You and the process

With a person
Anna, in-house recruiter
9 years hiring engineers
30 minutes with a real recruiter
They read your CV with you, on a call, and say where the offers are being lost.
Didn’t find what you were looking for? Tell us what to build
Be the first to open itNo views yet
6sense

Sr. Manager, Security Engineering

  • Remote
  • 6+ years

Salary

$204,721/ year

AI summary

For members

The whole posting in a few lines. Sign up to read it here and on every role you open.

Sign Up to Read

Description

Our Mission:

6sense's mission is to multiply what matters: growth, retention, and efficiency. We envision a future where companies, teams and people reach their full potential.

Our People:

People are the heart and soul of 6sense. We serve with passion and purpose. We live by our Being 6sense values of Win as One Team, Stay Curious, Do The Right Thing, Own the Outcome, and Create Belonging. Every 6sensor plays a part in defining the future of our industry-leading technology. 6sense is a place where difference-makers roll up their sleeves, take risks, act with integrity, and measure success by the value we create for our customers. We want 6sense to be the best chapter of your career.

Senior Manager, Security Engineering

Business Technology, Security

REPORTING AREA

Security - CISO

FUNCTION

Business Technology

TEAM MODEL

United States and India

LEADERSHIP SCOPE

Application/Product Security; Infrastructure/Cloud Security; Vulnerability Management

ROLE TYPE

Leader with technical depth

ENVIRONMENT

AI-first, cloud-native SaaS

Role Purpose

Lead the security engineering organization that protects 6sense's AI-enabled, cloud-native SaaS platform. This leader owns Vulnerability Operations, Infrastructure Security, and Application/Product Security, and is accountable for building scalable security capabilities that enable rapid product delivery without compromising customer trust, resilience, or compliance. The role leads a distributed team across the United States and India and combines strategic leadership with credible technical judgment.

Leadership Mandate

Build one integrated security engineering operating model across the three teams, with clear ownership, service expectations, priorities, and measurable outcomes.

Partner with Product, Engineering, Cloud Infrastructure, Data, AI/ML, Security Operations, Privacy, GRC, and Enterprise Technology leaders to embed security into planning and delivery.

Create an inclusive, high-accountability culture across time zones using clear decisions, durable documentation, effective handoffs, and intentional overlap for critical work.

Balance hands-on technical engagement with people leadership, program ownership, stakeholder influence, and executive-level risk communication.

Core Responsibilities

Organization and People Leadership

Lead, coach, and develop managers and engineers across the United States and India. Establish role clarity, career paths, succession coverage, and consistent performance expectations.

Create an operating cadence that supports asynchronous execution, reliable cross-region handoffs, rapid escalation, and shared accountability.

Build workforce and capacity plans aligned to product growth, AI investment, risk, and business priorities.

Foster a culture of constructive challenge, disagree and commit, continuous learning, quality, and automation-first improvement.

AI and Product Security

Own the security strategy for AI-enabled product capabilities from design through production, including threat modeling, architecture review, secure development standards, testing, monitoring, and release readiness.

Address AI-specific risks such as prompt injection, insecure tool or agent access, sensitive-data exposure, model and data pipeline integrity, excessive agency, abuse, and third-party model or service dependencies.

Partner with AI/ML, Product, and Engineering teams to define secure patterns for models, agents, retrieval-augmented generation, application programming interfaces, data access, and human approval controls.

Advance product security practices including secure software development lifecycle controls, code and design review, application security testing, penetration testing, security champions, and coordinated vulnerability disclosure or bug bounty.

Vulnerability Operations

Own end-to-end vulnerability discovery, prioritization, remediation governance, exception management, and validation across applications, cloud infrastructure, containers, endpoints, operating systems, and third-party components.

Move beyond severity-only prioritization by incorporating exploitability, internet exposure, asset criticality, data sensitivity, available compensating controls, and active threat intelligence.

