Contentful logo
Contentful

Contentful offers a next-generation, API-first content platform to power and accelerate great digital experiences. The company employs "kind and genuine people"

Manager, Security Engineering

Location

EST (UTC-5)

Posted

31 days ago

Salary

0

Seniority

Lead

Job Description

Manager, Security Engineering

Contentful

Role Description We are looking for a committed and driven manager who is passionate about solving complex security problems in innovative and scalable ways. As a Manager of Security Engineering, you will own security engineering across Contentful’s corporate systems, including the tooling and platforms that support the internal security team. While this role does not own security for the customer facing product, you will partner closely with product security teams within the security organization on shared responsibilities. - Develop a team, providing coaching, mentorship, goal setting, and performance feedback. - Define roles and make hiring decisions to grow the team in line with department needs. - Remain hands on, balancing technical leadership with direct implementation work. - Own execution and prioritization across projects and operations, using agile delivery practices. - Scale and mature effectiveness and efficiency by improving processes and tooling. - Champion continuous improvement across all aspects of the security program. - Continuously improve effectiveness and efficiency by evolving processes and tooling. - Communicate risks and technical concepts with clarity to leadership and stakeholders. - Collaborate with security leadership to execute business aligned, risk reduction roadmaps. - Shape work scope, sequencing, and success criteria inline with department and company needs. - Drive security processes, standards, and best practices across information technology assets. - Partner with stakeholders to evolve security awareness and specialized training across all functions. - Mature capabilities across endpoint, SaaS, and cloud configuration. - Own strategy evolution of corporate capabilities, including configuration, IAM, and data security. - Enhance tooling, automation, and integrations to improve visibility and reduce manual effort. - Support and guide security incident response efforts as a technical leader. - Support cross functional vulnerability management while advancing the program capabilities. - Define and maintain metrics to measure impact, optimize execution, and guide investment. - Partner with cross-functional teams for security enhancement and drive risk reduction. - Accelerate adoption of AI, balancing practicality enablement, and risk management. - Stay current on threats, vulnerabilities, and tactics, translating insights into actionable strategies. Qualifications - 8+ years of progressive engineering and security experience. - 3+ years managing people and security engineering teams. - Comfort operating in ambiguity, balancing strategic thinking, security, and practicality. - Expertise with AWS, GCP, and Azure. - Strong hands-on experience designing, implementing, and operating security controls at scale. - Demonstrated experience securing endpoint, SaaS, and cloud environments. - Experience working within identity and access management and data security programs. - Software development experience in modern programming language (Python, Go, etc). - Hands-on experience using Terraform and infrastructure-as-code. - Experience applying modern practices to improve efficiency and scalability of security programs. - Passion for solving complex security problems in innovative and scalable ways. - Experience using metrics to measure impact, optimize execution, and guide investment decisions. - Strong communication skills with the ability to explain technical topics to non-technical audiences. - Ability to support occasional off-hours incident response efforts. - Familiarity with attacker techniques in cloud-native and traditional environments. - Hands-on experience owning security technologies (e.g., EDR, AntiVirus, etc.). - Proven ability to lead cross-functional initiatives and influence outcomes without direct authority. - Experience owning end-to-end security programs, proactively driving incremental improvement. - Strong systems thinking, with the ability to design security solutions that scale through efficiency. Benefits - Join an ambitious tech company reshaping the way people build digital experiences. - Full-time employees receive Stock Options for the opportunity to share in the success of our company. - Comprehensive healthcare package covering 100% of monthly health premiums for employees and 85% of costs for your dependents. - Fertility and family building benefits, including a lifetime reimbursable wallet to support your growing family. - A generous amount of paid time off, including vacation days, sick days, compassion days for loss, education days, and volunteer days. - Company paid parental leave to care for and focus on your growing family. - Use your personal annual education budget to improve your skills and grow in your career. - Enjoy a full range of virtual and in-person events, including workshops, guest speakers, and fun team activities, supporting learning and networking exchange beyond the usual work duties. - An annual wellbeing stipend to care for your physical, financial, or emotional health. - A monthly communication stipend and phone hardware upgrade reimbursement. - New hire office equipment stipend for hybrid or distributed employees.

