Contentful is a leading digital experience platform that helps modern businesses meet the growing demand for engaging, personalized content at scale. They are seeking a committed and driven manager to own security engineering across corporate systems, balancing people leadership with hands-on technical execution.
Responsibilities:
- Develop a team, providing coaching, mentorship, goal setting, and performance feedback
- Define roles and make hiring decisions to grow the team in line with department needs
- Remain hands on, balancing technical leadership with direct implementation work
- Own execution and prioritization across projects and operations, using agile delivery practices
- Scale and mature effectiveness and efficiency by improving processes and tooling
- Champion continuous improvement across all aspects of the security program
- Continuously improve effectiveness and efficiency by evolving processes and tooling
- Communicate risks and technical concepts with clarity to leadership and stakeholders
- Collaborate with security leadership to execute business aligned, risk reduction roadmaps
- Shape work scope, sequencing, and success criteria inline with department and company needs
- Drive security processes, standards, and best practices across information technology assets
- Partner with stakeholders to evolve security awareness and specialized training across all functions
- Mature capabilities across endpoint, SaaS, and cloud configuration
- Own strategy evolution of corporate capabilities, including configuration, IAM, and data security
- Enhance tooling, automation, and integrations to improve visibility and reduce manual effort
- Support and guide security incident response efforts as a technical leader
- Support cross functional vulnerability management while advancing the program capabilities
- Define and maintain metrics to measure impact, optimize execution, and guide investment
- Partner with cross-functional teams for security enhancement and drive risk reduction
- Accelerate adoption of AI, balancing practicality enablement, and risk management
- Stay current on threats, vulnerabilities, and tactics, translating insights into actionable strategies
Requirements:
- 8+ years of progressive engineering and security experience
- 3+ years managing people and security engineering teams
- Comfort operating in ambiguity, balancing strategic thinking, security, and practicality
- Expertise with AWS, GCP, and Azure
- Strong hands-on experience designing, implementing, and operating security controls at scale
- Demonstrated experience securing endpoint, SaaS, and cloud environments
- Experience working within identity and access management and data security programs
- Software development experience in modern programming language (Python, Go, etc)
- Hands-on experience using Terraform and infrastructure-as-code
- Experience applying modern practices to improve efficiency and scalability or security programs
- Passion for solving complex security problems in innovative and scalable ways
- Experience using metrics to measure impact, optimize execution, and guide investment decisions
- Strong communication skills with the ability to explain technical topics to non technical audiences
- Ability to support occasional off-hours incident response efforts
- Familiarity with attacker techniques in cloud-native and traditional environments
- Hands-on experience owning security technologies (e.g., EDR, AntiVirus, etc.)
- Proven ability to lead cross-functional initiatives and influence outcomes without direct authority
- Experience owning end to end security programs, proactively driving incremental improvement
- Strong systems thinking, with the ability to design security solutions that scale through efficiency