Full Job Description
As Manager, Security Operations, you will defend our infrastructure, SaaS, and endpoints by hiring, growing, and developing a team of high-quality security engineers. You will collaborate closely with cross-functional technical teams, AppSec, and executive stakeholders to advance our AI security strategy and build robust detection controls. You will be the point person to lead incident response as senior Incident Commander, drive cybersecurity risk assessments, and maintain a seamless, hardened security posture against real-world adversaries.
In this role you will:
- Hire, grow, and develop a team of high-quality security engineers to defend our endpoints, SaaS estate, and infrastructure against real-world adversaries.
- Own the security of our corporate systems (SaaS applications and endpoints) including configuration hardening and vulnerability/patch oversight.
- Lead security operations and incident response, acting as senior Incident Commander for the Security Incident Response Team (SIRT).
- Own and tune our detection and response funnel and our CrowdStrike detection platform.
- Build and maintain detection coverage across endpoint, SaaS, and identity signals; audit/usage logs, egress-proxy traffic, DLP events, and access trails.
- Partner with other teams to build controls to contain external exposure: network allowlists, egress proxy, and proxy-level DLP.
- Partner with AppSec on detection opportunities surfaced by pentesting.
- Set quality and coverage standards for detection and response and own reporting on these metrics
- Conduct ongoing enterprise-wide cybersecurity risk assessments across infrastructure, endpoints, applications and business processes
- Own AI security as a zero-to-one build: build upon our existing detection tooling/response processes and execute our hiring plan to build the specialized team needed to keep pace with Forward's AI deployment
Why you should apply:
- Make a real difference in our security posture by driving the advancement of our AI security strategy. While this isn't a zero-to-one build from the ground up, you will have the opportunity to make a tangible impact by evolving detection and response processes to defend our critical infrastructure.
- Make a high-impact, hands-on impact: You will have the unique opportunity to lead the advancement of our AI security strategy, evolving our detection tooling and response processes to stay ahead of emerging threats, while owning and tuning our detection/response funnel to defend a critical fintech infrastructure against real-world adversaries.
- Flexibility is a top priority: Our employees are empowered to choose where they want to work (whether that's from home, in the office, or a combination of both) with flexible hours.
Role Requirements:
- 7 or more years in detection engineering, security operations, or incident response, including team leadership.
- Deep familiarity with adversary TTPs (MITRE ATT&CK), event correlation, and high-signal detection design.
- Hands-on experience with EDR/SIEM platforms and detection-as-code practices.
- Incident command experience: triage, containment, forensics, and stakeholder communication under pressure.
- Experience securing SaaS environments and endpoint fleets - configuration management, access governance, and vulnerability/patch management.
- Ability to communicate risk and priorities crisply to engineers and executives.
- Cloud control-plane monitoring and identity threat detection (AWS).
- Scripting/automation in Python, Ruby, or Go.
- Typically has a Bachelor's Degree in Computer Science or equivalent technical degree, or equivalent industry experience.
- Experience with SaaS security posture management (SSPM) or CASB tooling.
It would be nice if you also had:
- Experience with Gen-AI triage or LLM-as-Judge patterns in production.
- CISSP and/or CISM certification
- Red-team exposure - you think like an attacker.
Compensation:
Annual Salary: $172,000 - $237,000 USD
Annual Bonus: You have the potential to earn an additional 12% annual bonus.
At Forward Financing, we're committed to fair and transparent compensation. We believe in providing a compensation package that recognizes your skills, experience, and the unique value you bring to our team. We take a market-based approach to pay, regularly reviewing benchmark data to ensure our compensation remains competitive, equitable, and aligned with our performance-driven culture.
Final offers are determined by a variety of factors, including the candidate's qualifications, relevant experience, specific skills, and internal equity. This approach ensures that our compensation is competitive and equitable. Your recruiter will provide specific details on the expected base and variable earnings as it pertains to this specific role.
Total Rewards:
Additionally, we offer a comprehensive total rewards package, including but not limited to: medical, dental, vision, commuter benefits, a flexible time-off policy, paid parental leave, 401k match for US employees, wellness reimbursement, volunteering days, annual professional development budget, and charitable donation match.
Forward is proud to be a remote-first company, keeping workplace flexibility a top priority for our employees. As a business, we are focused on impact; we are more concerned with your contributions to the success of the company than where you get your work done. To help facilitate in-person collaboration, employees are welcome to work from one of our premiere office locations.
When we aren't collaborating to drive business and support our customers, we're finding virtual and in-person ways to get to know our colleagues, celebrate team wins, and have fun together!