Engineering Manager, Security

EvenUp EvenUp · Vertical AI · San Francisco, CA · Engineering

Engineering Manager, Security role at EvenUp, a fast-growing vertical SaaS company using AI to close the justice gap. This hybrid role involves defining the security roadmap, leading Security & IT teams, owning compliance (SOC 2, HIPAA), embedding security into the SDLC, managing corporate IT and cloud security, handling vendor risk, incident response, and fostering security culture. Requires proven security leadership at a startup, deep compliance experience, technical depth, product security skills, people leadership, vendor risk know-how, and a builder mentality.

What you'd actually do

  1. Define EvenUp's security roadmap and lead a growing Security & IT team. Serve as the internal authority on risk and security posture, advising engineering, legal, and the executive team. Hire and develop talent as the function scales.
  2. Own our SOC 2 Type II and HIPAA programs end-to-end: gap assessments, control design, audit readiness, and ongoing compliance. Maintain policies and procedures, manage auditor relationships, and stay ahead of evolving regulatory requirements.
  3. Partner with Engineering to embed security into the SDLC through threat modeling, secure design reviews, and vulnerability management (SAST, DAST, pen testing). Champion a shift-left, security-by-design culture across the product org.
  4. Own corporate IT systems (MDM, SSO/IdP, endpoint security, IAM) and cloud security posture. Evaluate and deploy security tooling. Enforce least-privilege and zero-trust principles across the organization.
  5. Lead the vendor risk program, including security assessments, contract reviews (BAAs, DPAs), and ongoing monitoring of third-party risk exposure.

Skills

Required

  • Security strategy and roadmap definition
  • Team leadership and talent development
  • SOC 2 Type II and HIPAA compliance programs
  • Risk assessment and management
  • Incident response planning and execution
  • Product security (threat modeling, secure design reviews, vulnerability management)
  • Cloud security (AWS/GCP/Azure)
  • IAM, endpoint security
  • Secure SDLC practices
  • Vendor and third-party risk management
  • Corporate IT systems management (MDM, SSO/IdP)
  • Zero-trust principles

Nice to have

  • Familiarity with emerging requirements (state privacy laws, AI governance)

What the JD emphasized

  • Proven security leadership at a startup or high-growth company
  • Deep compliance experience
  • hands-on ownership of SOC 2 Type II and HIPAA programs
  • Technical depth across the stack
  • Product security chops
  • People leadership
  • Vendor & third-party risk know-how
  • Builder mentality