OverviewThe Senior Information Security Engineering Manager is a strategic leadership role responsible for protecting the organization's critical data, applications, identities, and emerging technology platforms. This position leads security initiatives across data and application security, identity and access management, and AI security, ensuring effective controls are in place to reduce risk and strengthen the organization's overall security posture.
The ideal candidate combines strong technical expertise with leadership and collaboration skills, partnering across IT and cybersecurity teams to advance security capabilities, enhance privileged access controls, support secure development practices, and address risks associated with emerging technologies.
What You'll DoData & Application Security- Establish and maintain technical controls that protect data and applications across on-premises, cloud, and remote-access environments
- Align data protection and application security policies with corporate governance and risk management requirements
- Evaluate and implement controls that reduce risk from insider threats and data breaches, in coordination with security leadership and stakeholders
- Conduct data and application discovery to identify at-risk data and validate storage integrity
- Test and maintain business rules governing data use, handling, and access
- Recommend improvements that enforce least privilege and strengthen application security without degrading user experience
- Analyze systems and data sources for accidental, malicious, or unauthorized activity
Secure Coding & Application Security Testing- Maintain and administer the organization's Secure Coding Standard, including periodic review and updates
- Administer SAST, DAST, and SCA tooling, and track code-level vulnerability remediation against defined SLAs
- Conduct security reviews of high-risk or security-critical code and application components
- Make scoping determinations on whether development and automation initiatives fall within SDLC and Secure Coding Standard governance
- Lead secure coding gap assessments across development teams and evaluate tooling strategy to close systemic gaps
- Provide secure coding training and tooling to development teams
- Report on secure coding risk posture and remediation timelines to leadership
Identity & Access Management (IAM) Security- Administer and maintain PAM platforms, including vaulting, privileged session management, and access policy configuration
- Configure and manage privileged account controls, entitlements, and workflows within PAM tooling
- Monitor privileged session activity and investigate anomalous or unauthorized privileged access
- Drive improvements to the organization's identity and access security posture, including authentication controls, access governance, and identity risk reduction
- Develop and maintain a roadmap for maturing IAM and PAM security controls in line with risk and regulatory requirements
- Conduct periodic reviews of privileged and elevated access to confirm alignment with least-privilege and policy requirements
- Partner with identity operations and IT teams that perform standard account provisioning and deprovisioning to ensure privileged accounts are onboarded and offboarded accurately in PAM tooling
- Maintain and enforce IAM- and PAM-related policies, standards, and exception processes
- Provide audit and examiner support for identity and privileged access controls
Emerging Technology Security- Support evaluation of security risks associated with AI/GenAI and other emerging technologies, including model access and data exposure
- Partner with GRC to maintain risk register entries for AI-related and other emerging technology threats
- Help evaluate security tooling and controls as new technology-driven asset categories are introduced
General- Serve on a distributed security team responsible for maintaining technical controls across the above areas
- Maintain understanding of business processes to support enterprise data protection, access, and technology risk management
- Engage with business units to understand their risk posture and tolerance, and support their objectives securely
- Manage security projects from inception to completion, on time and within budget
- Build working relationships with engineering, IT, incident response, SOC, and software engineering teams
- Support the organization and leadership team, including during periods of change
Requirements For SuccessEducation: Bachelor's degree preferred in information assurance, computer science, engineering, or a related technical field.
Experience: 5-8+ years of cybersecurity or information technology experience
Required Skills:- Hands-on experience administering privileged access management (PAM) platforms (e.g., vaulting, session management, policy configuration)
- Experience advancing identity and access management (IAM) security programs, such as authentication controls, access governance, or identity risk reduction
- Familiarity with administering or overseeing directory services, databases, role-based access, DLP, data classification, and governance solutions
- Experience with secure coding principles and standards (e.g., OWASP Top 10) and application security testing tools (SAST, DAST, SCA)
- 2+ years of experience with data protection management solutions; endpoint, network, or application security experience preferred
- Experience with one or more of: CRI, CIS18, NIST Cybersecurity Framework (CSF) preferred
- Strong written and verbal communication skills across all levels of the organization
- Understanding of data protection, application security, and access control principles and frameworks
- Ability to prioritize and complete tasks within defined SLAs
- Sound judgment and the ability to make timely decisions in complex situations
- High degree of integrity, trustworthiness, and professionalism
Preferred Skills:- 5-8+ years of security systems administration experience, including 2+ years of hands-on data protection or PAM practitioner experience
- One or more of: CISSP, CIPP, CISA, CRISC, CDPSE, GSEC
- Experience developing or contributing to an IAM/PAM security roadmap or maturity program
- Experience leading secure coding gap assessments or maturity initiatives across development teams
- Familiarity with AI security posture management (AISPM) platforms or other emerging-technology risk evaluation tools
- Familiarity with regulatory requirements such as PCI, FFIEC, SOX, HIPAA, GDPR, CCPA, and GLBA
Conditions of EmploymentThis position manages employees and is responsible for the coaching, development, and performance management of those employees.
Schedule flexibility is required to work evenings and weekends as needed.
This position requires up to 10% travel.
Pay RangeUSD $84,136.00 - USD $139,486.00 /Yr.