Summit Health-posted 3 months ago
$109,000 - $247,000/Yr
Full-time • Manager
5,001-10,000 employees

As an Engineering Manager on our Application Security team, you’ll lead the charge in embedding secure practices across Shipt. You’ll manage a high-performing team of engineers focused on scaling security controls that protect our users, empower developers, and safeguard our applications. You’ll cultivate a culture of growth, accountability, and innovation by mentoring your team, driving strategic initiatives, and shaping security practices across the organization. If you are enthusiastic about cybersecurity, enjoy sharing your knowledge, and thrive on personal and professional growth, you're exactly the kind of manager we're looking for. Our Shipt Cybersecurity team is growing, and we're looking for a self-directing manager who can work both independently and collaboratively, with a passion for leading teams and achieving goals. You will gain valuable experience collaborating with cross-disciplinary teams, contributing to the protection of customers and shoppers nationwide.

  • Manage and prioritize the workload of engineering teams, ensuring alignment with company goals and security objectives.
  • Conduct regular 1:1s, performance reviews, and career development conversations while fostering a culture of growth, feedback, and accountability.
  • Manage end-to-end vendor relationships, including execution of annual agreements, seamless onboarding processes, and consistent touchbases.
  • Lead the planning, execution, and continuous improvement of PCI DSS and SOC 2 compliance programs.
  • Plan and coordinate with multiple external vendors to scope, schedule, and execute penetration testing initiatives.
  • Manage a comprehensive vulnerability management program leveraging tools such as Qualys.
  • Create and track key performance indicators (KPIs) for application security.
  • Lead post-incident reviews, ensuring root cause analysis and remediation actions are completed.
  • Collaborate on remediation plans for discovered security vulnerabilities.
  • Own the recruitment, onboarding, and retention efforts for the AppSec team.
  • Manage the team’s resource allocation, partnering with senior leaders.
  • Represent the team in cross-functional meetings, summarizing risks, achievements, and strategic priorities.
  • Communicate and escalate critical security issues to executive leadership.
  • Demonstrate a proven track record of delivery in cybersecurity or a security-focused leadership role.
  • Understand least privilege and/or role-based access control principles.
  • Experience in technical project management and application delivery.
  • Communicate effectively with all levels within the organization.
  • Proven experience managing engineering teams and aligning their work with company goals.
  • Experience in conducting performance reviews and fostering a culture of accountability.
  • Experience managing vendor relationships and ensuring alignment and performance tracking.
  • Experience with PCI DSS and SOC 2 compliance programs.
  • Experience in vulnerability management and remediation strategies.
  • Experience in creating and tracking KPIs for application security.
  • Experience in incident response and post-incident reviews.
  • Experience in recruitment and building diverse teams.
  • Strong communication skills for cross-functional collaboration.
  • CISSP, OSWE, CSSLP, GWAPT, GWEB, OSCP, CompTIA Security+ certification.
  • Experience with CI/CD systems as part of the software development lifecycle.
  • Familiarity with containerization concepts and tools.
  • Experience with cloud platforms, especially Kubernetes.
  • Experience building APIs, automation tools, and developer-facing services.
  • Working knowledge of relational databases, web applications, and services.
  • Experience with source code version control (Git/GitHub).
  • Medical, dental, and vision insurance.
  • 401k plan.
  • Discretionary vacation for exempt team members.
  • Paid holidays throughout the calendar year.
  • Paid sick leave.
  • Eligibility for an annual bonus.
  • Potential for restricted stock units based on role.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service