Manager, Security Engineering & Operations

Salesloft Salesloft · Enterprise · United States · Corporate Services

Manager, Security Engineering & Operations at Salesloft, focusing on building and leading a security team to defend the environment and engineer security infrastructure. The role emphasizes driving an AI mindset for automation and detection, overseeing vulnerability management, and integrating security into the architecture. It requires a player-coach with radical ownership and experience in AWS/GCP.

What you'd actually do

  1. Lead and Mentor: Manage a hybrid team of analysts and engineers, providing technical guidance, career development, and performance coaching.
  2. Program Oversight: Oversee the vulnerability management lifecycle, ensuring that scanning, triaging, and remediation efforts are executed with precision.
  3. Bridge the Gap: Ensure that Security Engineering is building the preventive/detective controls that Security Operations actually needs to be effective.
  4. Strategic Automation: Drive the "Automation and AI" mindset, moving the team away from manual triage toward automated detection, response, and remediation.
  5. Incident & Infrastructure Leadership: Serve as the escalation point for incidents while simultaneously overseeing the design and deployment of our security stack (SIEM, CNAPP, SWG, EDR, Vulnerability Scanners).

Skills

Required

  • 8+ years of overall experience in Security Engineering or Operations
  • Technical Mastery: Professional working knowledge of our stack (AWS, GCP, Kubernetes, Docker, Linux, Postgres) sufficient to architect solutions and conduct deep-dive architecture risk reviews.
  • Process Excellence: Experience building or maturing a vulnerability management program across source code, open source dependencies, containers, and cloud infrastructure.
  • AI Adoption & Innovation: An innovative mindset dedicated to driving AI-centric improvements across the security stack. You should be passionate about leveraging AI to automate repetitive tasks, enhance predictive detection, and ensure our security architecture evolves alongside AI-driven advancements in the industry
  • Data-Driven Leadership: Ability to analyze security metrics (MTTR, vulnerability burn-down rates, etc) to drive continuous improvement.
  • Low-Friction Leadership: Proven ability to manage upward effectively, providing proactive updates and results rather than requiring constant management oversight.
  • Detection Engineering: Experience identifying Indicators of Compromise (IOCs) and turning them into actionable alerting for the Ops team.
  • SaaS & Compliance: Deep familiarity with SaaS environments and evidencing controls for SOC 2, ISO 27001, and GDPR.
  • Communication: Strong ability to communicate technical risk to non-technical stakeholders and influence cross-functional outcomes.
  • Project Management: Ability to design and execute on projects via trackable work product and consistent methodology.

Nice to have

  • CISSP, AWS Security Specialty, or GCIH/GCIA are highly preferred.
  • Threat Modeling: Ability to mentor and lead the engineering team in conducting threat modeling and risk reviews of constantly evolving technical infrastructure.

What the JD emphasized

  • player-coach
  • bias-towards-action
  • radical ownership
  • AI Adoption & Innovation
  • Automation and AI mindset