About this Role
The Senior Manager, Security Engineering leads the team that designs, builds, and runs Quanta's security technology. This is a hands-on engineering leadership role. You will own the security platform stack and its integrations, drive the security engineering side of mergers and acquisitions, and set the technical direction your team builds against.
Quanta is large and decentralized, with hundreds of operating companies and tens of thousands of endpoints across corporate and field locations. The role suits an engineer who can standardize, automate, and integrate security across many autonomous business units rather than one uniform estate.
You will lead a small team of security engineers and are expected to understand the major areas of security, including endpoint, network, identity, cloud, vulnerability management, and penetration testing. You will own the ones this role is accountable for, and guide the team and partner with the functions that own the rest. This is an engineering role focused on building and hardening security capability, not a monitoring or on-call operations role.
The role calls for strong hands-on engineering depth alongside the leadership skills to run a team and the communication skills to explain technical risk to executives.
What You'll Do
Security Platform Engineering•Own the security platform stack end to end. For each platform, design, deploy, configure, tune, upgrade, integrate, and eventually retire it, and keep ownership and documentation current. The stack covers endpoint protection, the SIEM and security data pipeline, security automation, email security, secure web and private access, PAM, and EPM.•Build and maintain the integrations that connect security platforms to one another and to enterprise systems, including API and connector development.•Engineer and enforce cloud security controls on the approved cloud platforms, including guardrails, workload identity, logging, encryption, and prevention of public exposure.•Continuously verify that deployed controls work as designed, and fix what does not.•Lead platform consolidation and migration programs, from selection and parallel run through cutover and decommissioning of legacy tooling.
Mergers, Acquisitions, and Integration•Lead the security engineering side of mergers and acquisitions, starting with pre-close technical due diligence of a target's identity, endpoint, network, and cloud posture.• Plan and run post-close integration: onboard acquired environments onto enterprise security tooling and telemetry, consolidate tenants and domains, and sequence remediation of inherited exposure.•Support divestitures and carve-outs, including data segregation, access removal, and telemetry separation.•Standardize security controls across newly acquired and existing operating companies, working with local IT leaders in a decentralized model.
Technical Leadership and Breadth•Lead, mentor, and develop a small team of security engineers, and own hiring, performance management, and career growth.•Provide senior technical guidance across the adjacent domains the team works in, including identity security, vulnerability management, and penetration testing, partnering with the functions that own them.•Build and harden controls to the security architecture and standards set by the Security Architect, and provide engineering and feasibility input to design reviews and threat assessments.•Stay current on emerging technology relevant to the environment, including AI security, and guide how the team adopts and secures it.•Remove single points of knowledge through documentation, cross-training, and clear platform ownership.
Vendors and Budget•Lead technical evaluation and selection of security platforms, and own the resulting vendor and provider relationships, including scope and service levels.•Negotiate statements of work and licensing, and own the security engineering budget and forecast, including license planning and cost optimization.•Establish regular cadence to report engineering metrics to leadership, including platform and control coverage, platform health, and open engineering risk.•Adheres to internal standards, policies and procedures.•Performs other duties as assigned.
What You'll Bring
Required Education and Experience•Bachelor's degree in Computer Science, Cybersecurity, Information Technology, or a related field; or an equivalent combination of education and professional experience.•8+ years in IT and cybersecurity, including at least 5 years hands-on in security engineering or security architecture.•3+ years leading technical teams, including hiring and performance management.•Demonstrated end-to-end ownership of enterprise security platforms at significant scale (tens of thousands of endpoints or equivalent complexity), including design, deployment, integration, tuning, and migration.•Hands-on depth with endpoint protection and enterprise SIEM platforms, including building integrations and managing the security data pipeline.•Experience engineering cloud security controls on a major cloud platform (e.g., Microsoft Azure or AWS).•Experience leading the security engineering side of mergers, acquisitions, or large-scale environment integrations.•Broad understanding across the major areas of security, including endpoint, network, identity, cloud, vulnerability management, and penetration testing, with the depth to guide a team and partner with the functions that own the areas this role does not.•Ability to communicate credibly with engineers and executives, and to translate technical risk into business decisions.
Preferred Education and Experience•Master's degree in Cybersecurity, Computer Science, Information Systems, or an MBA.•Experience in construction, utilities, energy, telecommunications, or another large, decentralized industry.•Hands-on experience with privileged access management and with secure web or private access platforms.•Scripting and API proficiency (e.g., Python, PowerShell, Microsoft Graph) for automation and integration.•Developing experience with different AI platforms.•Experience integrating many autonomous business units onto common security tooling.
LICENSES / CERTIFICATIONS:Required Licenses/Certifications•Certified Information Systems Security Professional (CISSP)Preferred Licenses/Certifications•One or more of the following certifications○Certified Information Security Manager (CISM)○Microsoft Certified: Cybersecurity Architect Expert (SC-100) or Certified Cloud Security Professional (CCSP)○AWS Certified Security Specialty○GIAC Defensible Security Architecture (GDSA) or GIAC Certified Enterprise Defender (GCED)
SUPERVISORY RESPONSIBILITIES:Supervises others: YesHas hiring and terminating responsibilities: YesNumber of employees report to this job: 0 Subordinate Supervisory Employees, 3 to 6 Non-Supervisory Employees
TRAVEL REQUIREMENTS:Travels: YesPercent of time: 15%Overnight required: OccasionallyLocation: Hybrid