Full Job Description
We're looking for a Security Engineering Manager to lead our Production Security team at Snap Inc!
As the leader of the team, you will own the security of the infrastructure that runs Snapchat. Your team hardens Snap's production environment across AWS and Google Cloud, builds the perimeter, workload identity, and deployment controls that thousands of services depend on, and makes the secure path the easiest path for Snap developers. This is a builder's role as much as a leadership one. You will set technical direction for a portfolio of security services used company-wide, and you will be accountable for both their engineering quality and their day-to-day operation.
What you'll do:
- Set and drive a multi-year technical strategy for securing Snap's production infrastructure across network perimeter, cloud organization hardening, machine credentials and workload identity, and CI/CD.
- Translate production risk into a prioritized roadmap, making judicious tradeoffs between near-term asks, long-term security outcomes, team productivity, and system health.
- Ensure the platforms your team builds and operates, from perimeter and cloud configuration enforcement to service identity and secrets management, consistently demonstrate high technical quality, reliability, and operational excellence.
- Balance a substantial operational load against planned initiatives, owning service reliability, on-call health, and the customer support model for a portfolio of production security services and developer-facing libraries, and participate directly in incident response for production environments.
- Drive identification, triage, and remediation of vulnerabilities and misconfigurations across cloud environments and backend systems, holding clear ownership and timelines rather than accumulating open findings.
- Oversee security reviews of platforms, backend services, and business application integrations, and set a review model that produces measurable risk reduction while unblocking engineering teams. This includes managing exception handling and formal risk acceptance when a control cannot be met.
- Partner closely with Infrastructure, Developer Productivity, and Product Engineering to embed security controls inside Snap's service abstractions so that teams inherit security by default instead of adopting it by exception.
- Influence the secure and responsible adoption of LLMs, AI tooling, and agentic workloads across Snap's engineering ecosystem, with a focus on identity, access boundaries, and data protection.
- Partner with Detection and Response, Offensive Security, and infrastructure teams during incidents and red team engagements to drive containment and durable fixes rather than one-off patches.
- Align your team's direction with the strategic goals of the organization, and participate in quarterly and annual planning so investment lands on the highest impact risks.
- Recruit high caliber engineers and build an engaging, collaborative, and productive team that positively influences the security culture of the broader organization.
- Invest in your team members' career growth, use effective performance management tools, and build mechanisms that delegate execution while holding a high bar.
Knowledge, Skills & Abilities:
- Proven experience in one or more production and infrastructure security areas: cloud security architecture, network perimeter and zero-trust design, workload identity and secrets management, container and Kubernetes security, or CI/CD and software supply chain security.
- Deep understanding of one or more infrastructure domains: Kubernetes, containers, service mesh technologies such as Istio or Envoy, networking, or Linux internals.
- Hands-on experience deploying and securing services in multi-cloud environments, particularly AWS and Google Cloud Platform.
- Working knowledge of authentication and authorization protocols and frameworks, including OpenID Connect, OAuth, mTLS, and identity federation.
- Development skills in Go, Python, and/or Java, enough to review designs, assess technical quality, and stay credible with your engineers.
- Ability to apply defense in depth and zero-trust principles to a large, heterogeneous production environment, and to sequence controls so that adoption succeeds at scale.
- Strong verbal and written communication skills, and the ability to influence senior engineering leaders without direct authority.
Minimum Qualifications:
- Bachelor of Science in Computer Science, Engineering, Information Systems, or equivalent years of experience in a related technical field.
- 8+ years of post-bachelor's industry experience; or a Master's degree in a technical field + 7+ years of post-grad security experience; or a PhD in a related technical field + 4+ years of post-grad security experience.
- 1+ year(s) of experience as an Engineering Manager.
Preferred Qualifications:
- Experience leading teams that both build and operate platform services at scale, including accountability for SLAs, on-call, and migration of large internal customer bases.
- Track record driving company-wide adoption of a security control or platform, including the partner management and change management required to get there.
- Familiarity with cloud security posture management platforms and native AWS and GCP security services.
"Default Together" Policy at Snap: At Snap Inc. we believe that being together in person helps us build our culture faster, reinforce our values, and serve our community, customers and partners better through dynamic collaboration. To reflect this, we practice a "default together" approach and expect our team members to work in an office 4+ days per week.
Our Benefits: Snap Inc. is its own community, so we've got your back! We do our best to make sure you and your loved ones have everything you need to be happy and healthy, on your own terms. Our benefits are built around your needs and include paid parental leave, comprehensive medical coverage, emotional and mental health support programs, and compensation packages that let you share in Snap's long-term success!
Compensation
In the United States, work locations are assigned a pay zone which determines the salary range for the position. The successful candidate's starting pay will be determined based on job-related skills, experience, qualifications, work location, and market conditions. The starting pay may be negotiable within the salary range for the position.These pay zones may be modified in the future.
Zone A (CA, WA, NYC):
The base salary range for this position is $251,000-$377,000 annually.
Zone B:
The base salary range for this position is $238,000-$358,000 annually.
Zone C:
The base salary range for this position is $213,000-$320,000 annually.
This position is eligible for equity in the form of RSUs.
If you believe this job description is missing required pay transparency information, please submit a report through this form:Job Description Pay Range Disclosure