Cohere is on a mission to scale intelligence to serve humanity by training and deploying frontier models for developers and enterprises. The Manager of Security Engineering will oversee security initiatives, manage vulnerability processes, and lead a high-performing team to ensure application security aligns with industry standards.
Responsibilities:
- Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues
- Execute the long-term vision for the Security team in alignment with Cohere’s product and business goals
- Collaborate closely with leadership to prioritize high-impact initiatives and strategic customer engagements
- Vulnerability Management: Develop and implement enterprise-wide vulnerability management processes and tooling, including identification, prioritization, remediation tracking, and reporting, including customer artifacts
- Static Application Security Testing (SAST): Establish SAST programs, integrate tools into CI/CD pipelines, and analyze results to identify and remediate security flaws in source code
- Dynamic Application Security Testing (DAST): Implement DAST methodologies, configure scanning tools, and conduct regular assessments of running applications
- Penetration Testing: Lead and oversee internal and external penetration testing engagements, including web application, API, network and agentic AI platform including managing our bug bounty program
- Security Architecture Review: Collaborate with development teams to review and validate security architecture and design patterns
- Secure SDLC Integration: Embed security practices throughout the software development lifecycle, working closely with engineering and product teams
- Team Leadership: Lead and grow a high-performing team of Security engineers through hiring, coaching, and mentorship
- Metrics and Reporting: Establish key security metrics, generate regular reports for leadership, and communicate security posture to stakeholders
- Compliance and Standards: Ensure application security practices align with industry standards (OWASP Top10 for LLMs, ISO 27001) and regulatory requirements
Requirements:
- 8+ years of previous experience in Application Security / Security Engineering with a strong focus on vulnerability management, SDLC and bug bounty programs
- Proven experience with SAST, DAST, and penetration testing methodologies and tools
- Proficiency with programming languages (Python, GoLang, etc.) and web technologies
- Experience with cloud platforms (AWS, GCP, Azure) and container security
- Excellent communication and interpersonal skills with ability to influence technical and non-technical stakeholders
- Experience building and managing high-performing security teams
- You are comfortable with ambiguity and are able to make informed decisions with little data
- You employ a flexible and constructive approach when solving problems
- You are able to make trade-offs between build vs. buy decisions—help build solutions and be able to review what tools are available
- You understand secure engineering best practices, can articulate problem statements, and propose solutions to both technically savvy and non-technical audiences
- You have a deep technical understanding of common security vulnerabilities and risks, as well as countermeasures and compensating controls