
Senior Manager, Security – Continuous Monitoring
Posted 4 days ago

Posted 4 days ago
This is a fully remote position, open to applicants in California.
• Lead the Continuous Monitoring team and take charge of the engineering function that assesses the effectiveness of Databricks security controls.
• Showcase the control posture in compliance with SOC 2, ISO 27001, FedRAMP, PCI DSS, and evolving AI governance requirements.
• Establish the team’s vision, priorities, strategy, OKRs, and KPIs.
• Recruit, nurture, and guide Security Software Engineers along with future technical leaders and managers.
• Set engineering quality standards for code reviews, reliability, observability, and thorough documentation.
• Oversee the continuous monitoring platform roadmap, control-state collection, posture assessment, tooling integration, and remediation tracking.
• Define and prioritize controls, enhance automated coverage, minimize manual evidence collection, and ensure precise output.
• Manage security posture dashboards, metrics, and executive reporting.
• Communicate control gaps, risk implications, and remediation requirements to senior leadership.
• Collaborate with GRC, Enterprise Security, Product Security, Security Operations, IT, Legal, and Engineering leadership.
• Facilitate cross-functional initiatives such as addressing telemetry gaps, GRC platform migrations, and multi-quarter automation programs.
• Lead evaluations for build-versus-buy decisions regarding CSPM, SSPM, GRC automation, and security posture tools.
• Oversee program operating costs and translate regulatory and architectural changes into strategic roadmap decisions.
• At least 2 years of prior management experience leading Engineering or Security engineering teams.
• Typically a minimum of 12 years of experience, or an advanced degree plus 8 years, preferably with a focus on security engineering, security posture monitoring, or compliance automation.
• Proficient in reading and critiquing Python automation.
• Capable of evaluating integration architecture and assessing production readiness.
• Familiarity with security controls including identity and access management, configuration management, logging coverage, vulnerability management, and data protection.
• Knowledge of cloud security across at least one major platform: AWS, Azure, or GCP.
• Understanding of IAM, audit logging, CSPM concepts, and cloud-native security services.
• Working knowledge of SOC 2, ISO 27001, FedRAMP, or similar compliance frameworks.
• Experience in building security posture monitoring or compliance automation at scale.
• Ability to define and achieve OKRs and KPIs.
• Competence in making effective priority decisions regarding resource allocation and team alignment.
• Strong communication skills across technical, GRC, and executive audiences.
• Eligibility for an annual performance bonus.
• Equity opportunities.
• Comprehensive benefits and perks; specific regional details are provided by Databricks.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.