Security Engineering Manager
About the role
Reporting to the Infrastructure Director of Engineering, you are a pragmatic security leader who acts as a business enabler rather than a gatekeeper. You thrive in a high-velocity, non-regulated environment where you must define "what good looks like" from scratch and drive security progress with a blend of strong planning skills and strong cross-functional partnerships. You are a technical player-coach who manages the "how" behind engineering initiatives, providing direct guidance to a lean team which needs to navigate trade-offs between quality, depth, and delivery volume. You are just as comfortable planning core initiatives as you are writing a proposal for security program improvements. You have a proven track record of leading a team to achieve compliance with a security framework from scratch (e.g., CIS, SOC2, PCI-DSS, ISO27001).
Responsibilities
- Lead and develop a team of security engineers, acting as a technical player-coach to manage deliverables, mentorship, and continuous learning.
- Lead the team through prioritization and tradeoffs to determine which initiatives provide the most meaningful impact.
- Integrate foundational security tooling and automation across corporate, infrastructure, and application layers. Working closely with engineering teams, IT, legal and compliance.
- Develop data-driven security strategies, including OKRs, KPIs, and roadmaps, using clear written communication to advocate for security priorities during cross-functional planning.
- Manage compliance with security frameworks (e.g. CIS, SOC2, GDPR), designing sustainable controls in partnership with internal teams.
- Lead pragmatic incident response efforts, focusing on investigation and resolution while continuously maturing our response plans and threat modeling.
- Develop and implement security strategies for AI and machine learning integrations, ensuring safe adoption while mitigating associated risks.
- Drive cultural change through education, acting as a security evangelist to help cross-functional partners understand risk and own security within their respective domains.
- Govern the Information Security Program, developing high-quality proposals and recommendations that align security decisions with Taskrabbit’s innovative business goals.
Requirements
- 5+ years of experience building and managing security teams in an agile, high-growth environment.
- Proven track record of achieving a security framework from scratch (e.g., taking a company through its first SOC2 or ISO 27001 certification).
- Strong technical "Player-Coach" ability, with the comfort level to dive into technical initiatives and provide direct guidance to security engineers.
- Exceptional written and verbal communication skills, with a knack for telling the "story" of security through formal proposals, strategies, and risk presentations.
- Pragmatic Risk Management: Ability to handle moderate risk tolerance by focusing on business impact and customer trust rather than theoretical perfection.
- Analytical and data-oriented mindset, with experience designing metrics and KPIs that demonstrate the business value of security initiatives.
- Influence-based leadership, showing a history of driving security maturity in non-regulated industries through relationship building and alignment.
- Deep knowledge of modern security practices, including cloud security, access controls, and secure software development, with experience leading incident response.
- Extensive experience working with one or more security frameworks (e.g. CIS, SOC2) and regulatory compliance standards (e.g. GDPR).
- Experience with security governance for AI/ML systems and a proactive approach to managing the risks inherent in emerging technologies.
- Direct experience implementing or leading the implementation of comprehensive security tooling.
Qualifications
- Master's degree in Computer Science, Information Security, or related field.
- CISSP, CISM, or equivalent certifications preferred.
- Experience with security frameworks such as CIS, SOC2, GDPR, and ISO27001.
- Experience with security tooling implementation.
Skills
- Strong problem-solving and analytical skills.
- Excellent communication and interpersonal skills.
- Ability to work independently and as part of a team.
- Experience with Agile methodologies.
- Knowledge of cloud security principles and practices.
Benefits
At Taskrabbit, our approach to compensation is designed to be competitive, transparent, and equitable. Total compensation consists of base pay + bonus + benefits + perks. The base pay range for this position is $155,000 - $207,000. This range is representative of base pay only, and does not include any other total cash compensation amounts, such as company bonus or benefits. Final offer amounts may vary from the amounts listed above and will be determined by factors including, but not limited to, relevant experience, qualifications, geography, and level.
Pay
The base pay range for this position is $155,000 - $207,000.
Schedule
This role operates on a hybrid schedule requiring two days of in-office collaboration per week.