Manager, Security Engineering
$225k - $325k • United States • FullTime
Posted 2mo ago
About the job
Cohere is a leading enterprise AI company focused on building cutting-edge foundation AI models and end-to-end products. We are seeking a Manager of Security Engineering to lead and grow a high-performing team, executing the long-term vision for security in alignment with Cohere's product and business goals. This role involves serving as a trusted advisor to leadership, articulating business risks, and prioritizing high-impact initiatives. You will be instrumental in the widespread adoption of AI by ensuring robust security practices across the organization.
Responsibilities
- Serve as a trusted advisor to leadership and partner teams, articulating business risks associated with security issues.
- Execute the long-term vision for the Security team, aligning with Cohere's product and business goals.
- Collaborate with leadership to prioritize high-impact initiatives and strategic customer engagements.
- Develop and implement enterprise-wide vulnerability management processes and tooling.
- Establish SAST programs, integrate tools into CI/CD pipelines, and analyze results to identify and remediate security flaws.
- Implement DAST methodologies, configure scanning tools, and conduct regular assessments of running applications.
- Lead and oversee internal and external penetration testing engagements, including web application, API, network, and agentic AI platform, and manage the bug bounty program.
- Collaborate with development teams to review and validate security architecture and design patterns.
- Embed security practices throughout the software development lifecycle.
- Lead and grow a high-performing team of Security engineers through hiring, coaching, and mentorship.
- Establish key security metrics, generate regular reports for leadership, and communicate security posture to stakeholders.
- Ensure application security practices align with industry standards (OWASP Top10 for LLMs, ISO 27001) and regulatory requirements.
Requirements
- 8+ years of experience in Application Security / Security Engineering with a strong focus on vulnerability management, SDLC, and bug bounty programs.
- Proven experience with SAST, DAST, and penetration testing methodologies and tools.
- Proficiency with programming languages (Python, GoLang, etc.) and web technologies.
- Experience with cloud platforms (AWS, GCP, Azure) and container security.
- Excellent communication and interpersonal skills with the ability to influence technical and non-technical stakeholders.
- Experience building and managing high-performing security teams.
- Comfort with ambiguity and ability to make informed decisions with limited data.
- Flexible and constructive approach to problem-solving.
- Ability to make trade-offs between build vs. buy decisions and review available tools.
- Deep technical understanding of common security vulnerabilities, risks, countermeasures, and compensating controls.
Benefits
- Weekly lunch stipend of $75/£75 or equivalent.
- Full health and dental benefits, including a separate budget for mental health.
- RRSP matching, 401K, Pension Scheme.
- 100% Parental Leave top-up for up to 6 months.
- Annual enrichment benefits (Arts & culture, fitness/wellness, quality time, workspace improvement).
- Education & learning stipend for conferences, courses, and coaching.
- 6 weeks of paid vacation (30 working days).
- Budget for traveling to other offices if remote.
- Annual company offsite.
- Co-working benefit for those not near an office.
- $500 home office stipend.