remotejobopenings

Senior Engineering Manager, Security & IT

Fingerprint · posted 23 days ago

Remote seniorleadredisauditgrowth

Apply on Fingerprint →

At a glance

Location
Remote
Posted
Aug 10, 2026
Auto-expires by
Sep 10, 2026 (if not re-listed at source)

Remote Score for Fingerprint

Fingerprint hasn't been scored yet. Read the rubric at how we score.

About this role (from Fingerprint's posting)

Fingerprint empowers enterprises to detect and stop online fraud with the world’s most accurate device intelligence. We lead our industry with bleeding-edge identification capabilities and work on turning new ideas and discoveries in the fraud detection space into reality. Our customers range from innovative startups to leading enterprise companies, including Plaid, Dropbox, and Booking.com. Fingerprint is a globally dispersed, 100% remote company. We were named on on the 2026 Forbes Best Startup Employers list and ranked #803 on the 2026 Inc. 5000 list of America’s fastest-growing private companies. We have raised $77M and are backed by Craft Ventures (Tesla, Facebook, Airbnb ), Nexus Venture Partners ( Postman, Apollo.io, MinIO, Druva) and Uncorrelated Ventures ( Redis, Rollbar, Gradle). About the Role: Fingerprint's security, IT, and compliance function is more mature than most companies of this size: SOC 2 Type 2 achieved, a comprehensive policy suite in place, and solid IT operations running globally. What the function now needs is strategic leadership: someone who can unify security posture, IT operations, and compliance under a coherent strategy, mature each discipline to the next level, and be the credible voice of security and compliance to the rest of the engineering org and to enterprise customers. We're looking for a Senior Manager, Security & IT to own this function end-to-end, reporting directly to the VP of Engineering. You will manage 4 people across three disciplines: application security, IT operations, and compliance. This is a VP-direct role with high autonomy and high visibility. Enterprise customers — many of whom are financial institutions and large-scale fraud prevention operators — regularly ask about Fingerprint's security posture. You'll be the person who owns that answer. Responsibilties: Unify and mature the function — Security, IT, and compliance have operated as separate workstreams. You create a coherent strategy across all three, with shared standards, shared risk language, and a roadmap that scales with the business Own the security posture — Application security, zero-trust principles, vulnerability management, and security-by-default practices across the engineering org — you set the standard, you hold it, and you work across teams to embed it Scale the compliance program — The next horizon is expanding scope, maturing evidence collection, and positioning Fingerprint for compliance requirements as enterprise deals grow Run reliable IT operations — 100% remote, globally distributed engineering org. IT operations is a critical function that serves every Fingerprint employee. You own the tooling, the processes, and the reliability of those systems Be the security voice to customers and leadership — Enterprise customers, prospects, and partners regularly evaluate Fingerprint's security posture. You represent it credibly, own the security questionnaire process, and communicate risk and posture to the VP and leadership team What You'll Do Security Strategy & Application Security Define and own Fingerprint's application security roadmap: vulnerability management, penetration testing program, security review process for new features and architectural changes Build security-by-default practices into engineering workflows — not as a gate, but as a capability every engineering team has Own the vendor security assessment process — Fingerprint handles sensitive customer data for major enterprise customers; you ensure third parties meet the bar Define zero-trust security principles and ensure they're embedded in the Cloud Platform and engineering org Compliance & GRC Own the SOC 2 Type 2 annual audit cycle — evidence collection, auditor management, control maturation Drive the roadmap for compliance expansion: evaluate and prioritize future frameworks (ISO 27001, GDPR, customer-specific requirements from enterprise deals) Manage the Compliance Lead — support their growth while giving them the leadership context that makes their technical compliance work more impactful Be the compliance voice in enterprise sales cycles — security questionnaires, customer due diligence calls, contractual security requirements Own the policy framework: ensure Fingerprint's policy suite (already well-established) stays current, complete, and actually embedded in how teams work IT Operations Manage the Lead IT Engineer — they run day-to-day IT operations for a globally distributed engineering org; your job is to give them strategic direction and organizational context Own IT strategy: tooling decisions, access management (Okta, SCIM/SAML provisioning), endpoint management, identity governance Ensure IT operations scales with engineering headcount growth — proactive capacity planning, not reactive ticket-handling Define IT security policies and enforce them: device management, access reviews, offboarding rigor Cross-functional Leadership & Communication Proactively communicate security posture, compliance status, and IT health to the VP Engineering — come with recommendations, not status updates Partner with the Cloud Platform Sr. Manager on infrastructure security: network security, IAM standards, security logging and alerting Work with Engineering leadership to embed security practices across product teams — not as a compliance checkpoint but as a capability they value Represent Fingerprint's security and compliance posture to enterprise customers, prospects, and auditors Qualifications: 7+ years in security, IT, or GRC with at least 3 years managing a team — you've led people, made hard calls, and developed practitioners Breadth across the three disciplines: Genuine fluency across application security, IT operations, and compliance/GRC Application security depth: OWASP familiarity, vulnerability management programs (Snyk or equivalent), security review processes for engineering teams — you're credible in a room with senior engineers talking about AppSec IT operations leadership: Identity and access management (Okta or equivalent), endpoint management, remote workforce IT at scale Strategic communicator: You translate security and compliance complexity into business language for leadership and customers — risk framing, not technical jargon Preferred SOC 2 ownership experience: You've run or been the primary owner of a SOC 2 audit cycle — not just participated in one. You understand what good evidence looks like, how to manage auditor relationships, and how to build sustainable control operations vs. annual scramble mode Additional compliance frameworks: ISO 27001, GDPR, experience — particularly relevant given Fingerprint's enterprise customer base in financial services and healthcare Security tooling stack familiarity: Snyk (vulnerability management), Wiz (cloud security posture), Cloudflare (WAF/edge), Okta — these are live in Fingerprint's environment Enterprise security questionnaire experience: You've answered rigorous due diligence questionnaires from financial institution InfoSec teams and know what "good" looks like on both sides of that process Experience in a high-growth SaaS company where security had to keep pace with rapid product and customer growth without becoming a bottleneck The Unique Shape of This Role This role deliberately spans three disciplines that are often separated at larger companies. At Fingerprint's scale, that breadth is a feature, not a bug: the person who owns compliance also owns the security posture that makes compliance meaningful, and the person who owns IT operations also owns the identity and access foundation that security depends on. You won't have the luxury of optimizing one function at the expense of the others. What this means in practice: you need to be comfortable setting direction across domains where your team members have more operational depth than you do. We don't expect you to be the deepest technical expert in AppSec, IT operations, and…

Other open roles at Fingerprint (4)

Apply on Fingerprint →