Senior Manager – Security Engineering

Posted Aug 28

This is a fully remote position, open to applicants in Virginia.

📋 Description

• Provide strategic vision, leadership, and operational accountability for Ferguson’s enterprise security engineering functions.

• Build, lead, and nurture a high-performing Security Engineering team through recruitment, hiring, coaching, mentorship, performance management, and career development.

• Define and uphold the operating model, service ownership, roadmap, and measurable objectives for Security Engineering capabilities.

• Represent the Security Engineering performance, risks, resource requirements, and strategic opportunities to Information Security and Technology leadership.

• Collaborate with Security Architecture, Security Operations, GRC, Identity, Infrastructure, Application Development, Cloud, and business technology teams.

• Evaluate team skills, capacity, vendor support, and tooling maturity against current and emerging threats.

• Establish metrics, reporting routines, and executive-ready narratives on risk posture, control effectiveness, remediation progress, service value, and investment needs.

• Own and enhance vulnerability management, DevSecOps, penetration testing, adversarial validation, edge security, email security, endpoint security, cloud security posture, configuration risk, application security testing, and security tooling integrations.

• Lead risk-based vulnerability management, including asset visibility, authenticated scanning, assessment, risk contextualization, remediation tracking, exception management, and leadership reporting.

• Integrate security testing and guidance into development workflows, including static analysis, software composition analysis, container security, secrets protection, code signing, secure repositories, and developer remediation support.

• Conduct penetration testing, AI-enabled security testing, purple team support, and continuous adversarial validation.

• Protect public-facing applications and digital channels using WAF, bot management, CDN security, origin protection, API protections, and secure traffic patterns.

• Oversee email and endpoint security capabilities, including migration planning, policy tuning, telemetry quality, detection support, deployment health, and operational readiness.

• Drive enterprise configuration and posture management across cloud, infrastructure, endpoints, applications, and identity-adjacent services.

• Collaborate with identity and cryptographic services teams on PAM, SSO, certificates, non-human identities, key management, and cryptographic services.

• Support AI resilience, post-quantum readiness, cryptographic visibility, secrets removal, cloud posture modernization, and security tooling rationalization.

• Ensure security engineering platforms and services are reliable, monitored, documented, supportable, policy-aligned, and compliant with regulatory or audit obligations.

• Maintain runbooks, customer concern paths, operational handoffs, service ownership documentation, vendor engagement models, and cross-training practices.

• Prioritize engineering work based on business risk, exploitability, asset criticality, exposure, compliance requirements, operational impact, and remediation capacity.

• Contribute to security technology selection, proof-of-value efforts, vendor evaluations, architecture reviews, and implementation planning.

• Monitor emerging technologies, threats, attack patterns, regulatory expectations, and industry practices.

• Drive and report on service restoration activities as needed.

• Support enterprise business and sales objectives through effective job performance.


⛳️ Requirements

• Proven experience in leading information security engineering, application security, vulnerability management, cloud security, endpoint security, or related technical security teams is essential.

• Experience managing full-time employees, contractors, vendors, and multi-functional delivery partners is required.

• Strong preference for candidates with experience in building or operating risk-based vulnerability management, application security testing, DevSecOps, penetration testing, security tooling, or cloud posture management programs.

• Preferred experience in collaborating with infrastructure, application development, cloud, identity, security operations, GRC, and business technology teams to mitigate enterprise technology risk.

• A minimum of eight (8) years in information security, technology risk, security engineering, or related roles is strongly preferred, demonstrating leadership accountability.

• Excellent leadership, communication, organizational, and internal business customer leadership skills.

• Ability to translate technical security findings, control gaps, and threat scenarios into business risk, prioritized actions, and executive-level communication.

• Comprehensive knowledge of vulnerability management, exposure management, application security, DevSecOps, penetration testing, web application security, API security, cloud security, endpoint protection, email security, and configuration management practices.

• Solid understanding of vulnerability scanners, risk reporting platforms, SAST, SCA, container security, WAF, bot management, EDR, CSPM, SIEM integrations, secrets management, certificate management, and identity-related security platforms.

• Capability to lead multi-functional remediation efforts across ownership, technical complexity, business impact, and risk acceptance decisions.

• Familiarity with NIST CSF, ISO 27001/27002, OWASP, MITRE ATT&CK, CIS Benchmarks, secure SDLC, and IT service management.

• Ability to develop metrics and reporting showcasing security posture, remediation progress, control effectiveness, service health, and business value.

• Effectively operate in a distributed, matrixed environment.

• Ability to partner with architecture, delivery, operations, infrastructure, cloud, identity, and business teams.

• Strong skills in vendor management, proof-of-value, requirements development, and technology evaluation.

• Proficiency with Microsoft Office and collaboration tools.

• Certifications such as CISSP, CISM, CCSP, GIAC, Azure Security, AWS Security, or similar are preferred but not mandatory.

• Ability to prioritize tasks, establish timelines, manage trade-offs, and achieve outcomes by deadline.


🏝️ Benefits

• Health insurance

• Dental insurance

• Vision insurance

• Paid time off

• Life insurance

• 401(k) with a company match

• Mental health coverage

• Gender affirming benefits

• Family building benefits

• Paid parental leave

• Associate discounts

• Community involvement opportunities

• Bonus or Incentive Plan eligibility

People also viewed

Leidos21 hours ago

Senior Information Systems Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$107.9k – $195.1k/year
ApplyView job
Cisco2 days ago

Security Engineer

US flagColorado, +2 more statesFull-timeCybersecurity / Security Engineer$139.3k – $203.6k/year
ApplyView job
RELX2 days ago

Senior Security Engineer – Sec Ops

US flagNew Jersey, +4 more statesFull-timeCybersecurity / Security Engineer$78.8k – $131.3k/year
ApplyView job
TASQ Staffing Solutions2 days ago

Senior Cloud Security Engineer

PH flagPhilippines OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
MRO2 days ago

Information Security Assurance Advisor

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$104k – $140k/year
ApplyView job
AgelessRx2 days ago

Senior Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$155k – $170k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers