Job Closed
This listing is no longer active.
Manager, Security Engineering
Location
Arizona + 27 moreAll locations: Arizona | California | Colorado | Connecticut | Florida | Hawaii | Illinois | New Hampshire | New Jersey | New York | North Carolina | North Dakota | Ohio | Oregon | Maryland | Massachusetts | Michigan | Minnesota | Missouri | Pennsylvania | Rhode Island | South Carolina | Texas | Utah | Vermont | Virginia | Washington | Wisconsin
Posted
99 days ago
Salary
$173.7K - $210.7K / year
Seniority
Senior
Job Description
Manager, Security Engineering
ActBlue
• Team Leadership & Development: Mentoring, and growing security engineers. This includes running 1:1s, career development planning, performance reviews, and building a culture of continuous learning around evolving threats and technologies. • Security Execution: Partnering with engineers on your team and the Sr. Director of Security and Integrity you’ll define and prioritize the team's quarterly and annual security initiatives, aligning them with business objectives and frameworks like NIST CSF, CIS Controls, or SOC 2. Translating risk assessments into actionable engineering work. • Cross-Functional Collaboration: Partnering with Platform, SRE, Legal, IT, Compliance, and Product teams to embed security into the SDLC, incident response processes, and vendor management workflows. • Incident Response & Preparedness: You’ll help the team to maintain the Security incident response program: runbooks, running tabletop exercises, on call schedules, and ensuring timely response to alerts and events. • Product and Cloud Security: Drive product security practices and cloud security posture across our AWS infrastructure, ensuring secure architecture, configuration, and continuous monitoring of our production environments. • Vulnerability & Risk Management: Overseeing application security testing (SAST, DAST, SCA), penetration testing programs (including bug bounty), and ensuring vulnerabilities are triaged, prioritized, and remediated within SLA. • Corporate Security: Partnering with IT, you and the team will help ensure strong protections in corporate security including spam, EDR, and device security is mature and well executed. • Vendor & Third-Party Risk: Helping the team evaluating security vendors, and overseeing third-party risk assessments. • Budget & Resource Planning: In coordination with the other department managers; manage the security budget, justifying tooling spend, headcount requests.
Job Requirements
- 5–7 years managing a team of security engineers or similarly technical ICs. Demonstrated experience with hiring pipelines, structured interview loops, performance calibration, performance, and career laddering.
- Comfortable running daily standups and weekly 1:1s as core rituals, not afterthoughts.
- Familiar with translating frameworks like NIST CSF or CIS Controls into quarterly OKRs and sprint-level work.
- Hands-on experience building or maturing a security program at a mid-size or growth-stage organization.
- Experience overseeing AppSec tooling (SAST, DAST, SCA, Container Scanning, Secrets) and programs like penetration testing or bug bounty.
- A background working with or managing engineers who build and tune detections in a SIEM, manage alert pipelines, and reduce noise.
- Experience running an AI forward team of engineers. You’ll know how to find quick solutions to problems and you’ll help the team to similarly seek out speed and quality of execution via AI related tooling.
- A track record of working across engineering, SRE, platform, IT, and legal orgs.
- You have deep familiarity with cloud security (AWS), Application Security (particularly web native apps and authentication), endpoint security (EDR), email security (anti-spam/phishing), and device management.
- Experience evaluating security vendors, running third-party risk assessments.
- You have defined and reported on security KPIs like MTTD, MTTR, vulnerability aging, and coverage metrics.
- Demonstrated domain expertise in one or more core security domains and secondary specializations, (e.g. infrastructure security, application security, corporate IT security, security operations)
Benefits
- Flexible work schedules and an unlimited time-off policy
- Fully paid and trans-inclusive health, dental, and vision insurance for employees and their families; plus fully-paid health reimbursement arrangement to use for out of pocket expenses and fully-paid short- and long-term disability
- Fully paid basic and AD&D life insurance and a voluntary supplemental life insurance option
- Dependent and health care flexible spending account options
- Employee Assistance Program (EAP) benefits for employees
- Automatic 2% Employer-paid 401K contribution, plus up to an additional 6% match on employee contributions
- A minimum of three months paid medical, family and parental leave (for all new parents, adoptions included)
- Commuter or home-office benefits, including a $1,000 home-office setup allowance for all new full-time remote employees
- Additional perks including quarterly snack deliveries and digital subscriptions to the Boston Globe & New York Times
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Develop and implement threat modeling to identify security risks across applications and infrastructure. • Conduct vulnerability scanning, penetration testing, and security assessments to detect weaknesses. • Define and enforce secure coding practices in collaboration with development teams. • Work with DevOps to integrate security into CI/CD pipelines and automate security testing. • Monitor and respond to security incidents, conducting root cause analysis and implementing preventative measures. • Ensure compliance with security standards and regulations (e.g., ISO 27001, GDPR, SOC 2). • Design and implement identity and access management (IAM) policies, encryption standards, and authentication mechanisms. • Collaborate with product teams to conduct security reviews of features, APIs, and third-party integrations. • Develop incident response plans, security documentation, and best practices. • Stay ahead of emerging threats, vulnerabilities, and security technologies.
