Security Manager

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 1,001-5,000H1B No SponsorCompany SiteLinkedIn

Location

Arizona + 7 moreAll locations: Arizona | Florida | New York | North Carolina | Michigan | Tennessee | Texas | Virginia

Posted

2 days ago

Salary

$120K - $130K / year

Seniority

Senior

Job Description

Security Manager

Marigold

• Lead and develop the Security Engineering team by providing technical leadership, coaching, mentorship, and performance management while fostering a culture of continuous improvement and security awareness. • Develop, implement, and maintain enterprise security strategies, policies, standards, and controls that align with business objectives and regulatory frameworks including ISO 27001, SOC 2, NIST, and GDPR. • Lead security operations, including incident response, threat detection, vulnerability management, security monitoring, root cause analysis, and continuous improvement of the organization's security posture. • Design, implement, and manage security technologies including SIEM, endpoint detection and response (EDR), firewalls, web application firewalls (WAF), identity and access management (IAM), and cloud security controls across AWS and GCP environments. • Partner cross-functionally with Engineering, Infrastructure, Product, Legal, HR, and IT teams to integrate security into system design, change management, application development, and enterprise risk management while monitoring security metrics, supporting audits, and driving ongoing compliance initiatives.

Job Requirements

  • 4+ years of dedicated cybersecurity experience with progressively increasing responsibility, including prior people leadership or team management experience.
  • Strong expertise in enterprise security operations, vulnerability management, incident response, network and system architecture, endpoint protection, and identity and access management.
  • Experience securing cloud environments, particularly AWS and/or Google Cloud Platform (GCP), and partnering with Managed Security Service Providers (MSSPs).
  • Demonstrated experience implementing security frameworks and regulatory standards such as ISO 27001, SOC 2, NIST, and GDPR.
  • Excellent communication skills with the ability to present technical security risks and recommendations to both technical and executive audiences.
  • Ability to make informed decisions under pressure and participate in an on-call incident response rotation.
  • Bachelor's degree in Computer Science, Information Security, Information Technology, or a related field, or equivalent professional experience.

Benefits

  • Competitive benefits including: medical/dental/vision insurance, life/accident/disabilities insurance, supplemental health benefits, FSA, EAP and pet insurance
  • Generous time off (we call it Open Time Away) as well as paid holidays and a birthday benefit day off.
  • Paid Volunteer Time
  • 401k plan with a company match on your contributions.
  • Employee-centric and supportive remote work environment with flexibility.
  • Support for life events including paid parental leave.

Related Categories

Related Job Pages

More Security Engineer Jobs

CVS Health logo

Senior Security Engineer – Active Directory

CVS Health

CVS Health is a leading healthcare company operating CVS Specialty, CVS Pharmacy, CVS MinuteClinic, and CVS Caremark. In 2018, CVS combined forces with healthca

• Lead the security hardening and governance of Active Directory (AD) and Microsoft Entra ID (Azure AD) environments, reducing attack surfaces and enforcing secure identity configurations • Identify, assess, and remediate identity and access management vulnerabilities, including privilege escalation risks, excessive permissions, and lateral movement attack paths • Design and implement enterprise identity security controls, including privileged access management, tiered administration, secure delegation, Conditional Access, and authentication protections • Partner with Cybersecurity, Red Team, and Infrastructure teams to validate findings, drive remediation efforts, and strengthen overall security posture • Monitor and investigate security events, threats, and indicators of compromise using tools such as Microsoft Security, Splunk, CrowdStrike, BloodHound, and Qualys • Develop and maintain security standards, conduct security assessments, and support compliance and audit initiatives (SOX, PCI, HIPAA) through remediation of identity-related findings

California
$102.0K - $203.9K / year
CVS Health logo

AVP, Application Security

CVS Health

CVS Health is a leading healthcare company operating CVS Specialty, CVS Pharmacy, CVS MinuteClinic, and CVS Caremark. In 2018, CVS combined forces with healthca

