Security Engineering Manager
$155,000–$207,000 year
HybridSan Francisco, California, United States
Job Summary
Lead and develop a team of security engineers, acting as a technical player-coach to manage deliverables, mentorship, and continuous learning. Integrate foundational security tooling and automation across corporate, infrastructure, and application layers while collaborating with engineering teams, IT, legal, and compliance. Develop data-driven security strategies, including OKRs, KPIs, and roadmaps, to advocate for security priorities during cross-functional planning. Manage compliance with frameworks such as CIS, SOC2, and GDPR, and lead pragmatic incident response efforts focused on investigation, resolution, and threat modeling. Drive cultural change through education and govern the Information Security Program by developing proposals that align with Taskrabbit's business goals. This role operates on a hybrid schedule with two days of in-office collaboration per week.
Required Qualifications
- 5+ years of experience building and managing security teams in an agile, high-growth environment
- Proven track record of achieving a security framework from scratch (e.g., taking a company through its first SOC2 or ISO 27001 certification)
- Strong technical 'Player-Coach' ability, with the comfort level to dive into technical initiatives and provide direct guidance to security engineers
- Exceptional written and verbal communication skills, with a knack for telling the 'story' of security through formal proposals, strategies, and risk presentations
- Pragmatic Risk Management: Ability to handle moderate risk tolerance by focusing on business impact and customer trust rather than theoretical perfection
- Analytical and data-oriented mindset, with experience designing metrics and KPIs that demonstrate the business value of security initiatives
- Expertise in influence-based leadership, showing a history of driving security maturity in non-regulated industries through relationship building and alignment
- Deep knowledge of modern security practices, including cloud security, access controls, and secure software development, with experience leading incident response
- Extensive experience working with one or more security frameworks (e.g. CIS, SOC2) and regulatory compliance standards (e.g. GDPR)
- Experience with security governance for AI/ML systems and a proactive approach to managing the risks inherent in emerging technologies
- Experience with security tooling implementation: Direct experience implementing or leading the implementation of comprehensive security tooling
- This role operates on a hybrid schedule requiring two days of in-office collaboration per week
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.