Manager, Security Engineering

Cohere Cohere · AI Frontier · United States · Product

Manager of Security Engineering responsible for developing and implementing enterprise-wide security processes, including vulnerability management, SAST, DAST, penetration testing, and secure SDLC integration. The role involves leading a team of security engineers, reviewing security architecture, and ensuring alignment with industry standards and regulatory requirements. While the company works with AI models, this role focuses on the security engineering aspects of the platform and applications, not direct AI/ML model development.

What you'd actually do

  1. Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues
  2. Execute the long-term vision for the Security team in alignment with Cohere’s product and business goals.
  3. Collaborate closely with leadership to prioritize high-impact initiatives and strategic customer engagements.
  4. Vulnerability Management: Develop and implement enterprise-wide vulnerability management processes and tooling, including identification, prioritization, remediation tracking, and reporting, including customer artifacts
  5. Static Application Security Testing (SAST): Establish SAST programs, integrate tools into CI/CD pipelines, and analyze results to identify and remediate security flaws in source code

Skills

Required

  • Application Security
  • Security Engineering
  • Vulnerability Management
  • Secure SDLC
  • Bug Bounty Programs
  • SAST
  • DAST
  • Penetration Testing
  • Python
  • GoLang
  • Cloud Platforms (AWS, GCP, Azure)
  • Container Security
  • Team Leadership
  • Communication Skills
  • Interpersonal Skills

Nice to have

  • OWASP Top10 for LLMs
  • ISO 27001
  • Agentic AI platform security

What the JD emphasized

  • 8+ years of previous experience in Application Security / Security Engineering with a strong focus on vulnerability management, SDLC and bug bounty programs.
  • Proven experience with SAST, DAST, and penetration testing methodologies and tools
  • You understand secure engineering best practices, can articulate problem statements, and propose solutions to both technically savvy and non-technical audiences.
  • You have a deep technical understanding of common security vulnerabilities and risks, as well as countermeasures and compensating controls.