thetradedesk
Manager, Security Engineering
At a Glance
- Location
- Bellevue; Seattle
- Experience
- 7+ years
- Posted
- 2026-06-08T15:57:15-04:00
Key Requirements
Required Skills
Certifications
- CISSP
- ISO
Domain Knowledge
- Cybersecurity
- Engineering
- Finance
- Healthcare
- Insurance
- Medical
- Regulatory
- SaaS
Requirements
7+ years of experience in Information Security or Cybersecurity, with hands-on depth in Application Security and/or Platform/Cloud Security.
2+ years of experience leading and developing security engineering teams, including hiring, mentoring, performance management, and roadmap ownership.
Experience driving a measurable security maturity program — defining KPIs, reporting to leadership, and demonstrating posture improvement over time.
Experience building programs that apply industry-standard security best practices and reconcile them against business and engineering needs.
Experience managing a security assessment program — including architecture reviews, secure design reviews, threat models, and code/configuration reviews across many product teams.
Experience building security visibility and engagement programs (e.g., Security Champions, security awareness, training) that scale culture and coverage across the organization.
Compensation & Benefits
here
to learn more.
Responsibilities
Lead, grow, mentor, and develop a combined team of Application Security and Platform Security engineers; drive performance, growth, and retention across the function.
Own and evolve The Trade Desk’s Security Engineering strategy, roadmap, and maturity model across both application and platform domains; define and report KPIs that demonstrate measurable improvement in security posture to senior leadership.
Ensure consistency and alignment across application and platform security controls — driving unified standards, shared tooling, and integrated posture outcomes for the enterprise.
Drive shift-left integration of security into the SDLC in partnership with Engineering and Product — including threat modeling, secure design reviews, and the rollout and tuning of SAST, DAST, and SCA tooling.
Mature TTD’s posture management capabilities across cloud and infrastructure — including CSPM, Infrastructure-as-Code scanning, hardening baselines, and configuration management.
Mature TTD’s vulnerability management and remediation orchestration practices — including triage workflows, risk-based prioritization, SLA tracking, and integration with engineering workflows.