Related Categories

Related Job Pages

More Security Engineer Jobs

Allstate logo

Risk Partner Senior Manager - Technology and Cybersecurity

Allstate

Allstate, known for its slogan “you’re in good hands,” was founded in 1931 and is now the United States' largest publicly-held insurance company. Allstate

Risk Partner Senior Manager - Technology & Cybersecurityremote type USA - IL (Remote) Full time Job requisition id R27628 At Allstate, great things happen when our people work together to protect families and their belongings from life’s uncertainties. And for more than 90 years, our innovative drive has kept us a step ahead of our customers’ evolving needs. From advocating for seat belts, air bags and graduated driving laws, to being an industry leader in pricing sophistication, telematics, and, more recently, device and identity protection. Job Description As a Risk Partner Senior Manager supporting Technology and Cybersecurity, you’ll add value by being a second line of defense, responsible for representing and providing a forward‑looking view of operational risk for Allstate’s Enterprise Shared Services Technology team. You’ll also support other shared services like HR, Legal, Finance and Law & Regulation. Your consolidated operational risk view of the criticality of enterprise platforms, sensitive data, regulatory obligations and third-party ecosystems will be provided for each these functions. Recognizing that engagement with technology teams and that many material risk discussions are rooted in cyber and technology risk, your deep cybersecurity knowledge and expertise will help drive alignment. While supported by an extended team of domain specialists (e.g., resilience, third‑party, regulatory), the Risk Partner personally leads cybersecurity risk engagement and integrates those insights into a broader operational risk narrative for executive leaders. You’ll act as a trusted advisor to business and technology leadership, translating complex risk signals into clear business impact, enabling informed decision‑making, and ensuring that material risks are identified, assessed, escalated, and managed in alignment with enterprise risk frameworks. Key Responsibilities: Enterprise and Business Risk Partnership - Serve as the primary risk partner and advisor to senior business and technology leaders for Enterprise Shared Services Technology (ATS) and the supported shared services functions (Human Resources, Legal, Finance, and Law & Regulation) providing an integrated view of operational risk across cybersecurity, technology, resilience, third‑party, and compliance domains. - Develop and maintain a consolidated risk profile that connects disparate risk signals into a coherent, decision‑enabling narrative for leadership and governance forums. - Influence strategy, investment decisions, and delivery roadmaps by ensuring risk considerations are identified early and aligned with enterprise risk tolerance. Cybersecurity Risk Leadership (Core Accountability) - Provide cybersecurity risk leadership for enterprise platforms supporting shared services, including risks related to sensitive employee data, financial systems, legal information, regulatory data, and privileged access. - Maintain hands‑on cybersecurity expertise and serve as the primary cybersecurity risk authority for the supported business and technology domain. - Lead high-impact cyber risk discussions with technology teams and ensure informed stakeholder risk acceptance decisions. - Translate high-severity cybersecurity findings (e.g., vulnerabilities, control deficiencies, incident learnings) into clear business impact, tradeoffs, and risk posture for senior leaders. - Function as the second line risk advisor during significant cyber incidents or supplier events, assessing business and customer impact and overseeing remediation and risk decisions. Second Line of Defense Oversight - Operate as a second line of defense function, providing independent oversight, challenge, and guidance to first line teams without owning controls or delivery execution. - Apply enterprise risk taxonomies, assessment methodologies, and reporting standards to ensure consistency and comparability of risk information. - Monitor remediation commitments, documented exceptions, and compensating controls, escalating risks that exceed established tolerance. Risk Identification, Assessment, and Reporting - Plan and oversee risk assessments and thematic reviews, synthesizing outputs into executive‑level insights and trend analysis. - Identify systemic risk trends and emerging threats, proactively advising leadership on potential impacts and mitigation options. - Prepare and deliver concise risk briefings for senior leaders, councils, and committees. Collaboration Across Risk Functions - Prepare and deliver concise risk briefings for senior leaders, councils, and committees. - Leverage extended domain expertise while retaining accountability for the integrated risk view and messaging. Required Qualifications: - 10+ years of experience in cybersecurity, technology risk, operational risk, or related disciplines within a large, complex organization. - Demonstrated deep cybersecurity expertise equivalent to a Business Information Security Officer, Security Risk Lead, or similar senior cyber risk role. - Proven experience operating in or alongside a second line of defense function within a Three or Four Lines of Defense model. - Ability to engage credibly with senior engineers, architects, and security teams while maintaining independence from first‑line delivery ownership. - Strong executive communication skills with the ability to translate technical risk into business impact. Preferred Qualifications: - Experience in highly regulated environments and familiarity with regulatory expectations impacting technology and cybersecurity risk. - Experience with operational resilience, third‑party risk, or enterprise risk management functions. - Relevant professional certifications (e.g., CISSP, CISM, CRISC, or equivalent). Skills Cyber Risks, Data Privacy, Enterprise Risk Management (ERM), Information Security Risk Management, IT Governance Risk and Compliance (GRC), IT Security Operations, Operation Risk Management, Relationship Management, Security Consulting, Security Risk, Stakeholder Influence, Stakeholder Relationship Management Compensation Compensation offered for this role is 151,700.00 - 221,675.00 annually and is based on experience and qualifications. The candidate(s) offered this position will be required to submit to a background investigation.

