Manager, Security Engineering

The Trade Desk The Trade Desk · Media · Bellevue, WA · Information Security

Manager, Security Engineering to lead a combined team of Application Security and Platform Security engineers, with end-to-end ownership of how TTD secures both the code they ship and the infrastructure they run it on. Contribute to the strategy, roadmap, and execution of TTD’s Security Engineering function — including the KPIs, maturity model, and executive-level reporting that demonstrate measurable improvement in our overall security posture over time.

What you'd actually do

  1. Lead, grow, mentor, and develop a combined team of Application Security and Platform Security engineers; drive performance, growth, and retention across the function.
  2. Own and evolve The Trade Desk’s Security Engineering strategy, roadmap, and maturity model across both application and platform domains; define and report KPIs that demonstrate measurable improvement in security posture to senior leadership.
  3. Ensure consistency and alignment across application and platform security controls — driving unified standards, shared tooling, and integrated posture outcomes for the enterprise.
  4. Drive shift-left integration of security into the SDLC in partnership with Engineering and Product — including threat modeling, secure design reviews, and the rollout and tuning of SAST, DAST, and SCA tooling.
  5. Mature TTD’s posture management capabilities across cloud and infrastructure — including CSPM, Infrastructure-as-Code scanning, hardening baselines, and configuration management.

Skills

Required

  • 7+ years of experience in Information Security or Cybersecurity, with hands-on depth in Application Security and/or Platform/Cloud Security.
  • 2+ years of experience leading and developing security engineering teams, including hiring, mentoring, performance management, and roadmap ownership.
  • Experience driving a measurable security maturity program — defining KPIs, reporting to leadership, and demonstrating posture improvement over time.
  • Experience building programs that apply industry-standard security best practices and reconcile them against business and engineering needs.
  • Experience managing a security assessment program — including architecture reviews, secure design reviews, threat models, and code/configuration reviews across many product teams.
  • Experience building security visibility and engagement programs (e.g., Security Champions, security awareness, training) that scale culture and coverage across the organization.
  • Working knowledge of cloud security, Cloud Security Posture Management (CSPM), and Infrastructure-as-Code scanning across one or more major cloud platforms (AWS, GCP, or Azure).
  • Strong understanding of secure software development and deployment practices, including common application security risks and mitigations (e.g., OWASP, CWE).

Nice to have

  • Familiarity with common Information Security

What the JD emphasized

  • end-to-end ownership
  • strategy, roadmap, and execution
  • measurable improvement
  • security posture
  • security engineering function
  • maturity model
  • KPIs
  • executive-level reporting
  • application and platform security expertise
  • building and developing high-performing teams
  • bias to action
  • translate technical risk into business outcomes
  • integrity
  • communicate clearly
  • empathy
  • curiosity
  • ownership of outcomes
  • calm under pressure
  • feedback
  • humility
  • willingness to grow
  • team sport
  • setting the tone
  • security assessment program
  • secure design reviews
  • threat models
  • code/configuration reviews
  • security visibility and engagement programs
  • security champions
  • security awareness
  • training
  • scale culture and coverage
  • cloud security
  • Cloud Security Posture Management (CSPM)
  • Infrastructure-as-Code scanning
  • secure software development and deployment practices
  • common application security risks and mitigations
  • OWASP
  • CWE