- Company Name
- Twilio
- Job Title
- Senior Manager, Security Risk
- Job Description
-
**Job Title**
Senior Manager, Security Risk
**Role Summary**
Lead and expand a global security risk function across hybrid cloud, on‑prem, and microservices environments. Drive risk assessment, regulatory compliance, and strategic risk frameworks while mentoring an international team of analysts. Serve as the primary risk liaison for engineering, product, IT, and external auditors.
**Expectations**
- Deliver high‑impact, executive‑level risk reporting that translates technical vulnerabilities into clear business mitigation plans.
- Mature and operationalize the One Twilio Risk Management framework using NIST RMF, ISO 27005, ISO 31000, and emerging AI risk and data governance standards.
- Maintain a pragmatic, scalable risk approach that balances security controls with business velocity.
- Foster a culture of excellence, continuous professional development, and accountability within the risk team.
**Key Responsibilities**
- • Lead, mentor, and grow an international and domestic risk analyst team.
- • Conduct complex risk assessments across microservices, cloud‑native, and legacy telecom systems.
- • Integrate compliance controls into risk processes and mature the One Twilio Risk Management framework.
- • Develop and deliver executive‑level risk reporting and actionable insights.
- • Design and optimize risk intake, tracking, and remediation workflows in Jira and GRC tools (LogicGate, ServiceNow, Archer).
- • Craft pragmatic risk solutions that enable business innovation without compromising security.
- • Act as primary point of contact for external auditors and regulators, articulating risk posture and control effectiveness.
**Required Skills**
- 8+ years in cybersecurity/information security, 4+ years leading international security teams.
- Deep knowledge of hybrid cloud (AWS, GCP), on‑prem infrastructure, and microservices architectures; telecom experience preferred.
- Proven implementation of NIST RMF, ISO 31000, ISO 27005, AI risk, and data governance frameworks.
- Advanced proficiency in Jira workflow orchestration and security tooling (Wiz, Orca, Snyk).
- Experience with GRC platforms (LogicGate, Archer, ServiceNow).
- Strong negotiation, diplomacy, and stakeholder management ability.
- “No‑ego” leadership style with a focus on team credit and impact.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, or related discipline (or equivalent experience).
- Relevant certifications preferred: CISSP, CISM, ISO 27001 Lead Implementer, NIST RMF Certified Practitioner.