Illinois
$151.7K - $221.7K / year

Security Shift Supervisor

Allied Universal

Allied Universal, founded in 2016 with the merger of AlliedBarton Security Services and Universal Services of America, is now a widely-recognized industry leader and North America�

Title: Security Shift Supervisor - Unarmed Job Description: Company Overview: Allied Universal®, North America's leading security and facility services company, offers rewarding careers that provide you a sense of purpose. While working in a dynamic, welcoming, and collaborative workplace, you will be part of a team that contributes to a culture that positively impacts the communities and customers we serve. We are hiring for our refinery in Cameron! LOCATION: Cameron, LA (55 miles South of Lake Charles) POSITION: TWIC Security Shift Supervisor- Unarmed SCHEDULE: 8 days on, 6 days off SHIFTS: 12-hr shifts / PM Shift PAY: $28.00 / hour / pays weekly ALL CANDIDATES MUST HAVE SUPERVISORY EXPERIENCE. MANDATORY JOB REQUIREMENTS: - 25 years of age or older - Experience working in direct elements (position is 100% outdoors) - 5 years of experience in Security or TWIC environment - or minimum of 1 year armed security, military or law enforcement - Experience in security surveillance (a must) ADDITIONAL JOB REQUIREMENTS: - Ability to pass background and drug screen - Unexpired Drivers License and Social Security Card (no copies) - TWIC Card or Receipt - Reliable transportation (Location is remote) - Able to work 12-hour shifts - Can stand/walk for extended periods of time - Can work outdoors as site is 100% outdoors First interview will be a Live Video Interview. Allied Universal Services is currently searching for a Professional Security Shift Supervisor. The Shift Security Supervisor will supervise and coordinate the delivery of quality services on a specific shift at an assigned customer. The Security Shift Supervisor will act as a liaison between site supervisor, Account Manager/Field Operations Manager and professional security officers. Supervise staff on assigned shift, providing coaching, recognition and discipline within approved empowerment range. Qualifications/Requirements: - At least 18 years of age - Possess a high school diploma or equivalent, or 5 years verifiable experience - Must possess effective written and oral communication and interpersonal skills with ability to deal with all levels of personnel and the general public in a professional and effective manner; must be able to use initiative and independent judgment within established guidelines - Must be able to frequently prepare written reports and logs in neat, legible handwriting; - Must be able to read and understand all operating procedures and instructions - Licensing requirements are subject to state and/or local laws and regulations and may be required prior to employment. - Driving Positions: must possess a valid Driver's License with at least one year of driving experience, a clean driving record (no major violations within last 36 months, no more than 1 accident in last 24 months, no more than one minor moving violation in last 24 months), a minimum level of insurance as required by Company policy, and the ability to safely operate a vehicle required. - As a condition of employment, employee must successfully complete a background investigation and a post-offer/pre-employment drug/alcohol test, may be required to pass Drivers Record check - Intermediate computer skills to utilize innovative, wireless technology at client specific sites - Ability to handle both common and crisis situations at the client site, calmly and efficiently - Display exceptional customer service and communication skills - Ability to handle crisis situations at the client site, calmly and efficiently Allied Universal® is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race/ethnicity, age, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, disability, protected veteran status or relationship/association with a protected veteran, or any other basis or characteristic protected by law. For more information: www.aus.com(opens in new window) If you have difficulty using the online system and require an alternate method to apply or require an accommodation, please contact our local Human Resources department. . Apply Now After submitting your application, keep an eye out for an email or text with a link to start your HireVue Digital Interview. It's a quick and easy way to move your application forward, and you could even receive an offer in just a few days instead of waiting weeks!