Improve remediation speed and predictability through automation, clear service-level objectives, transparent ownership, and decision-ready reporting.

Establish effective coverage for software supply chain risk, including open-source dependencies, build systems, artifacts, secrets, and continuous integration and delivery pipelines.

Infrastructure and Cloud Security

Own preventive and detective security guardrails for the AWS environment, infrastructure as code, containers, identity and access, network boundaries, workloads, secrets, logging, and data services.

Partner with Infrastructure and Platform Engineering to make secure cloud patterns easy to adopt and to reduce reliance on manual review.

Drive least privilege, secure administrative access, workload identity, segmentation, configuration assurance, and continuous cloud risk reduction.

Ensure architecture and change reviews focus on material risk while preserving engineering velocity.

Strategy, Governance, and Business Partnership

Translate business strategy, product roadmaps, AI priorities, threat trends, customer commitments, and audit requirements into a multi-quarter security engineering roadmap.

Define quarterly objectives and key results, key performance indicators, and key risk indicators that show coverage, outcomes, trends, and remaining exposure.

Communicate risk and tradeoffs clearly to technical leaders and executives. Escalate material risks with practical options, owners, and recommended decisions.

Maintain policies, standards, control evidence, inventories, and operating procedures that support SOC 2, ISO 27001, privacy, customer assurance, and other applicable obligations.

Evaluate and rationalize security tools and services based on measurable risk reduction, engineer experience, coverage, integration, and total cost.

Success Measures

Success will be measured by outcomes and sustained operating health, not activity volume alone:

Risk reduction

Material vulnerabilities and security design risks are identified early, prioritized consistently, and remediated or formally accepted within defined objectives.

Coverage

Security controls and testing provide measurable coverage across product code, AI features, cloud infrastructure, containers, identities, dependencies, and critical data paths.

Engineering velocity

Approved secure patterns, automation, and self-service controls reduce security friction and late-stage rework.

AI security readiness

AI features have repeatable security requirements, threat models, tests, release criteria, monitoring, and documented residual risk.

Operational maturity

The three teams operate with clear ownership, reliable cross-region handoffs, actionable metrics, current documentation, and effective escalation.

People and leadership

The organization demonstrates strong engagement, skill growth, succession depth, retention, and accountable delivery across locations.

Stakeholder trust

Product, Engineering, Infrastructure, and executive partners receive timely, clear, decision-ready security guidance and reporting.

Required Experience and Capabilities

8+ years in information security, including significant experience in product or application security, cloud security, vulnerability management, or security engineering.

3+ years leading security engineering teams, including experience managing distributed or cross-region teams. Experience leading managers is preferred.

Demonstrated ability to build and mature security programs in a cloud-native SaaS environment, preferably on AWS.

Practical experience securing modern software delivery, including secure development lifecycle practices, application security testing, cloud-native infrastructure, containers, infrastructure as code, software supply chain, and vulnerability operations.

Working knowledge of AI and machine learning security risks and controls. Experience securing large language model, agentic, or retrieval-augmented generation features is strongly preferred.

Ability to evaluate technical risk, make sound tradeoffs, and convert strategy into clear roadmaps, operating mechanisms, and measurable outcomes.

Strong executive and technical communication skills, including the ability to explain complex risk in plain language and influence without relying on authority.

Knowledge of relevant practices and frameworks such as NIST Secure Software Development Framework, OWASP, OWASP guidance for large language model applications, MITRE ATLAS, CIS Benchmarks, NIST 800-53, SOC 2, and ISO 27001.

Technical Domain Familiarity

Application and product security: threat modeling, architecture review, static and dynamic testing, code review, penetration testing, security champions, application programming interface security, and bug bounty or coordinated disclosure.

Cloud and infrastructure security: AWS, cloud security posture management, cloud-native application protection, identity and access management, containers, Kubernetes, infrastructure as code, secrets, operating system hardening, and logging.

