Sr. Manager, Security Engineering

6senseNew York, NY
$204,722 - $254,258Remote

About The Position

This leader owns Vulnerability Operations, Infrastructure Security, and Application/Product Security, and is accountable for building scalable security capabilities that enable rapid product delivery without compromising customer trust, resilience, or compliance. The role leads a distributed team across the United States and India and combines strategic leadership with credible technical judgment. The role's purpose is to lead the security engineering organization that protects 6sense's AI-enabled, cloud-native SaaS platform.

Requirements

  • 8+ years in information security, including significant experience in product or application security, cloud security, vulnerability management, or security engineering.
  • 3+ years leading security engineering teams, including experience managing distributed or cross-region teams. Experience leading managers is preferred.
  • Demonstrated ability to build and mature security programs in a cloud-native SaaS environment, preferably on AWS.
  • Practical experience securing modern software delivery, including secure development lifecycle practices, application security testing, cloud-native infrastructure, containers, infrastructure as code, software supply chain, and vulnerability operations.
  • Working knowledge of AI and machine learning security risks and controls. Experience securing large language model, agentic, or retrieval-augmented generation features is strongly preferred.
  • Ability to evaluate technical risk, make sound tradeoffs, and convert strategy into clear roadmaps, operating mechanisms, and measurable outcomes.
  • Strong executive and technical communication skills, including the ability to explain complex risk in plain language and influence without relying on authority.
  • Knowledge of relevant practices and frameworks such as NIST Secure Software Development Framework, OWASP, OWASP guidance for large language model applications, MITRE ATLAS, CIS Benchmarks, NIST 800-53, SOC 2, and ISO 27001.
  • Application and product security: threat modeling, architecture review, static and dynamic testing, code review, penetration testing, security champions, application programming interface security, and bug bounty or coordinated disclosure.
  • Cloud and infrastructure security: AWS, cloud security posture management, cloud-native application protection, identity and access management, containers, Kubernetes, infrastructure as code, secrets, operating system hardening, and logging.
  • Vulnerability and supply chain security: scanners, risk-based prioritization, dependency and artifact security, software bills of materials, build pipelines, remediation governance, and exception management.
  • AI security: model and data access, prompt injection, agent and tool permissions, retrieval security, output handling, data leakage prevention, red teaming, abuse monitoring, and third-party AI service risk.

Nice To Haves

  • Bachelor's degree in cybersecurity, computer science, engineering, or a related field, or equivalent practical experience.
  • Relevant certification such as CISSP, CISM, GIAC, or an advanced cloud security certification.
  • Experience in a high-growth business-to-business SaaS company and in customer-facing security assurance.

Responsibilities

  • Lead, coach, and develop managers and engineers across the United States and India. Establish role clarity, career paths, succession coverage, and consistent performance expectations.
  • Create an operating cadence that supports asynchronous execution, reliable cross-region handoffs, rapid escalation, and shared accountability.
  • Build workforce and capacity plans aligned to product growth, AI investment, risk, and business priorities.
  • Foster a culture of constructive challenge, disagree and commit, continuous learning, quality, and automation-first improvement.
  • Own the security strategy for AI-enabled product capabilities from design through production, including threat modeling, architecture review, secure development standards, testing, monitoring, and release readiness.
  • Address AI-specific risks such as prompt injection, insecure tool or agent access, sensitive-data exposure, model and data pipeline integrity, excessive agency, abuse, and third-party model or service dependencies.
  • Partner with AI/ML, Product, and Engineering teams to define secure patterns for models, agents, retrieval-augmented generation, application programming interfaces, data access, and human approval controls.
  • Advance product security practices including secure software development lifecycle controls, code and design review, application security testing, penetration testing, security champions, and coordinated vulnerability disclosure or bug bounty.
  • Own end-to-end vulnerability discovery, prioritization, remediation governance, exception management, and validation across applications, cloud infrastructure, containers, endpoints, operating systems, and third-party components.
  • Move beyond severity-only prioritization by incorporating exploitability, internet exposure, asset criticality, data sensitivity, available compensating controls, and active threat intelligence.
  • Improve remediation speed and predictability through automation, clear service-level objectives, transparent ownership, and decision-ready reporting.
  • Establish effective coverage for software supply chain risk, including open-source dependencies, build systems, artifacts, secrets, and continuous integration and delivery pipelines.
  • Own preventive and detective security guardrails for the AWS environment, infrastructure as code, containers, identity and access, network boundaries, workloads, secrets, logging, and data services.
  • Partner with Infrastructure and Platform Engineering to make secure cloud patterns easy to adopt and to reduce reliance on manual review.
  • Drive least privilege, secure administrative access, workload identity, segmentation, configuration assurance, and continuous cloud risk reduction.
  • Ensure architecture and change reviews focus on material risk while preserving engineering velocity.
  • Translate business strategy, product roadmaps, AI priorities, threat trends, customer commitments, and audit requirements into a multi-quarter security engineering roadmap.
  • Define quarterly objectives and key results, key performance indicators, and key risk indicators that show coverage, outcomes, trends, and remaining exposure.
  • Communicate risk and tradeoffs clearly to technical leaders and executives. Escalate material risks with practical options, owners, and recommended decisions.
  • Maintain policies, standards, control evidence, inventories, and operating procedures that support SOC 2, ISO 27001, privacy, customer assurance, and other applicable obligations.
  • Evaluate and rationalize security tools and services based on measurable risk reduction, engineer experience, coverage, integration, and total cost.

Benefits

  • generous health insurance coverage
  • life, and disability insurance
  • 401K employer matching program
  • paid holidays
  • self-care days
  • paid time off (PTO)
  • paid parental leave
  • stock options
  • equipment and support needed to work and connect with teams
  • learning and development initiatives
  • access to LinkedIn Learning platform
  • quarterly wellness education sessions
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service