Automox logo
Automox

All your endpoints. Always configured. Always secured. Cloud-native IT operations for modern organizations.

Senior Manager, Security & IT Operations

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 201-500Since 2015H1B SponsorCompany SiteLinkedIn

Location

Colorado + 2 moreAll locations: Colorado | Florida | Texas

Posted

13 days ago

Salary

$160K - $190K / year

Seniority

Senior

Bachelor Degree6 yrs expEnglishCloudLinuxMacOSPython

Job Description

Senior Manager, Security & IT Operations

Automox

• Lead Automox's Security and IT Operations functions. • Run both teams day to day, set and execute a 6-12 month roadmap, and report directly to the CTO. • Manage the IT and Security budget, assist with on-call, and lead incident response. • Turn security priorities into a concrete roadmap with clear milestones, owners, and metrics. • Own the GRC program, treating SOC 2 as an ongoing discipline rather than a periodic event. • Own the ProdSec program, partnering with Engineering and Product to embed security into the development lifecycle. • Lead incident response: runbooks, escalation paths, and post-incident reviews that improve response over time. • Set and execute the strategy for endpoints, identity, and SaaS at scale. • Oversee MDM, patch compliance via Automox, hardware lifecycle, and zero-touch provisioning across macOS and Windows. • Administer core SaaS across collaboration, source control, secrets management, and cloud, including ongoing license rationalization. • Automate repetitive work with AI coding tools and keep it documented, measured, and maintained. • Track KPIs across ticket responsiveness, patch and MDM coverage, access reviews, and IT spend, using them to drive improvement. • Develop engineers and helpdesk staff, with clear career paths and succession depth. • Build a culture of clarity, ownership, and psychological safety across both teams.

Job Requirements

  • 6+ years in security engineering or security operations, including hands-on IT operations responsibility (or a combined security and IT role).
  • 3+ years managing people.
  • A track record of turning strategy into execution with measurable outcomes.
  • SOC 2 experience and hands-on incident management.
  • A modern identity provider (IdP), MDM for macOS and Windows, collaboration suite administration, source control administration, and cloud IAM.
  • Working Linux experience.
  • Uses AI coding tools effectively to produce and accelerate automation. Reads that output well enough to review it for correctness and security, guide its design, and sign off on what ships, with working familiarity in PowerShell, bash, and Python.
  • Sound judgment on architectural and tooling trade-offs.
  • Balances longer-horizon planning with daily operational demands across two functions.
  • Clear and credible in technical and leadership conversations, action-oriented on risk.
  • Handles difficult conversations (performance, misalignment, competing priorities) directly.
  • A culture builder who is data-driven and energized by leaving things better than they were.

Benefits

  • Competitive Salary
  • Equity for Full-Time Employees
  • 401K Match
  • Flexible PTO, generous sick time policy
  • Comprehensive Health Plans with generous employer contributions
  • 100% Company-paid Short Term/Long Term Disability and Life Insurance
  • Company HSA Contribution: $100-$200 per month based on tier
  • $25 per month Lifestyle Spending Account
  • Internet Reimbursement - $50/month
  • $500 Home office stipend
  • $10k Adoption Benefit
  • Comprehensive Family Planning Covered on Meritian Medical Plan

Related Categories

Related Job Pages

More Security Engineer Jobs

BeyondTrust logo

Technical Program Manager, Product Security

BeyondTrust

Protect identities, stop threats, and deliver dynamic access to empower and secure a work-from-anywhere world.

Full TimeRemoteTeam 1,001-5,000Since 1985H1B Sponsor

• Own the end-to-end remediation process from validated finding through fix verification. Define and enforce SLAs by severity, track progress across engineering teams, escalate aging findings, and drive blockers to resolution. • Organize third-party penetration tests: scoping, scheduling, vendor coordination, finding intake, and tracking through remediation. Own the operational side of the bug bounty program, ensuring researcher submissions are acknowledged, triaged, validated, and resolved within committed timelines. • Build and maintain security kanban boards that give the entire organization visibility into vulnerability status: internal findings, pen test results, bug bounty submissions, and security exceptions. These boards are the single source of truth. Engineering knows what's on their plate, security leadership knows the posture, and Customer Trust has what they need for customer conversations. • Use Claude and LLM platforms to automate finding intake and routing, generate status reports, flag at-risk SLAs, draft stakeholder communications, and surface patterns that indicate systemic issues. Focus your time on judgment and coordination by letting AI handle the repetitive tracking. • Own the security exception process: intake, risk documentation, approval routing, time-bound tracking, and expiration enforcement. When an engineering team requests an exception, you ensure it's documented with clear risk context, reviewed by the right people, and actively tracked to expiration. • Own Product Security metrics: mean time to remediate, SLA compliance, finding aging, exception counts, recurrence rates, coverage by product. Build reporting that serves the VP (portfolio posture), engineering leaders (their team's queue), and Customer Trust (defensible data for customer security reviews). • Coordinate with Engineering and Product Management on remediation prioritization and release planning. Work with Customer Support and Customer Trust on vulnerability status for customer inquiries and security questionnaires. Partner with Cyber Defense on findings that cross product and infrastructure boundaries. Keep Security Architects and Product Security Engineers aligned on remediation status.

