Senior Manager, Enterprise Security Engineering
DoorDashAbout the role
About the Role
We are hiring a hands-on Senior Manager (L7) to lead our Enterprise Security Engineering function. This team builds the security guardrails—baselines, controls, and automated assurance—that make our enterprise secure by design. You will set vision and roadmaps, scale and mentor security engineering teams, and deliver security that is built-in, not bolted on. The work blends strategy and execution: design the playbook, coach leaders and senior engineers, and lean in directly when the stakes are high. Success in this role stems from a deep technical engineering understanding of the enterprise domain and effective cross-functional partnership and collaboration. You will work closely with IT service owners to embed guardrails into enterprise platforms and services, ensuring controls scale with reliability and business enablement. We prioritize crown-jewel systems and data through explicit risk tiering, focusing engineering efforts where they matter most.
You are excited about this opportunity because you will…
- Define and deliver enterprise guardrails. Ship and drive adoption of hardened baselines across identity, endpoints, SaaS, networks, and data; hold SLAs/SLOs and automated attestation for control health and adoption of Zero Trust primitives.
- Advance Zero Trust. Enforce identity-aware access with continuous attestation for device/user signals, micro-segmentation, to adopt user- and machine-bound identities, and enable a hardened VPN-free environment.
- Protect data in motion and at rest. Define and scale data classification and context-aware DLP with least-privilege; enforce managed browsers for session isolation and data egress control; provide safe-by-default paths for AI and collaboration tools.
- Lead SaaS hardening, discovery, and control (with IT). Establish a hardening baseline for sanctioned SaaS applications, continuously monitor for and identify shadow SaaS, and enforce a data-egress policy across the SaaS portfolio using modern, forward-thinking primitives.
- Scale architecture reviews. Drive threat models, trust boundaries, and data-flow/abuse-case reviews; requiring assurance in code (e.g., tests, policy, mTLS/service identity, per-request authorization) for secure-by-default enterprise services.
- Engineer assurance-as-code. Build policy engines and change gates for identity, device, SaaS, and network control planes; enforce posture and identity claims, detect drift, require signed configuration, and fail-safe on non-compliance.
- Oversee secrets hygiene. Detect plaintext secrets in SaaS and on endpoints, block egress with managed browsers, route to approved vaulting, and verify KMS rotation and attestation signals.
- Review third-party and AI integrations. Set pre-production minimums and clearly define exceptions that protect access boundaries and crown-jewel data.
- Strengthen the human edge. Support phishing resilience, managed browsers adoption, and user-centric security controls that reduce risk without friction.
- Harden control gaps. In partnership with Detection and Response, the Red Team, and Leadership, to implement corrective controls, close root causes, and prevent regressions through enforced tests and policy-as-code.
- Deliver measurable impact. Define key control metrics and enterprise control health indicators, publish results, and drive improvements with accountable owners.
We are excited about you because you bring…
- Leadership experience. 10+ years in security or infrastructure; 5+ years managing. Player-coach who sets technical direction, mentors managers and senior engineers, and dives in on the hardest problems.
- Technical depth. Foundation-first security—secure-by-default baselines, least privilege, segmentation, device and identity attestation, and telemetry-backed control health—applied with crown-jewel prioritization and pragmatic managed browsers use to reduce unsanctioned data egress without friction.
- Customer orientation. Make the secure path the easy path by instrumenting adoption and time-to-task, reducing support tickets, and iterating guardrails for clarity and speed.
- Automation-first mindset. Strong orientation toward policy-as-code, infrastructure-as-code, and automated assurance pipelines.
- Execution under pressure. Demonstrated ability to make high-stakes calls with incomplete information and to sequence priorities against risk and business needs.
- Collaboration at scale. History of building durable partnerships with IT, embedd
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s