Louisiana
$28+ / hour
Zions Bancorporation logo

Manager - Quantum Safe Cybersecurity Program

Zions Bancorporation

A financial services company headquartered in Salt Lake City, Utah, Zions Bancorporation specializes in Small Business Administration (SBA) lending, agricultura

Title: Manager - Quantum Safe Cybersecurity Program (Remote) Location: Midvale, Utah, United States Enterprise Technology Operations 069842 Job Description: Zions Bancorporation’s Enterprise Technology and Operations (ETO) team is transforming what it means to work for a financial institution. With a commitment to technology and innovation, we have been providing our community, clients and colleagues with the best experience possible for over 150 years. Help us transform our workforce of the future, today. We are seeking a seasoned cybersecurity leader to build and run our enterprise Quantum‑Safe Program. This role will own the strategy, roadmap, and delivery of post‑quantum cryptography (PQC) and quantum‑safe networking initiatives, partnering closely with Network Engineering, AppSec, Cloud Platform, and Enterprise Architecture. You will drive cryptographic modernization, govern algorithm agility, secure R&D environments, and ensure our controls, standards, and services are future‑ready for quantum threats—balancing business enablement with risk management. Key Responsibilities - Enhance and lead the implementation of a multi‑year quantum‑safe strategy covering PQC migration, algorithm agility, key management modernization, and quantum‑safe networking. - Oversee the partnership between cybersecurity and technology teams to maintain the crypto inventory (protocols, libraries, certificates, keys, HSMs, KMS, embedded/IoT) and a risk‑based prioritization for remediation. - Partner with platform and product teams to upgrade TLS/SSH/IPsec stacks, enable algorithm agility, and adopt vetted PQC libraries and configurations. - Align outcomes with industry best practices and internal cyber/tech controls, lead policy updates for crypto agility, key lifecycles, and certificate governance. - Support documentation and evidence for risk management, control validation, and accreditation efforts in partnership with GRC. - Engage with vendors and partners (HSM/KMS, PKI, networking, cloud) to evaluate quantum‑safe capabilities; run RFPs/POCs and manage deliverables. - Define and oversee a strategy for third-party PQC assurance (vendors and customers) including proof of capability, PQC readiness, and ongoing assessment and validation. - Collaborate with the Cyber Threat Intelligence team to provide regular risk assessment and analysis to management based on the evolving state of quantum computing, threats, capabilities, and risks. - Define and track program KPIs: crypto inventory coverage, PQC adoption rate, TLS posture remediation, key lifecycle compliance, lab audit pass rates, and incident reduction. Required Qualifications, Capabilities, & Skills - 8+ years in cybersecurity, network security, or secure systems engineering; 3+ years in technical leadership or program management. - Proven delivery of technical software/network projects from design through deployment, maintenance, and support. - Technical proficiency with networking protocols and architectures (TLS/SSH/IPsec, routing/segmentation, service mesh/mTLS) and one or more programming languages (Go, Rust, Java, Python). - Solid understanding of cryptography and PKI (certificates, CAs, HSMs/KMS, key lifecycles) and modern cloud security practices. - Experience collaborating with interdisciplinary R&D teams and operating across cross‑functional stakeholders. - Bachelor’s degree in Computer Science, Cybersecurity, Computer/Network Engineering, IT, or related field. Plus - Hands‑on experience implementing PQC (e.g., migration planning, algorithm agility, library selection) and/or quantum key distribution (QKD) solutions or evaluations. - Experience with cryptography‑centric libraries/applications (e.g., OpenSSL/BoringSSL, liboqs), HSM/KMS, and certificate management at enterprise scale. - Background adopting emerging tech (AI, blockchain, quantum) in regulated industries (finance, telecom, high‑tech). - Experience with cloud architecture (AWS/Azure/GCP), key management strategies, and secure deployment pipelines (Kubernetes, service mesh). - Familiarity with secure software development, digital forensics, or penetration testing and associated control frameworks. - Graduate degree in CS/CE/IT or related discipline; certifications such as CISSP, CISM, CCSP, CEH, OSCP (or equivalent) are a plus. Core Competencies - Strategic program leadership; outcome‑oriented delivery. - Deep technical fluency in crypto, PKI, and network security; ability to make pragmatic build/buy decisions. - Strong stakeholder influence and vendor management. - Excellent communication—able to convey complex concepts to varied audiences. - Bias for action in fast‑paced, shifting priorities; thoughtful risk‑taking. - Commitment to inclusive collaboration and talent development. Pay Range: $160,000 - $210,000 $ (Based upon relatable skills/experience) Work Location: This position can be located 100% remote within the United States or fully in office (5 days a week) if you are within 50 miles of the new Zions Technology Center in Midvale, UT. Benefits: - Medical, Dental and Vision Insurance - START DAY ONE! - Life and Disability Insurance, Paid Parental Leave and Adoption Assistance - Health Savings (HSA), Flexible Spending (FSA), and dependent care accounts - Paid Training, Paid Time Off (PTO) and 11 Paid Federal Holidays - 401(k) plan with company match, Profit Sharing, competitive compensation in line with work experience - Mental health benefits including coaching and therapy sessions - Tuition Reimbursement for qualifying employees - Employee Ambassador preferred banking products - Employees may, at the company’s discretion, be eligible to receive a cash bonus award

