Sr. Manager, Security Engineering

6senseNew York City, NY
Remote

About The Position

Lead the security engineering organization that protects 6sense's AI-enabled, cloud-native SaaS platform. This leader owns Vulnerability Operations, Infrastructure Security, and Application/Product Security, and is accountable for building scalable security capabilities that enable rapid product delivery without compromising customer trust, resilience, or compliance. The role leads a distributed team across the United States and India and combines strategic leadership with credible technical judgment. The core responsibilities include Organization and People Leadership, AI and Product Security, Vulnerability Operations, Infrastructure and Cloud Security, and Strategy, Governance, and Business Partnership. Success will be measured by risk reduction, coverage, engineering velocity, AI security readiness, operational maturity, people and leadership, and stakeholder trust.

Requirements

  • 8+ years in information security, including significant experience in product or application security, cloud security, vulnerability management, or security engineering.
  • 3+ years leading security engineering teams, including experience managing distributed or cross-region teams.
  • Demonstrated ability to build and mature security programs in a cloud-native SaaS environment, preferably on AWS.
  • Practical experience securing modern software delivery, including secure development lifecycle practices, application security testing, cloud-native infrastructure, containers, infrastructure as code, software supply chain, and vulnerability operations.
  • Working knowledge of AI and machine learning security risks and controls.
  • Ability to evaluate technical risk, make sound tradeoffs, and convert strategy into clear roadmaps, operating mechanisms, and measurable outcomes.
  • Strong executive and technical communication skills, including the ability to explain complex risk in plain language and influence without relying on authority.
  • Knowledge of relevant practices and frameworks such as NIST Secure Software Development Framework, OWASP, OWASP guidance for large language model applications, MITRE ATLAS, CIS Benchmarks, NIST 800-53, SOC 2, and ISO 27001.
  • Application and product security: threat modeling, architecture review, static and dynamic testing, code review, penetration testing, security champions, application programming interface security, and bug bounty or coordinated disclosure.
  • Cloud and infrastructure security: AWS, cloud security posture management, cloud-native application protection, identity and access management, containers, Kubernetes, infrastructure as code, secrets, operating system hardening, and logging.
  • Vulnerability and supply chain security: scanners, risk-based prioritization, dependency and artifact security, software bills of materials, build pipelines, remediation governance, and exception management.
  • AI security: model and data access, prompt injection, agent and tool permissions, retrieval security, output handling, data leakage prevention, red teaming, abuse monitoring, and third-party AI service risk.

Nice To Haves

  • Experience leading managers is preferred.
  • Experience securing large language model, agentic, or retrieval-augmented generation features is strongly preferred.
  • Bachelor's degree in cybersecurity, computer science, engineering, or a related field, or equivalent practical experience.
  • Relevant certification such as CISSP, CISM, GIAC, or an advanced cloud security certification.
  • Experience in a high-growth business-to-business SaaS company and in customer-facing security assurance.

Responsibilities

  • Lead, coach, and develop managers and engineers across the United States and India. Establish role clarity, career paths, succession coverage, and consistent performance expectations.
  • Create an operating cadence that supports asynchronous execution, reliable cross-region handoffs, rapid escalation, and shared accountability.
  • Build workforce and capacity plans aligned to product growth, AI investment, risk, and business priorities.
  • Foster a culture of constructive challenge, disagree and commit, continuous learning, quality, and automation-first improvement.
  • Own the security strategy for AI-enabled product capabilities from design through production, including threat modeling, architecture review, secure development standards, testing, monitoring, and release readiness.
  • Address AI-specific risks such as prompt injection, insecure tool or agent access, sensitive-data exposure, model and data pipeline integrity, excessive agency, abuse, and third-party model or service dependencies.
  • Partner with AI/ML, Product, and Engineering teams to define secure patterns for models, agents, retrieval-augmented generation, application programming interfaces, data access, and human approval controls.
  • Advance product security practices including secure software development lifecycle controls, code and design review, application security testing, penetration testing, security champions, and coordinated vulnerability disclosure or bug bounty.
  • Own end-to-end vulnerability discovery, prioritization, remediation governance, exception management, and validation across applications, cloud infrastructure, containers, endpoints, operating systems, and third-party components.
  • Move beyond severity-only prioritization by incorporating exploitability, internet exposure, asset criticality, data sensitivity, available compensating controls, and active threat intelligence.
  • Improve remediation speed and predictability through automation, clear service-level objectives, transparent ownership, and decision-ready reporting.
  • Establish effective coverage for software supply chain risk, including open-source dependencies, build systems, artifacts, secrets, and continuous integration and delivery pipelines.
  • Own preventive and detective security guardrails for the AWS environment, infrastructure as code, containers, identity and access, network boundaries, workloads, secrets, logging, and data services.
  • Partner with Infrastructure and Platform Engineering to make secure cloud patterns easy to adopt and to reduce reliance on manual review.
  • Drive least privilege, secure administrative access, workload identity, segmentation, configuration assurance, and continuous cloud risk reduction.
  • Ensure architecture and change reviews focus on material risk while preserving engineering velocity.
  • Translate business strategy, product roadmaps, AI priorities, threat trends, customer commitments, and audit requirements into a multi-quarter security engineering roadmap.
  • Define quarterly objectives and key results, key performance indicators, and key risk indicators that show coverage, outcomes, trends, and remaining exposure.
  • Communicate risk and tradeoffs clearly to technical leaders and executives.
  • Escalate material risks with practical options, owners, and recommended decisions.
  • Maintain policies, standards, control evidence, inventories, and operating procedures that support SOC 2, ISO 27001, privacy, customer assurance, and other applicable obligations.
  • Evaluate and rationalize security tools and services based on measurable risk reduction, engineer experience, coverage, integration, and total cost.

Benefits

  • generous health insurance coverage
  • life, and disability insurance
  • a 401K employer matching program
  • paid holidays
  • self-care days
  • paid time off (PTO)
  • paid parental leave
  • stock options
  • equipment and support needed to work and connect with teams
  • access to our LinkedIn Learning platform
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service