This one is closed
Live roles like this one
-
B
3h ago
VivSoft Technologies United States $135k - $140k/yr
-
D
3h ago
Ergomed Spain
- C 8h ago
- C 8h ago
See every "Engineering Manager Security" role →
Get new “Engineering Manager Security” roles by email
One email a day with what is new in "Engineering Manager Security". Nothing new, no email.
We confirm the address first, and every mail carries an unsubscribe link. Alerts are ours, not a third party's.
Why this grade This listing scored 54/100, which is a D. It lost the most ground on pay transparency. See the breakdown
- Description depth 20 / 20 How much the posting actually says about the work, measured in characters of real text.
- Remote clarity 15 / 15 Whether "remote" means anywhere, or is quietly restricted to one country.
- Pay transparency 12 / 25 A published salary range, worth more than any other single factor because it is what a candidate cannot find out without applying.
- Corroboration 10 / 10 Whether more than one source carries this listing.
- Freshness 4 / 15 How recently it was posted. Older postings are likelier to be filled or abandoned.
- Role specificity 3 / 10 Whether the listing is tagged well enough to tell what the role actually is.
-10 Ghost-job penalty — Deducted for signals that this posting may not be a real, currently-open role — staleness, repeated relisting, or talent-pool language.
Every figure above is arithmetic over the posting itself — its salary field, its text, its age, its tags and how many sources carry it. How the grades work →
redis
Fingerprint empowers developers to stop online fraud at the source.
We work on turning radical new ideas in the fraud detection space into reality. Our products are developer-focused and our clients range from solo developers to publicly traded companies. We are a globally dispersed, 100% remote company with a strong open-source focus. Our flagship open-source project is FingerprintJS (27K stars on GitHub).
We have raised $77M and are backed by Craft Ventures (previously invested in Tesla, Facebook, Airbnb ), Nexus Venture Partners (previously invested in Postman, Apollo.io, MinIO, Druva) and Uncorrelated Ventures (previously invested in Redis, Rollbar & Gradle).
We have noticed a rise in recruiting impersonations across the industry, where scammers attempt to access candidates' personal and financial information through fake interviews and offers. All Fingerprint recruiting email communications will always come from the @fingerprint.com domain. Any outreach claiming to be from Fingerprint via other sources should be ignored.
The Role in Context
Fingerprint's security, IT, and compliance function is more mature than most companies of this size: SOC 2 Type 2 + HIPAA achieved, a comprehensive policy suite in place, and solid IT operations running globally. What the function now needs is strategic leadership: someone who can unify security posture, IT operations, and compliance under a coherent strategy, mature each discipline to the next level, and be the credible voice of security and compliance to the rest of the engineering org and to enterprise customers.
We're looking for a Senior Manager, Security & IT to own this function end-to-end, reporting directly to the VP of Engineering. You will manage 4 people across three disciplines: application security, IT operations, and compliance.
This is a VP-direct role with high autonomy and high visibility. Enterprise customers — many of whom are financial institutions and large-scale fraud prevention operators — regularly ask about Fingerprint's security posture. You'll be the person who owns that answer.
Your Mission
- Unify and mature the function — Security, IT, and compliance have operated as separate workstreams. You create a coherent strategy across all three, with shared standards, shared risk language, and a roadmap that scales with the business
- Own the security posture — Application security, zero-trust principles, vulnerability management, and security-by-default practices across the engineering org — you set the standard, you hold it, and you work across teams to embed it
- Scale the compliance program — The next horizon is expanding scope, maturing evidence collection, and positioning Fingerprint for compliance requirements as enterprise deals grow
- Run reliable IT operations — 100% remote, globally distributed engineering org. IT operations is a critical function that serves every Fingerprint employee. You own the tooling, the processes, and the reliability of those systems
- Be the security voice to customers and leadership — Enterprise customers, prospects, and partners regularly evaluate Fingerprint's security posture. You represent it credibly, own the security questionnaire process, and communicate risk and posture to the VP and leadership team
What You'll Do
Security Strategy & Application Security
- Define and own Fingerprint's application security roadmap: vulnerability management, penetration testing program, security review process for new features and architectural changes
- Build security-by-default practices into engineering workflows — not as a gate, but as a capability every engineering team has
- Own the vendor security assessment process — Fingerprint handles sensitive customer data for major enterprise customers; you ensure third parties meet the bar
- Define zero-trust security principles and ensure they're embedded in the Cloud Platform and engineering org
Compliance & GRC
- Own the SOC 2 Type 2 annual audit cycle — evidence collection, auditor management, control maturation
- Drive the roadmap for compliance expansion: evaluate and prioritize future frameworks (ISO 27001, GDPR, customer-specific requirements from enterprise deals)
- Manage the Compliance Lead — support their growth while giving them the leadership context that makes their technical compliance work more impactful
- Be the compliance voice in enterprise sales cycles — security questionnaires, customer due diligence calls, contractual security requirements
- Own the policy framework: ensure Fingerprint's policy suite (already well-established) stays current, complete, and actually embedded in how teams work
IT Operations
- Manage the Lead IT Engineer — they run day-to-day IT operations for a globally distributed engineering org; your job is to give them strategic direction and organizational context
- Own IT strategy: tooling decisions, access management (Okta, SCIM/SAML provisioning), endpoint management, identity governance
- Ensure IT operations scales with engineering headcount growth — proactive capacity planning, not reactive ticket-handling
- Define IT security policies and enforce them: device management, access reviews, offboarding rigor
Cross-functional Leadership & Communication
- Proactively communicate security posture, compliance status, and IT health to the VP Engineering — come with recommendations, not status updates
- Partner with the Cloud Platform Sr. Manager on infrastructure security: network security, IAM standards, security logging and alerting