Utah
$160K - $210K / year
Cognizant logo

Network Security Engineer

Cognizant

Cognizant is an award-winning global provider of information technology and business consulting services. Founded in 1994, the company is headquartered in Teaneck, New Jersey, and

Title: Network Security Engineer CCIE Certified Location: Austin United States ID 00068539721 - Location Austin, TX - 815 Brazos St / United States - Job category IT Infrastructure - Work model Work from Office Job Description: Cognizant is seeking a Network Security Engineer for a full-time remote opportunity. About Cognizant's CIS Practice: Cognizant's CIS (Cognizant Infrastructure Services) Practice is a global leader in providing IT infrastructure services. We deliver innovative solutions to optimize and transform IT infrastructure, ensuring business agility and operational efficiency. Our services include cloud computing, data center management, network services, and cybersecurity. We focus on understanding client needs and delivering customized solutions to drive business success. In this role, you will: - Engineer and maintain site-to-site and remote access VPN solutions (IPsec, SSL/TLS, DMVPN. Troubleshoot VPN client connectivity issues across multiple platforms (Windows, macOS, mobile). - Support firewall and security policy configuration tied to VPN services. - Perform root cause analysis on tunnel failures, latency, and authentication issues. - Collaborate with internal teams on access and security architecture. Qualifications: - CCIE Security (certified, not written-only). - 5+ years of hands-on experience with enterprise VPN technologies. - Strong knowledge of IPsec, IKEv2, SSL VPN, and related protocols. - Experience troubleshooting VPN clients (AnyConnect, GlobalProtect, or equivalent) - Solid understanding of PKI, certificate-based authentication, and MFA integration. - Familiarity with firewall platforms (ASA, Palo Alto, Fortinet). - Experience in large-scale enterprise or service provider environments. - Exposure to Zero Trust / ZTNA frameworks. At Cognizant, we are eager to meet people who believe in our mission and can make an impact in various ways! We strongly encourage you to apply even if you only meet the required skills listed. Consider what transferable experience and skills make you an outstanding applicant and help us see how you would be helpful in this role. Cognizant will only consider applicants for this position who are legally authorized to work in United States without requiring employer sponsorship, now or at any time in the future. At Cognizant, we strive to provide flexibility wherever possible, and we are here to support a healthy work-life balance though our various wellbeing programs. Based on this role's business requirements, this is a remote position. The salary range for this role is between $99,000 and $116,000 will be determined by the skills and experience level of the candidate.

Texas
$99K - $116K / year