Senior Manager, Information Security

Benevity

$110K — $130K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years in information security with 5+ years in leadership roles.
  • Experience managing teams of managers and individual contributors.
  • Proficient in security operations, product and application security, and cloud security.
  • Hands-on expertise in AWS security operations and incident response management.
  • Familiar with AI and LLM security risks, including OWASP Top 10 for LLMs.
  • Working knowledge of SAST, SCA, DAST, API, and microservices security.
  • Bachelor's degree in Computer Science, Information Security, or equivalent practical experience.

Responsibilities

  • Lead and coach a multi-disciplinary security team, fostering development and growth.
  • Own and enhance critical security KPIs to improve the organization's security posture.
  • Drive the information security roadmap and oversee vendor management aligned with CISO strategy.
  • Manage end-to-end security operations and serve as escalation lead during incidents.
  • Ensure accountability of external security partners for quality and rapid response.
  • Establish AI security standards for LLMs and operationalize AI to enhance security processes.
  • Embed security into the SDLC using automated tooling and secure patterns.

Benefits

  • Opportunity to lead a multi-disciplinary team in a fast-paced environment.
  • Exposure to cutting-edge AI technologies in security practices.
  • Engagement with cross-functional teams, including GRC and DevOps.
  • Accountability for key security metrics and continuous improvement initiatives.
  • Chance to shape the organization's approach to AI-driven security solutions.
Full Job Description
Benevity is seeking a Senior Manager, Information Security to lead our security operations, product and application security, and corporate security teams. Accountable for the posture of our cloud-native platform, you will manage both leaders and senior individual contributors while maintaining the technical depth needed to critically review architectures, incident timelines, and risk ratings. In this role, you will partner closely with GRC and fraud operations to drive alignment across the organization. Additionally, you will define how Benevity secures its AI-powered product capabilities and shapes the adoption of AI tooling to accelerate our internal security practice. What you'll do: - Lead and coach a multi-disciplinary security team, driving team development, hiring, and a sustainable operating cadence. - Own critical security KPIs and ensure continuous improvement on various metrics to improve Benevity's security posture. - Drive the information security roadmap and manage security vendors, aligning execution directly with CISO strategy and direction. - Oversee end-to-end security operations and incident response, serving as the senior escalation lead during major events. - Hold external security partners (including MDR providers) accountable for high-fidelity coverage, triage quality, and rapid response. - Establish AI security standards for LLM integrations, RAG pipelines, and agentic workflows using frameworks like OWASP and MITRE ATLAS. - Operationalize AI within the security team to enhance triage, threat detection, investigation, and reporting capabilities. - Embed security into the SDLC via CI/CD automation, SAST/SCA/DAST tooling, secure API patterns, and threat modeling. - Maintain the enterprise security risk register and vulnerability management lifecycle, prioritizing remediation by real-world risk. - Direct corporate security hygiene, phishing simulations, security awareness training, and the Responsible Disclosure Program. - Partner with DevOps and GRC to implement infrastructure-as-code security, meet audit compliance obligations, and deliver clear posture metrics. What you'll bring: - 10+ years of progressive experience in information security, including 5+ years leading teams - Experience managing managers as well as individual contributors, with a track record of developing both - Breadth across security operations, product and application security, and cloud security Hands-on experience managing security operations on AWS, and other cloud providers. - Hands-on experience leading major incident response, including acting as incident commander, coordinating cross-functional responders and managing communications under pressure - Practical understanding of AI and LLM security risks, including the OWASP Top 10 for LLMs, prompt injection and the security implications of agentic systems - A clear, evidence-based point of view on where AI adds value in security work, where it falls short, and how to get it production-ready - and the curiosity to keep revising that view as the tooling changes - Working knowledge of SAST, SCA, DAST, API and microservices security, proven ability to set direction and evaluate the quality of the work - Deep understanding of cloud security, threat detection and modern attacker tactics, techniques and procedures in containerized, API-driven environments. Hands-on WAF experience is a must. - Experience owning budget, vendor selection and managed-service relationships - Experience building or scaling a security awareness program and developer security champions program. - Familiarity with security frameworks including NIST CSF, ISO 27001, SOC 2 Type II, CIS Controls, and OWASP SAMM or BSIMM - Strong problem-solving and analytical skills, with the ability to communicate security concepts effectively to both technical and non-technical audiences - A strong sense of ownership and accountability, and the ability to lead initiatives from concept to completion without being directed at every step - Bachelor's degree in Computer Science, Information Security, or equivalent practical experience Nice to have: - Relevant certifications such as CISSP, CISM or GCIH - IC-level credentials such as OSCP, CSSLP or GWAPT - Prior experience in a SaaS product company with a multi-tenant architecture - Experience in a regulated or high-trust environment where client security scrutiny is routine

Similar Jobs

More Jobs at Benevity

More Information Technology Jobs

Find similar Senior Manager, Information Security jobs: