- Company Name
- Attentive
- Job Title
- Senior Manager, Information Security
- Job Description
-
**Job Title:** Senior Manager, Information Security
**Role Summary:**
Lead the strategic vision, roadmap, and day‑to‑day operations of the organization’s security function, encompassing vulnerability management, application security, cloud and endpoint protection, detection engineering, security operations, and corporate security. Manage, mentor, and scale a team of engineers and analysts while partnering cross‑functionally with Engineering, Product, Legal, and IT to embed robust security practices into the software development lifecycle and business operations.
**Expectations:**
- Deliver measurable risk reduction while maintaining high developer velocity.
- Scale security capabilities in a fast‑growing, distributed environment.
- Build and maintain a high‑performance, diverse security team.
- Serve as a trusted advisor to senior leadership on security strategy and incident response.
**Key Responsibilities:**
- Define and execute a comprehensive security strategy and roadmap.
- Mentor and develop security engineers and analysts, fostering a culture of security rigor, innovation, and psychological safety.
- Oversee vulnerability management, application security, cloud infrastructure security, endpoint protection, detection engineering, and security operations.
- Lead high‑impact initiatives such as enterprise secrets management, CSPM tooling, platform abuse prevention, and incident response readiness.
- Guide the development, operation, and reliability of critical security services; act as primary escalation point during incidents.
- Communicate security risks, trade‑offs, and recommendations to technical teams, product stakeholders, and senior leadership.
- Partner with engineering leaders to integrate security into architecture reviews, SDLC, and operational practices.
**Required Skills:**
- 7+ years in security engineering; 2+ years in leadership/mentoring.
- Hands‑on expertise in cloud security, product security, detection engineering, incident response, and GRC.
- Proficiency with modern security tooling (e.g., Datadog, Terraform, SentinelOne, Wiz, Panther, Semgrep).
- Strong communication and stakeholder‑management skills.
- Ability to balance rigorous security controls with rapid software delivery.
- Problem‑solving mindset for complex, ambiguous security challenges.
- Deep technical engagement on infrastructure design, product architecture, and secure‑by‑default design patterns.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Relevant security certifications (e.g., CISSP, CISM, CCSP, CEH, or equivalent) preferred.