Manhattan designs, builds and delivers market-leading supply chain technology solutions for leading companies around the world. We help drive the commerce revolution with unmatched insight and unrivaled technology, connecting front-end revenue and relationships with back-end execution and efficiency—optimized on a common technology platform. This platform-based approach is enabling leading companies across the globe to Push Possible® by getting closer to customers and achieving real-world results.
The Senior Security Engineer is responsible for architecting, designing, and continuously improving security across Manhattan’s multi-cloud environment. This role combines deep expertise in cloud security architecture, software engineering, automation, and cyber risk management across Google Cloud, Microsoft Azure, AWS, and Oracle Cloud with strategic leadership to protect the confidentiality, integrity, and availability of cloud-based systems and services. The Senior Security Engineer will build cloud-native security solutions and tooling, manage and enhance the CNAPP platform, guide vulnerability remediation and security controls, lead cross-functional security initiatives, and champion secure, scalable, and resilient cloud capabilities across the organization.
Job Summary
- Bring 7+ years of IT experience, 5+ years of security experience, 4+ years of hands-on multi-cloud experience, and 3+ years each in scripting/programming and cloud vulnerability remediation.
- Hold a bachelor’s degree in information systems, Computer Science, or comparable experience. CISSP and cloud-security certifications are preferred; ability to handle confidential information and pass a US federal government background investigation is required.
- Lead the architecture, design, and continuous improvement of security across Google Cloud, Microsoft Azure, AWS, and Oracle Cloud, protecting the confidentiality, integrity, and availability of cloud services.
- Build cloud-native security solutions, automation tooling, and scalable security controls from the ground up using hands-on coding and software engineering expertise.
- Manage and continuously enhance the Cloud-Native Application Protection Platform (CNAPP) to advance enterprise cloud-security objectives.
- Assess cyber risks, identify and remediate cloud vulnerabilities and security gaps, and guide improvements to multi-cloud services, configurations, and controls.
- Apply strong knowledge of cloud networking, identity and access management, encryption fundamentals, secure configuration standards, and recognized security practices.
- Work with containerization and orchestration technologies such as Docker, Kubernetes, ECS, GKE, and AKS, plus infrastructure-as-code and policy-as-code tools including Terraform, CloudFormation, and OPA.
- Lead security initiative planning and produce clear documentation for architecture, design decisions, security improvements, and major incidents for technical and executive audiences.
- Collaborate across teams to deliver security projects from concept through completion, contribute to cloud-security standards, and provide practical design recommendations.
- Monitor emerging cloud-security trends, translate them into actionable recommendations for leadership, and demonstrate independent troubleshooting, prioritization, attention to detail, and a strong security mindset.
Key Responsibilities
- Security Standards Enforcement: Ensure multi-cloud infrastructure designs and configurations comply with defined security standards.
- Information Protection: Build controls that protect client, company, and employee information across multi-cloud environments.
- Cyber-Risk Hardening: Review cyber risks, identify remediation gaps, and guide actions to harden multi-cloud environments.
- Architecture Change Recommendations: Recommend design changes across multi-cloud environments, services, and configurations.
- Cloud Security SME: Serve as a subject matter expert on platform and architecture security across cloud environments.
- Security Standards Stewardship: Participate in setting, maintaining, and improving cloud security standards.
- Control Framework Knowledge: Understand NIST, CIS Benchmarks, and ISO 27001 controls.
- Business-Aware Security Decisions: Understand the business impact and critical needs of IT services when prioritizing security improvements.
- Independent Delivery Discipline: Manage tasks independently, ...
- Continuous Learning and Security Advocacy: Stay current with security best practices and promote security awareness throughout the organization.