
Senior Manager – Security Engineering
Posted Aug 28

Posted Aug 28
This is a fully remote position, open to applicants in Virginia.
• Provide strategic vision, leadership, and operational accountability for Ferguson’s enterprise security engineering functions.
• Build, lead, and nurture a high-performing Security Engineering team through recruitment, hiring, coaching, mentorship, performance management, and career development.
• Define and uphold the operating model, service ownership, roadmap, and measurable objectives for Security Engineering capabilities.
• Represent the Security Engineering performance, risks, resource requirements, and strategic opportunities to Information Security and Technology leadership.
• Collaborate with Security Architecture, Security Operations, GRC, Identity, Infrastructure, Application Development, Cloud, and business technology teams.
• Evaluate team skills, capacity, vendor support, and tooling maturity against current and emerging threats.
• Establish metrics, reporting routines, and executive-ready narratives on risk posture, control effectiveness, remediation progress, service value, and investment needs.
• Own and enhance vulnerability management, DevSecOps, penetration testing, adversarial validation, edge security, email security, endpoint security, cloud security posture, configuration risk, application security testing, and security tooling integrations.
• Lead risk-based vulnerability management, including asset visibility, authenticated scanning, assessment, risk contextualization, remediation tracking, exception management, and leadership reporting.
• Integrate security testing and guidance into development workflows, including static analysis, software composition analysis, container security, secrets protection, code signing, secure repositories, and developer remediation support.
• Conduct penetration testing, AI-enabled security testing, purple team support, and continuous adversarial validation.
• Protect public-facing applications and digital channels using WAF, bot management, CDN security, origin protection, API protections, and secure traffic patterns.
• Oversee email and endpoint security capabilities, including migration planning, policy tuning, telemetry quality, detection support, deployment health, and operational readiness.
• Drive enterprise configuration and posture management across cloud, infrastructure, endpoints, applications, and identity-adjacent services.
• Collaborate with identity and cryptographic services teams on PAM, SSO, certificates, non-human identities, key management, and cryptographic services.
• Support AI resilience, post-quantum readiness, cryptographic visibility, secrets removal, cloud posture modernization, and security tooling rationalization.
• Ensure security engineering platforms and services are reliable, monitored, documented, supportable, policy-aligned, and compliant with regulatory or audit obligations.
• Maintain runbooks, customer concern paths, operational handoffs, service ownership documentation, vendor engagement models, and cross-training practices.
• Prioritize engineering work based on business risk, exploitability, asset criticality, exposure, compliance requirements, operational impact, and remediation capacity.
• Contribute to security technology selection, proof-of-value efforts, vendor evaluations, architecture reviews, and implementation planning.
• Monitor emerging technologies, threats, attack patterns, regulatory expectations, and industry practices.
• Drive and report on service restoration activities as needed.
• Support enterprise business and sales objectives through effective job performance.
• Proven experience in leading information security engineering, application security, vulnerability management, cloud security, endpoint security, or related technical security teams is essential.
• Experience managing full-time employees, contractors, vendors, and multi-functional delivery partners is required.
• Strong preference for candidates with experience in building or operating risk-based vulnerability management, application security testing, DevSecOps, penetration testing, security tooling, or cloud posture management programs.
• Preferred experience in collaborating with infrastructure, application development, cloud, identity, security operations, GRC, and business technology teams to mitigate enterprise technology risk.
• A minimum of eight (8) years in information security, technology risk, security engineering, or related roles is strongly preferred, demonstrating leadership accountability.
• Excellent leadership, communication, organizational, and internal business customer leadership skills.
• Ability to translate technical security findings, control gaps, and threat scenarios into business risk, prioritized actions, and executive-level communication.
• Comprehensive knowledge of vulnerability management, exposure management, application security, DevSecOps, penetration testing, web application security, API security, cloud security, endpoint protection, email security, and configuration management practices.
• Solid understanding of vulnerability scanners, risk reporting platforms, SAST, SCA, container security, WAF, bot management, EDR, CSPM, SIEM integrations, secrets management, certificate management, and identity-related security platforms.
• Capability to lead multi-functional remediation efforts across ownership, technical complexity, business impact, and risk acceptance decisions.
• Familiarity with NIST CSF, ISO 27001/27002, OWASP, MITRE ATT&CK, CIS Benchmarks, secure SDLC, and IT service management.
• Ability to develop metrics and reporting showcasing security posture, remediation progress, control effectiveness, service health, and business value.
• Effectively operate in a distributed, matrixed environment.
• Ability to partner with architecture, delivery, operations, infrastructure, cloud, identity, and business teams.
• Strong skills in vendor management, proof-of-value, requirements development, and technology evaluation.
• Proficiency with Microsoft Office and collaboration tools.
• Certifications such as CISSP, CISM, CCSP, GIAC, Azure Security, AWS Security, or similar are preferred but not mandatory.
• Ability to prioritize tasks, establish timelines, manage trade-offs, and achieve outcomes by deadline.
• Health insurance
• Dental insurance
• Vision insurance
• Paid time off
• Life insurance
• 401(k) with a company match
• Mental health coverage
• Gender affirming benefits
• Family building benefits
• Paid parental leave
• Associate discounts
• Community involvement opportunities
• Bonus or Incentive Plan eligibility
Leidos
Cisco
RELX
TASQ Staffing Solutions
Get handpicked remote jobs straight to your inbox weekly.