
Engineering Manager, Security
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in Europe.
• Take ownership of security foundations, which include secure-by-default Terraform and Docker modules, as well as hardened images for ECS and EKS workloads, coupled with developer-platform guardrails.
• Enhance cloud security posture by addressing Wiz findings and optimizing IAM, KMS, CloudTrail, and GuardDuty settings.
• Automate the gathering of compliance evidence for standards such as PCI DSS, SOC 2, ISO 27001, and DORA.
• Oversee the comprehensive management of vulnerability and incident response processes, which include triage, SLAs, remediation, and post-incident reviews.
• Establish the application security practice through threat modeling, architecture reviews, and guidance on secure coding.
• Utilize and develop AI-native security tools for VulnOps, red-teaming, and incident response activities.
• Lead and expand the security team, which includes the recruitment of a third Security Engineer.
• Define the security roadmap and create measurable metrics to assess security posture.
• Collaborate with teams from Platform Core, SRE, and product divisions.
• Engage in security reviews and provide support during incidents.
• Practical experience in DevSecOps or cloud security, preferably with direct responsibility for an AWS environment.
• Hands-on expertise with IAM, KMS, CloudTrail, GuardDuty, and Service Control Policies (SCPs).
• Strong proficiency in Terraform, including the ability to write secure, reusable modules from the ground up.
• Experience in securing containerized workloads with ECS, EKS, or Kubernetes.
• Knowledge of hardened base images and admission controllers.
• Scripting skills in Python, Bash, or TypeScript for automating compliance checks and triage workflows.
• Familiarity with PCI DSS, SOC 2, and/or ISO 27001 standards.
• Experience in managing vulnerability processes at scale or leading incident response efforts.
• Experience in managing engineers or guiding trusted technical projects.
• At least one hiring decision that has provided valuable learning experiences.
• Ability to articulate security risks in a clear manner to non-security stakeholders.
• Perspective on AI as a tool for attackers and the evolving timelines for vulnerability response.
• Comfort with AI-assisted development tools and a rigorous approach to reviewing AI-generated pull requests.
• Competitive salary.
• Choice of preferred operating system, either Windows or Mac.
• Flat organizational structure and open communication in a relaxed yet professional environment.
• Opportunity to cultivate your skills within a dynamic team with ambitious objectives.
• Flexibility and potential for remote work.
• Pliant Card with a monthly allowance to explore the product and enjoy meals with colleagues.
Remote People
Bestow
Virta Health
Space Inch
Get handpicked remote jobs straight to your inbox weekly.