Senior Security Engineering Manager, Enterprise Security

Upstart Upstart · Fintech · Remote · InfoSec

Upstart is an AI lending marketplace that uses AI to reshape access to credit. This role is for a Senior Security Engineering Manager, Enterprise Security, focusing on building and maturing security programs across enterprise security, security operations, and detection engineering to protect the company's systems, products, and data. The role involves leading a team, defining security strategies, building proactive controls, improving threat detection and response, and driving cross-functional security initiatives.

What you'd actually do

  1. Lead the strategy, roadmap, and execution for security engineering programs across enterprise security, security operations, and detection security engineering.
  2. Manage, coach, and develop a team of security professionals, ensuring the team has clear priorities, measurable goals, effective operating rhythms, and opportunities for career growth.
  3. Build and mature proactive and preventative security controls across corporate systems, cloud environments, identity platforms, endpoints, SaaS applications, and security operations workflows.
  4. Improve Upstart’s ability to detect, investigate, and respond to threats by strengthening detection coverage, alert quality, logging strategy, response playbooks, automation, and operational processes.
  5. Drive cross-functional security initiatives across Engineering, IT, Compliance, Legal, Risk, and business teams, aligning security priorities with company objectives, risk tolerance, and operational needs.

Skills

Required

  • Experience leading security engineering teams
  • Experience in enterprise security, security operations, and detection engineering
  • Experience building and maturing security controls
  • Experience improving threat detection and response capabilities
  • Experience driving cross-functional security initiatives
  • Experience with security metrics and reporting

Nice to have

  • Experience in a regulated environment (fintech, compliance, risk)

What the JD emphasized

  • shape a security engineering culture that prioritizes proactive and preventative controls over purely reactive response
  • investing in durable controls, automation, detection coverage, and early risk reduction
  • reduce costly incidents, minimize operational disruption
  • aligning security priorities with company objectives, risk tolerance, and operational needs