Skip to content
← Back to job listings

Security Engineering Manager (Cloud & AppSec)

Horizon3 · United States

External listingfull-time2 months ago

About The Role

Join our team as a Security Engineering Manager, where you will lead the engineers responsible for securing our Cloud environments and embedding security into the software development lifecycle. You will directly support the security, resilience, and scalability of our platform and internal systems. Your responsibilities will include designing and implementing security controls, partnering with engineering teams, leading the application security program, and continuously monitoring and improving security posture. You will also be responsible for recruiting and onboarding talented individuals, mentoring and coaching your team, and communicating security posture and priorities to business owners and leadership.

  • Lead and manage the Security Engineering team, setting priorities and operating rhythms for the team, balancing strategic security investments, day-to-day engineering support, and incident response.
  • Design and implement security controls across Cloud environments, continuously monitor and improve cloud posture, and partner with engineering teams to embed security into the software development lifecycle.
  • Develop and maintain security policies, standards, and procedures aligned to frameworks such as SOC 2, GDPR, ISO 27001, FedRAMP, NIST, CIS, and MITRE ATT&CK.
  • The ideal candidate brings strong technical depth in cloud security, practical application security experience, and the ability to partner effectively across engineering, infrastructure, and compliance
  • Must be able to work independently and as part of a team, with a strong sense of ownership and accountability
  • Must be knowledgeable in compliance standards and security frameworks, including SOC 2, GDPR, ISO 27001, FedRAMP, NIST, CIS, and MITRE ATT&CK
  • Must have strong written and verbal communication skills, with the ability to explain technical risks and tradeoffs to both technical and non-technical stakeholders
  • Must have a deep understanding of AWS security architecture, IAM, cloud posture management, data security principles, and secure SDLC practices
  • Must have experience developing metrics and reporting that communicate risk and security posture to leadership
  • Must have familiarity with DLP concepts, including data classification, identification, and protection
  • Must have experience leading or closely partnering with Application Security efforts, including threat modeling, vulnerability management, and security reviews
  • Must be proficient in AWS security services, Terraform, GitLab, and modern CI/CD security practices
  • 5+ years of experience securing cloud-native systems and modern software delivery pipelines
  • 5+ years of experience in cybersecurity
  • 5+ years of experience securing AWS environments
  • Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent practical experience
  • Prior experience leading security engineers or serving as a technical lead in a security engineering function
  • Crossplane
  • ArgoCD
  • Terraform
  • AWS
  • GitLab
  • CI/CD security tooling
  • IAM and access control systems
  • Cloud security monitoring and posture tools
  • Required Tech Stack Experience:
  • Experience leading both Cloud Security and Application Security teams
  • AWS Certified Security – Specialty
  • Experience in high-growth SaaS or cybersecurity companies
  • CISSP or other relevant security certifications
  • Experience building security programs that scale across engineering organizations
  • Broad knowledge across the security domain, with deeper specialization in one or more areas such as incident management, detection engineering, response tooling, or logs/events processing

This is an external listing. JobSpring does not represent or verify the employer. Report this listing