lifecycle • Contribute to incident response training for the organization • Assist in integrating our platforms and services with the SOC • Participate in “protect, detect, and respond” engineering tasks • Participate in Threat Hunting tasks • Participate in improving our threat intelligence system • Help develop, improve, and manage alerts of automated escalation processes • Work on custom integrations, which may require development skills in Python and Bash in containerized environments such as Kubernetes • Collaborate with other teams to streamline security across OLX, including Tech, Privacy, and Compliance teams.

Portugal