• Develop and implement threat modeling to identify security risks across applications and infrastructure. • Conduct vulnerability scanning, penetration testing, and security assessments to detect weaknesses. • Define and enforce secure coding practices in collaboration with development teams. • Work with DevOps to integrate security into CI/CD pipelines and automate security testing. • Monitor and respond to security incidents, conducting root cause analysis and implementing preventative measures. • Ensure compliance with security standards and regulations (e.g., ISO 27001, GDPR, SOC 2). • Design and implement identity and access management (IAM) policies, encryption standards, and authentication mechanisms. • Collaborate with product teams to conduct security reviews of features, APIs, and third-party integrations. • Develop incident response plans, security documentation, and best practices. • Stay ahead of emerging threats, vulnerabilities, and security technologies.
Role Description Be the spark that brightens days and ignite your career with TTEC’s award-winning employment experience. As an Application Security Engineer working remotely in Mexico City, you’ll be a part of creating and delivering amazing customer experiences while you also #experienceTTEC, an award-winning employment experience and company culture. Looking to use your expertise to protect and strengthen mission-critical systems and applications? In this role, you’ll lead efforts to secure new and existing applications by assessing risks, developing mitigation strategies, and embedding security best practices throughout the SDLC. - Lead security assessments and code reviews across web, mobile, cloud, and on-prem applications - Guide development teams on secure coding practices and implement effective security controls - Evaluate threats, conduct risk assessments, and define mitigation strategies - Maintain documentation on architecture, incident response, and security procedures - Stay current on emerging threats and support incident response efforts when needed You’ll report to the Executive Director of Information Security and contribute to safeguarding our clients and enterprise data. During a Typical Day, You’ll: - Conduct vulnerability scans, penetration testing, and manage remediation processes. - Use tools like SAST, DAST, and IAST to continuously monitor application security - Collaborate with DevOps to embed security in CI/CD pipelines - Deliver security training to developers and internal teams - Participate in cloud security reviews (AWS, Azure, GCP) and recommend improvements - Provide guidance on automation opportunities using Python, Java, or C# - Serve as a security advisor across global business units and support planning of key security initiatives - Clearly communicate findings to both technical and non-technical stakeholders across cultures Qualifications - Bachelor's degree in Computer Science, Information Security, or related field - 3+ years of experience in application security (cloud and on-premise) - Experience with penetration testing, risk assessments, and vulnerability management - Solid understanding of OWASP Top 10 and mitigation strategies - Proficiency in scripting or programming (Python, Java, or C#) - Familiarity with security testing tools and cloud platforms (AWS, Azure, GCP) - Excellent communication skills with global and cross-functional collaboration experience - Certifications such as CISSP, CSSLP, or CEH are a plus Benefits - Supportive of your career and professional development - An inclusive culture and community minded organization where giving back is encouraged - A global team of curious lifelong learners guided by our company values - Ask us about our paid time off (PTO) and wellness and healthcare benefits - A great compensation package and performance bonus opportunities, benefits you'd expect and maybe a few that would pleasantly surprise you (like tuition reimbursement) Company Description Our business is about making customers happy. That's all we do. Since 1982, we've helped companies build engaged, pleased, profitable customer experiences powered by our combination of humanity and technology. On behalf of many of the world's leading iconic and hypergrowth brands, we talk, message, text, and video chat with millions of customers every day. These exceptional customer experiences start with you. TTEC is proud to be an equal opportunity employer where all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. TTEC embraces and is committed to building a diverse and inclusive workforce that respects and empowers the cultures and perspectives within our global teams. We aim to reflect the communities we serve, by not only delivering amazing service and technology, but also humanity. We make it a point to make sure all our employees feel valued, belonging, and comfortable being their authentic selves at work. As a global company, we know diversity is our strength because it enables us to view things from different vantage points and for you to bring value to the table in your own unique way.
