Lead the Product Security team at LaunchDarkly, focusing on risk management and team ownership in a fully remote environment.
Posted by employer 11 hours ago
First seen on Joblaze 5 hours ago
Last verified on the company career page 5 hours ago
Skills & Technologies
What you'll build
Must have
Nice to have
AI in the day-to-day
Automation and AI take the first pass on every finding.
Requirements
Not disclosed in this posting: visa sponsorship.
Benefits
Joblaze summary
In this role, the Senior Manager of Security will lead the Product Security team, focusing on integrating security practices into engineering workflows and ensuring teams take ownership of their security health. The position requires expertise in risk management, incident response, and familiarity with AWS security, as well as strong leadership skills to guide and develop a team of security engineers. This role is ideal for someone with a background in security engineering and management, particularly those who have transitioned security functions from a gatekeeping model to a collaborative approach.
Joblaze insights
Quick facts
From the original posting
We're looking for a senior security leader to run our Product Security team and partner to the Director of Security. In this role, you'll own how Security operates: a program led by risk rather than audit calendars, where engineering teams own their security health and Security informs, guides, and validates, where automation and AI take the first pass on every finding, and where posture is measured and published to executives every quarter. You'll build that model, starting with Product Security and extending across the division.
You'll bring a balance of people management, security judgment, and program leadership as you manage a team of security engineers, act as incident manager of record, hold delegated approval for vendor and access decisions, and run the division when the Director is in an audit, a board cycle, or on vacation. You'll work closely with every engineering team to make the secure path the easy one.
Manage the portfolio of your team's work, appropriately managing everyone's time and assigning them to the highest priority work.
Help your team and the engineering organization make sense of, and simplify, how security work gets done: who owns what, what is automated, and what Security stops doing.
Guide product engineering teams in owning their own security health: findings route to them with mapped severity, Security reviews and validates rather than fixes, and each team sees its security health in its own service review.
Own the wiring and routing of security findings and requests, driving down noise and the human-decision rate across intake, triage, and review.
Serve as incident manager of record for security incidents: first escalation for our service-level commitments, delegated approver for vendor and access decisions, and cover for the Director's operational duties.
Publish posture: monthly service-level attainment to engineering, quarterly posture to the executive team, and a risk register that drives priorities.
You have led a security team out of the gatekeeper model once already, and you can say what teams owned afterward, what Security stopped doing, and what the numbers did.
You think in risk, not control lists, and you would rather defend a priority call than a checklist.
You treat automation and AI as the first responder and yourself as the escalation path.
You have been the second leader to a director or CISO and know which decisions to make in their name.
You have run security incidents end to end, including the comms and the review afterward.
You were a strong Senior or Staff security engineer before you managed, and you can still read a PR, a threat model, or a cloud finding and make a call.
You track and drive metrics, and you understand what they can and can't tell you.
5+ years of experience in a formal security or engineering management role, including managing senior engineers.
Experience moving a security function from gatekeeper to team ownership, with measurable results.
Experience as incident manager for security incidents at a SaaS company, including external communication.
Experience guiding teams through technical tradeoffs and developing senior engineers' careers.
The ability to track and drive metrics, and the wisdom to understand what they can and can't tell you.
Familiarity with AWS security at scale and with external audits (SOC 2, ISO 27001, or FedRAMP) as a participant or control owner.
Excellent communication skills with both technical and non-technical stakeholders.
A thoughtful, empathetic approach to leadership and collaboration.
Pay:
Target pay ranges based on Geographic Zones* for Level M3:
Do you need a disability accommodation?
Standard company text repeated across LaunchDarkly's postings is omitted here.
Explore more