Skip to main content
Fingerprint

Senior Engineering Manager, Security & IT

RemoteWorldwide
Published
Role
Security
Experience
Senior
Company size
Startup
$177k–$240k/yr
Check eligibility

Open to Worldwide. Set where you work from to check your eligibility.

No BS summary

Senior security/IT/GRC manager with 7+ years across security, IT or GRC and 3+ years managing teams. Needs real breadth in AppSec, IT operations, compliance/GRC, OWASP, vulnerability management, IAM and remote workforce IT. Must be authorized to work from their home location; Fingerprint does not sponsor visas.

Core skills

Application SecurityGRCIdentity and Access Management

Required skills

OWASPSnykOkta

Optional skills

SOC 2ISO 27001GDPRHIPAASnykWizCloudflareOkta

What you'll do

  • Unify and mature Security, IT, and compliance under a coherent strategy with shared standards, shared risk language, and a roadmap that scales with the business.
  • Own the security posture across application security, zero-trust principles, vulnerability management, and security-by-default practices across the engineering org.
  • Scale the compliance program by expanding scope, maturing evidence collection, and positioning Fingerprint for compliance requirements as enterprise deals grow.
  • Run reliable IT operations for a 100% remote, globally distributed engineering org, owning tooling, processes, and system reliability.
  • Be the security voice to customers and leadership, representing Fingerprint's security posture, owning the security questionnaire process, and communicating risk and posture to the VP and leadership team.
  • Define and own Fingerprint's application security roadmap: vulnerability management, penetration testing program, and security review process for new features and architectural changes.
  • Build security-by-default practices into engineering workflows as a capability every engineering team has.
  • Own the vendor security assessment process and ensure third parties meet the bar.
  • Define zero-trust security principles and ensure they're embedded in the Cloud Platform and engineering org.
  • Own the SOC 2 Type 2 annual audit cycle, including evidence collection, auditor management, and control maturation.
  • Drive the roadmap for compliance expansion by evaluating and prioritizing future frameworks such as ISO 27001, GDPR, and customer-specific enterprise requirements.
  • Manage the Compliance Lead, support their growth, and give them leadership context for more impactful technical compliance work.
  • Be the compliance voice in enterprise sales cycles, including security questionnaires, customer due diligence calls, and contractual security requirements.
  • Own the policy framework and ensure Fingerprint's policy suite stays current, complete, and embedded in how teams work.
  • Manage the Lead IT Engineer, giving them strategic direction and organizational context for day-to-day IT operations.
  • Own IT strategy, including tooling decisions, access management, Okta, SCIM/SAML provisioning, endpoint management, and identity governance.
  • Ensure IT operations scales with engineering headcount growth through proactive capacity planning.
  • Define IT security policies and enforce them, including device management, access reviews, and offboarding rigor.
  • Proactively communicate security posture, compliance status, and IT health to the VP Engineering with recommendations.
  • Partner with the Cloud Platform Sr. Manager on infrastructure security, including network security, IAM standards, security logging, and alerting.
  • Work with Engineering leadership to embed security practices across product teams as a valued capability.
  • Represent Fingerprint's security and compliance posture to enterprise customers, prospects, and auditors.
  • Manage 4 people across application security, IT operations, and compliance.

What they require

  • 7+ years in security, IT, or GRC with at least 3 years managing a team — you've led people, made hard calls, and developed practitioners.
  • Breadth across the three disciplines: genuine fluency across application security, IT operations, and compliance/GRC.
  • Application security depth: OWASP familiarity, vulnerability management programs (Snyk or equivalent), security review processes for engineering teams — you're credible in a room with senior engineers talking about AppSec.
  • IT operations leadership: identity and access management (Okta or equivalent), endpoint management, remote workforce IT at scale.
  • Strategic communicator: you translate security and compliance complexity into business language for leadership and customers — risk framing, not technical jargon.
  • Comfortable setting direction across domains where team members have more operational depth than you do.
  • Understand AppSec, IT operations, and GRC well enough to set direction, evaluate the work, and make hard prioritization calls across all three.
  • Lead through strategy, communication, and people development, not through personal technical execution.
  • Fingerprint teammates need to be authorized to work from their home location.
  • Preferred: SOC 2 ownership experience: you've run or been the primary owner of a SOC 2 audit cycle — not just participated in one.
  • Preferred: You understand what good evidence looks like, how to manage auditor relationships, and how to build sustainable control operations vs. annual scramble mode.
  • Preferred: Additional compliance frameworks: ISO 27001, GDPR, HIPAA experience — particularly relevant given Fingerprint's enterprise customer base in financial services and healthcare.
  • Preferred: Security tooling stack familiarity: Snyk, Wiz, Cloudflare, Okta — these are live in Fingerprint's environment.
  • Preferred: Enterprise security questionnaire experience: you've answered rigorous due diligence questionnaires from financial institution InfoSec teams and know what "good" looks like on both sides of that process.
  • Preferred: Experience in a high-growth SaaS company where security had to keep pace with rapid product and customer growth without becoming a bottleneck.

Benefits

  • VP direct line with genuine autonomy: you own the function and come to the VP with recommendations.
  • A strong team already in place: the Lead IT Engineer and Compliance Lead are capable, experienced practitioners.
  • High customer visibility with major enterprise customers in financial services, fraud prevention, and beyond.
  • Compliance maturity to build on: SOC 2 Type 2 + HIPAA is already achieved.
  • A function that's finally getting its own leadership with focused, strategic leadership to reach the next level.
  • Globally dispersed, 100% remote company.

Fingerprint empowers developers to stop online fraud at the source. Globally dispersed, 100% remote company focused on fraud detection with open-source emphasis.

TechnologyStartup

Details

Visa sponsorshipNo
$177k–$240k/yr