Head of Security
Reach FinancialReach Financial is a financial services company dedicated to assisting individuals in effectively managing and overcoming debt through customizable personal loa
Role Description We’re looking for a Head of Security to own and lead information security at Reach. This is a hands-on leadership role: you will set the strategy, own the program end-to-end, and stay actively in the work alongside your team. In a given week you might be writing a policy, triaging a pen test finding, running a phishing campaign, responding to a customer security questionnaire, and presenting the quarterly security update to leadership. The right person is energized by owning an entire domain end-to-end, is comfortable moving between strategy and execution, and is equally credible with a senior engineer and a SOC 2 auditor. You believe security is most effective when it is practical, measurable, and built into how the business operates. Key Responsibilities - Vulnerability management and offensive testing: Own the vuln lifecycle end-to-end — intake, triage, prioritization, risk acceptance, ticketing to dev teams, and remediation within SLA — and manage external pen tests and targeted assessments. Report regularly on status, SLA performance, and trends. - Security operations and incident response: Manage our MSSP partner for 24/7 SIEM and SOC monitoring; ensure telemetry, detections, and playbooks match our threat model. Serve as incident commander for real events, and run regular tabletops and post-incident reviews. - Policy, controls, and risk: Define and maintain Reach’s security policies and control framework. Design, implement, and measure the effectiveness of controls; maintain a risk register; and surface material risk decisions to leadership. - Compliance and audits: Own SOC 2 Type II and PCI DSS end-to-end with continuous control monitoring and evidence collection between audits. Serve as the primary contact for external auditors. - Application and cloud security: Partner with engineering on secure SDLC, threat modeling for new products and features, SAST/DAST/SCA coverage, and cloud security posture (IAM, configuration, workload protection). - Identity and access management: Own IAM policy, periodic access reviews, privileged access, and joiner/mover/leaver processes, in partnership with IT and People. - Third-party and customer security: Run Reach’s vendor risk program (due diligence, questionnaires, DPAs, ongoing monitoring) and own responses to customer and prospect security reviews. - Security awareness and training: Run phishing simulations, ongoing and role-targeted training, and regular company-wide sessions on new threats and best practices. - Executive reporting: Provide regular security posture updates with meaningful metrics (MTTD/MTTR, patch latency, control coverage, phishing outcomes, audit readiness). - People, budget, and tooling: Act as a mentor for your report; own the security budget and tool stack — evaluating, procuring, rationalizing, and retiring tools as the program matures. Qualifications - 8+ years in information security, with 3+ years leading a security program or a major security function. - Direct experience owning SOC 2 Type II audits end-to-end; PCI DSS experience strongly preferred. - Proven, hands-on ownership of vulnerability management programs at scale. - Experience managing an MSSP/MDR relationship for SIEM and 24/7 SOC. - Strong application and cloud security fundamentals, with hands-on experience in AWS, GCP, or Azure, and the ability to partner credibly with engineering. - Experience leading incident response end-to-end, including cross-functional coordination and working with external parties. - Experience writing and operationalizing security policies against recognized frameworks (NIST CSF, ISO 27001, CIS Controls). - Excellent written and verbal communication — credible with engineers, executives, auditors, and customers. - Comfortable as a player-coach in a lean environment, with a strong sense of ownership and bias for action. Additional Assets - Experience in fintech, payments, or ecommerce — ideally cross-border or merchant-of-record. - Prior experience standing up or scaling a security program at a growth-stage company. - Familiarity with GRC/continuous compliance platforms (e.g., Vanta, Drata, Secureframe). - AWS experience (our primary cloud) and Atlassian suite (Jira, Confluence) for workflow and documentation. - Formal people-management experience. - Relevant certifications (e.g., CISSP, CISM, CCSP). Benefits - Competitive compensation - Flexible remote work - Comprehensive benefits - Opportunity to build and own a security function - Direct impact on a global commerce platform Our Core Values - We value solving problems and building products by focusing on outcomes - We value making decisions while considering input from multiple sources - We value taking action over getting stuck in planning - We value taking chances and failing fast - We value teamwork over individual accomplishments - We value optimizing time to value and achieving outcomes, not checking boxes - We value work/life balance and a mindset of “it’s a marathon, not a sprint” - We value using the right technology to solve the right problems Apply with your CV and a brief cover letter outlining your security leadership experience and your interest in joining Reach. #LI-Remote