- Work with Engineering leadership to embed security practices across product teams — not as a compliance checkpoint but as a capability they value
- Represent Fingerprint's security and compliance posture to enterprise customers, prospects, and auditors
What We're Looking For
Required
- 7+ years in security, IT, or GRC with at least 3 years managing a team — you've led people, made hard calls, and developed practitioners
- Breadth across the three disciplines: Genuine fluency across application security, IT operations, and compliance/GRC
- Application security depth: OWASP familiarity, vulnerability management programs (Snyk or equivalent), security review processes for engineering teams — you're credible in a room with senior engineers talking about AppSec
- IT operations leadership: Identity and access management (Okta or equivalent), endpoint management, remote workforce IT at scale
- Strategic communicator: You translate security and compliance complexity into business language for leadership and customers — risk framing, not technical jargon
Preferred
- SOC 2 ownership experience: You've run or been the primary owner of a SOC 2 audit cycle — not just participated in one. You understand what good evidence looks like, how to manage auditor relationships, and how to build sustainable control operations vs. annual scramble mode
- Additional compliance frameworks: ISO 27001, GDPR, HIPAA experience — particularly relevant given Fingerprint's enterprise customer base in financial services and healthcare
- Security tooling stack familiarity: Snyk (vulnerability management), Wiz (cloud security posture), Cloudflare (WAF/edge), Okta — these are live in Fingerprint's environment
- Enterprise security questionnaire experience: You've answered rigorous due diligence questionnaires from financial institution InfoSec teams and know what "good" looks like on both sides of that process
- Experience in a high-growth SaaS company where security had to keep pace with rapid product and customer growth without becoming a bottleneck
The Unique Shape of This Role
This role deliberately spans three disciplines that are often separated at larger companies. At Fingerprint's scale, that breadth is a feature, not a bug: the person who owns compliance also owns the security posture that makes compliance meaningful, and the person who owns IT operations also owns the identity and access foundation that security depends on. You won't have the luxury of optimizing one function at the expense of the others.
What this means in practice: you need to be comfortable setting direction across domains where your team members have more operational depth than you do. We don't expect you to be the deepest technical expert in AppSec, IT operations, and GRC simultaneously — your team covers that depth. What we do expect is that you understand each domain well enough to set direction, evaluate the work, and make hard prioritization calls across all three. The judgment to know when to rely on your team vs. when to drive the decision yourself is what distinguishes the right candidate from someone who is simply strong in one area.
This isn't a role for someone who wants to be a player-coach in one discipline. It's a role for someone who has moved past that — who leads through strategy, communication, and people development, not through personal technical execution.
Why This Role?
- VP direct line with genuine autonomy: You own the function. You come to the VP with recommendations, not requests for direction
- A strong team already in place: The Lead IT Engineer and Compliance Lead are capable, experienced practitioners. You're not building from scratch — you're giving them strategic leadership and maturing what they've already built
- High customer visibility: Fingerprint serves major enterprise customers in financial services, fraud prevention, and beyond. Security posture is a real differentiator in enterprise sales, and you're the person who owns it
- Compliance maturity to build on: SOC 2 Type 2 + HIPAA is already achieved. The next horizon — expanded frameworks, deeper enterprise compliance requirements — is yours to define
- A function that's finally getting its own leadership: Security and IT have been embedded in a larger infrastructure group without dedicated management. This role exists because Fingerprint recognizes these functions need focused, strategic leadership to reach the next level
Compensation Range
For US-based employees, the cash compensation range for this role is $177,000 – $240,000. We set standard ranges for all US roles based on function, level, and geographic location, benchmarked against similar stage growth companies. To comply with local legislation and provide greater transparency, we share salary ranges on all job postings. However, these ranges are specific to the hiring location and may differ within or outside the US.
We have noticed a rise in recruiting impersonations across the industry, where scammers attempt to access candidates' personal and financial information through fake interviews and offers. All Fingerprint recruiting email communications will always come from the @fingerprint.com domain. Any outreach claiming to be from Fingerprint via other sources should be ignored.
Offers vary depending on, but not limited to, relevant experience, education, certifications/licenses, skills, training, and market conditions.
Due to regulatory and security reasons, there’s a small number of countries where we cannot have Fingerprint teammates based. Additionally, because Fingerprint is an all-remote company and people can join our workforce from almost any country, we do not sponsor visas. Fingerprint teammates need to be authorized to work from their home location.
We are dedicated to creating an inclusive work environment for everyone. We embrace and celebrate the unique experiences, perspectives and cultural backgrounds that each employee brings to our workplace. Fingerprint strives to foster an environment where our employees feel respected, valued and empowered, and our team members are at the forefront in helping us promote and sustain an inclusive workplace. We highly encourage people from underrepresented groups in tech to apply.
If you are applying as a resident of California, please read our CCPA notice here
If you are applying as a resident of the EU, please read our GDPR notice here
Apply for this role Opens fingerprint.com — verified as the employer's own application page
Quick question · anonymous · one tap
Would you apply to this job?
Answer to see what other job seekers said.
Your turn · no account needed
Help the next applicant
You may know something about this listing that we cannot see from here. One tap. No account needed. Signed-in reports earn points once the evidence agrees with you.
I know what it pays
Sign in with Google to earn points for reports — 100 confirmed points buy a week of Early Access.
Where this listing came from
- 06 Aug 2026 Real Work From Anywhere first sighting
Seen on 1 board over 63 days.