Canada
Level Access logo

Security Engineer

Level Access

A leading provider of digital accessibility solutions, Level Access endeavors to create a world in which individuals with disabilities can readily access digital systems. Founded b

• Performing initial triage of disparate security signals and events to determine severity and drive response to potential business-impacting incidents. • Monitoring and analyzing vulnerability management tools and feeds; providing remediation guidance to downstream teams; and keeping technical risk under control. • Operating the security awareness program, including course design, phishing simulations, reporting, and support for business teams and users. • Supporting internal and external stakeholders as required to gather information and evidence for security governance activities and compliance audits. • Using AI and automation techniques to enhance compliance, facilitate business operations, and improve efficiency. • Undertaking small projects to mitigate risk, support the team, and support other company objectives.

Ukraine
BeyondTrust logo

Product Security Architect

BeyondTrust

Protect identities, stop threats, and deliver dynamic access to empower and secure a work-from-anywhere world.

Full TimeRemoteTeam 1,001-5,000Since 1985H1B Sponsor

• Lead threat modeling, attack surface analysis, and secure design reviews across products, platform services, endpoint agents, and cloud-native systems. • Use LLM platforms (Claude, OpenAI) as core tools to scale threat analysis, abuse-case generation, architecture review, and remediation guidance. • Work directly with engineering teams to embed secure-by-default patterns into product development. • Own and expand the Product Security handbook that inferences product context from multiple sources and leverage it for enforcing secure design standards. • Mentor Product Security Engineers and Security Champions on secure design, attack surface reduction, and AI-first security workflows. • Help evolve BeyondTrust's AI-first Product Security Architecture strategy by identifying where AI workflows can replace manual processes.

United States
BeyondTrust logo

Senior Product Security Engineer

BeyondTrust

Protect identities, stop threats, and deliver dynamic access to empower and secure a work-from-anywhere world.

Full TimeRemoteTeam 1,001-5,000Since 1985H1B Sponsor

• Build and maintain the product security tooling pipeline integrated across the software development lifecycle. Implement and tune Claude Code Security, Codex Security, GitHub Advanced Security (code scanning, secret scanning, Dependabot), and Wiz CLI across repositories and CI/CD pipelines. Own the configuration, policy enforcement, and continuous improvement of these tools so engineering teams get accurate, actionable security feedback at the speed of development. • Design and operate automated product security review workflows with human-in-the-loop checkpoints. Use Claude and LLM platforms to automate initial review triage, risk classification, and recommendation generation, escalating to Security Architects or senior engineers for decisions that require judgment. The goal is every change gets appropriate security review coverage without manual review becoming the bottleneck. • Ensure security tooling integrates cleanly into engineering workflows: GitHub PRs, CI/CD pipelines, IDE plugins, and developer dashboards. Reduce false positives, tune rulesets to the product's actual risk profile, and build feedback loops so findings improve over time. You own the engineering experience of security tooling. When a developer interacts with a security gate, it should be clear, fast, and useful. • Leverage Claude Code Security, Codex Security, and LLM platforms to build automation that scales security engineering. This includes automated code review triage, vulnerability pattern detection, fix suggestion generation, policy-as-code enforcement, and security review summarization. Contribute reusable prompts, skills, and plugins back to the Product Security team's shared library. • Support product incident response alongside the Product Security team. Help investigate security incidents affecting products, scope impact, coordinate with engineering on emergency fixes, and contribute to root cause analysis and post-incident improvements. • Work closely with Security Testers to ensure scanning and automated tooling feed validated findings into their workflow. Partner with Architects on translating secure design standards into enforceable pipeline policies. Coordinate with the TPM on tracking and reporting for tooling-generated findings. Be the go-to person for engineering teams on security tooling questions, configuration, and troubleshooting.

United States