A day in the life of a Senior Manager, Product Security & Security Operations at CalendlyWe are seeking a highly technical and strategic Senior Manager of Product Security & Security Operations to lead, mature, and scale both functions. This leader will build strong partnerships across Product and Engineering, embed security throughout the software development lifecycle, and strengthen Calendly's ability to detect and respond to threats.
The ideal candidate combines product and application security depth with strong security operations experience. They will lead teams, set strategy, and remain close enough to the work to guide architecture reviews, vulnerability remediation, detection engineering, investigations, and high-severity incidents.
Key Responsibilities:- Lead the Product Security and Security Operations teams, developing talent and holding the teams accountable for measurable outcomes.
- Define strategy, operating plans, metrics, and resource priorities aligned with Calendly's highest risks.
- Build strong partnerships across Security and with key cross-functional teams to align on risk, response, and remediation.
- Communicate priorities, risk tradeoffs, and program performance to senior leadership and cross-functional stakeholders.
- Scale product security capabilities, including threat modeling, application security testing, vulnerability management, and developer enablement.
- Lead detection engineering, incident response, threat intelligence, monitoring, and threat hunting capabilities.
- Guide high-severity incidents, complex investigations, and security reviews, driving durable remediation of systemic issues.
- Establish standards for control coverage and effectiveness across applications, cloud, identity, and endpoints.
- Manage program budgets and strategic security vendors.
What We're Looking ForThis opportunity is for you if you have:
- 7+ years of cybersecurity experience across product, application, or infrastructure security, plus security operations, incident response, or detection engineering.
- 4+ years managing experienced security engineers or multidisciplinary technical teams.
- Strong communication skills and the ability to navigate sensitive decisions with technical teams and senior leaders.
- Experience defining strategy and delivering measurable outcomes across multiple security disciplines.
- Experience building or scaling product security programs with Product and Engineering teams.
- Strong knowledge of secure software development, threat modeling, application security testing, vulnerability management, and cloud-native architectures.
- Strong knowledge of incident response, detection engineering, SIEM, EDR, cloud security, and identity security.
- Experience translating ambiguous risks into prioritized, cross-functional programs and driving remediation through influence.
- Experience managing budgets, MSSPs, testing firms, or other security providers.
- Authorization to work in the United States, as Calendly does not provide immigration sponsorship at this time.
The ranges listed above are the expected annual base salary for this role, subject to change.
Calendly takes a number of factors into consideration when determining an employee's starting salary, including relevant experience, relevant skills sets, interview performance, location/metropolitan area, and internal pay equity.
Base salary is just one component of Calendly's total rewards package. All full-time (30 hours/week) employees are also eligible for equity awards, and competitive benefits. Eligible Sales employees also qualify for a Sales Incentive program.
Calendly uses the zip code of an employee's remote work location, or the onsite building location if hybrid, to determine which metropolitan pay range we use. Current geographic zones are as follows:
- Tier 1: San Francisco, CA, San Jose, CA, New York City, NY
- Tier 2: Chicago, IL, Austin, TX, Denver, CO, Boston, MA, Washington D.C., Philadelphia, PA, Portland, OR, Seattle, WA, Miami, FL, and all other cities in CA.
- Tier 3: All other locations not in Tier 1 or Tier 2
This role may require occasional travel for company events, team collaboration, or offsites.