Vulnerability and supply chain security: scanners, risk-based prioritization, dependency and artifact security, software bills of materials, build pipelines, remediation governance, and exception management.

AI security: model and data access, prompt injection, agent and tool permissions, retrieval security, output handling, data leakage prevention, red teaming, abuse monitoring, and third-party AI service risk.

Preferred Qualifications

Bachelor's degree in cybersecurity, computer science, engineering, or a related field, or equivalent practical experience.

Relevant certification such as CISSP, CISM, GIAC, or an advanced cloud security certification.

Experience in a high-growth business-to-business SaaS company and in customer-facing security assurance.

Leadership Behaviors

Leads with clarity, trust, accountability, and sound judgment.

Develops people and creates space for strong technical leaders to lead.

Prioritizes based on business impact and risk, not noise or tool output.

Communicates early, directly, and in plain language.

Uses data to guide decisions while recognizing where judgment is required.

Challenges constructively, commits to decisions, and follows through.

Stays current on modern threats affecting cloud-native SaaS and AI-enabled products.

Base Salary Range: $204,721.50 - $254,258.20. The base salary range represents the anticipated low and high end of the base salary range for this position. Actual salaries may vary and may be above or below the range based on various factors, including but not limited to work location and experience. The base salary is one component of 6sense’s total compensation package for this position. Other compensation may include a bonus program or commission plan, and stock options if approved by 6sense’s board. In addition, 6sense provides a variety of benefits, including generous health insurance coverage, life, and disability insurance, a 401K employer matching program, paid holidays, self-care days, and paid time off (PTO). Li-remote

Our Benefits:

Full-time employees can take advantage of health coverage, paid parental leave, generous paid time-off and holidays, quarterly self-care days off, and stock options. We’ll make sure you have the equipment and support you need to work and connect with your teams, at home or in one of our offices.

We have a growth mindset culture that is represented in all that we do, from onboarding through to numerous learning and development initiatives including access to our LinkedIn Learning platform. Employee well-being is also top of mind for us. We host quarterly wellness education sessions to encourage self care and personal growth. From wellness days to ERG-hosted events, we celebrate and energize all 6sense employees and their backgrounds.

Where you’d work

Fully remote

You can work from

  • United States

About the company

6sense

  • Industry: SaaS

Also hiring in San Francisco, United States

3 of their 3 open roles are remote

Your chances

Worth a look before you spend an evening tailoring a CV for it.

  • 21 checks run
  • 3 red flags

Still hiring?

14 checks

2 red flags

How crowded?

7 checks

1 red flag

Fits Me

How well does this role fit you?

Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.

  • Your field
  • Level
  • Stack
  • Work model
  • Salary floor
  • Must-haves
Details13 facts · Role, Location, Compensation, Employment, Company
Tech stack
  • AWS
  • Kubernetes
  • CI/CD
Seniority
Senior
Type
Full-time
Equity
Equity offered
Industry
SaaS
Specialty
Security
Show 7 more factsShow less

Role

Category
DevOps & Infrastructure
Specialty
Security
Seniority
Senior
Experience
8+ years
Tech stack
  • AWS
  • Kubernetes
  • CI/CD

Location

Work model
Remote
Region
United States
Remote from
  • United States

Compensation

Salary
$204,721 / year
Pay period
Annual
Equity
Equity offered

Employment

Type
Full-time

Company

Industry
SaaS

Something wrong with this vacancy?

Similar vacancies

  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer, New Grad

    Salary by agreement

    • Office · Dublin
    • Junior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Senior Security Operations Analyst

    Salary by agreement

    • Hybrid · Wellington, Auckland
    • Senior
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Platform Security Engineer

    £90,000 - 160,000 / year

    • Hybrid · London
    • Mid-Level
  • Early Window: Be the first to open itNo views yetCloses in
    Company hidden

    Security Engineer

    $275,000 - 345,000 / year

    • Office · London

Share this vacancy

What's wrong with it?

The employer never sees who reported.

Reason