• Define and own the enterprise application security strategy, roadmap, and policy framework, aligned with CVS Health's business objectives and regulatory obligations. • Establish and enforce technical standards for secure software development, including code scanning, code vulnerability management, and secure-by-design principles. • Serve as a subject matter expert and trusted advisor to senior technology and business executives on emerging application security risks, attack trends, and industry best practices. • Drive continuous improvement across the application security program through metrics, benchmarking, and innovation. • Lead the integration of application security scanning, testing, and policy enforcement gates into CI/CD pipelines across the enterprise. • Define strategy, standards, and tooling for enterprise-wide SAST scanning. • Oversee DAST program covering pre-production and production environments. • Own the strategy, configuration, and operations of the enterprise WAF platform. • Implement and manage continuous scanning of source code repositories for secrets, misconfigurations, exposed credentials, and policy violations. • Manage the Software Composition Analysis (SCA) program to identify and remediate vulnerabilities in third-party libraries and open-source dependencies. • Oversee security configuration and policy enforcement for content delivery network infrastructure. • Own the full application security tooling portfolio. Manage vendor relationships, licensing, platform health, and roadmap alignment. • Define and maintain application security policies, standards, and operational procedures. • Ensure compliance with applicable regulatory frameworks and industry standards, including HIPAA, PCI-DSS, CCPA, NIST SSDF, and OWASP. • Build, lead, and develop a high-performing team of application security engineers, architects, and program managers. • Partner closely with Developer Experience leadership to align security tooling and practices with developer workflows, ensuring security is integrated seamlessly into agile and DevSecOps pipelines.

New York + 1 moreAll locations: New York | Rhode Island
$185.4K - $376.0K / year
Worth AI logo

Security Engineer

Worth AI

AI Data-Driven Credit Score For Every Business 💸✨

Full TimeRemoteTeam 11-50H1B No Sponsor

• Own the vulnerability scanning program across endpoints, servers, and cloud infrastructure • Triage, prioritize, and track findings through remediation, partnering with engineering and IT owners • Monitor and report on remediation SLAs; escalate aging or high-severity findings • Maintain vulnerability management documentation, metrics, and recurring reporting • Improve our identity management program through improvements in configurations, automations, to simultaneously improve security and user experience • Monitor and harden AWS environments: IAM, security groups, S3, CloudTrail, GuardDuty, Security Hub, Config • Implement and maintain security guardrails and baseline configurations across AWS accounts • Investigate and respond to cloud security alerts and incidents • Support least-privilege access reviews and cloud configuration audits • Support SAST, DAST, and dependency/SCA scanning integrated into the CI/CD pipeline • Review and triage AppSec findings with engineering teams and track remediation to closure • Participate in secure code reviews and threat modeling for new features and services • Help maintain secure development guidelines and AppSec tooling • Triage and resolve security tickets and requests within defined SLAs • Take ownership of incidents and requests through to resolution, escalating when needed • Maintain clear, accurate documentation of decisions, incidents, and remediation status • Lead or contribute to security initiatives — tooling rollouts, control implementations, audit and compliance prep • Collaborate with engineering, IT, and compliance to embed security into everyday workflows • Communicate risk, status, and trade-offs clearly to both technical and non-technical stakeholders

Florida
Full TimeRemoteTeam 10,001+Since 1931H1B Sponsor

• The Digital Product Manager (DPM) is responsible for defining, delivering, and optimizing cybersecurity products, platforms, controls, data capabilities, and AI-enabled solutions across Allstate's Cybersecurity, Controls, and Compliance (ACC) organization. • This role owns product strategy, roadmap, backlog, and outcome delivery, helping the organization improve security operations, strengthen controls, reduce enterprise risk, and enable secure-by-design technology practices. • The DPM partners with Cyber Operations, Product Security, Technology Risk, Compliance, Engineering, Architecture, and business stakeholders to build scalable, measurable, and high-impact security products that drive operational efficiency, compliance readiness, and risk reduction. • Define and execute product vision, strategy, roadmap, and success metrics. • Translate security, risk, compliance, and operational needs into scalable product capabilities. • Prioritize initiatives that improve security workflows, controls, data quality, AI enablement, automation, and platform adoption. • Align product outcomes to enterprise risk reduction and business objectives. • Translate cyber operations needs into testable hypotheses, epics, and user stories; lead discovery and framing to drive measurable outcomes. • Lead discovery, requirements gathering, and product framing efforts. • Partner with security, engineering, risk, compliance, and business stakeholders to identify opportunities and define solutions. • Own backlog management, prioritization, and Agile delivery processes. • Partner closely with engineering and architecture teams to deliver secure, scalable solutions. • Drive iterative releases and ensure alignment across cross-functional teams. • Deliver data-driven insights and executive reporting to support decision-making and prioritization.

United States
$120K - $193.7K / year