Skip to main content
Back to jobs

Manager, Enterprise Security

External
turo logoTuro · San Francisco
$184K–$230K/yrFull-timeHybrid3w ago
AWSComplianceIncident ResponseInformation SecurityLeadershipMentoring
Cover LetterConnect

Prepare for this interview

Elite

AI-generated questions, company research, and talking points tailored to this role


About the role

Turo is searching for a highly motivated and strategic Manager, Enterprise Security to lead and mentor a team of Security Engineers in securing enterprise systems and data through the definition, execution, and continuous improvement of a comprehensive security framework. This role will focus heavily on advancing the Zero Trust principles across the organization, ensuring the integrity of our systems and protecting against emerging threats. Key areas of focus include Advanced Email Security, Data Loss Prevention (DLP), Insider Threat prevention, Endpoint Security, Identity and Access Governance, Security Awareness Training, Configuration management and Infrastructure as Code, Incident Response (SOAR automation), Regulatory Compliance and SaaS Security Posture. The successful candidate will provide strategic direction and technical leadership for these domains, anticipating and mitigating potential threats and ensuring regulatory compliance.

Responsibilities

  • Provide technical and strategic leadership for the Enterprise Security team, managing, mentoring, and supporting the career development of team members.
  • Define the strategy and oversee the implementation of Zero Trust security frameworks across the enterprise, focusing on continuous verification and least privilege access models.
  • Direct the development and management of Advanced Email Security, Data Loss Prevention (DLP), Insider Threat prevention, and Endpoint Security solutions.
  • Collaborate with the Identity and Access Governance teams to define policy and ensure secure and efficient access control policies are enforced.
  • Lead efforts to ensure ongoing compliance with SOX and SOC 2 standards, including performing regular audits and gap assessments.
  • Direct the delivery of Security Awareness Training programs and security phishing campaigns to educate employees.
  • Drive the adoption and deployment of Infrastructure as Code to automate security configurations and infrastructure, specifically using Terraform.
  • Manage and lead Incident Response efforts (including automation playbooks and SOC collaboration) and identify, assess, and mitigate security risks to protect Turo's assets.
  • Establish a robust SaaS Security Posture and collaborate with cross-functional teams to integrate security into all stages of the Software Development Life Cycle (SDLC).
  • Lead the annual penetration testing and annual security tabletop exercise.
  • Your profile
  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
  • 10+ years of experience in enterprise security, focusing on Zero Trust architecture, Advanced Email Security, DLP, Endpoint Security (e.g., Crowdstrike), and Infrastructure as Code/configuration management (e.g., Terraform).
  • 2+ years of experience managing or leading a team of security engineers, with a demonstrated ability to provide leadership, guidance, and motivation.
  • Strong knowledge of identity governance frameworks (e.g., Okta, Sailpoint), SaaS security, compliance (SOX/SOC 2), and experience with Incident Response and advanced threat detection methodologies (SOAR tools like Tines preferred).
  • Proficiency in scripting and automating security processes using Python, PowerShell, or similar languages, with a passion for building tooling from the ground up.
  • Experience working on cloud infrastructure, especially AWS and its Security services suite, with a solid understanding of containerized environments and familiarity with GitOps flow.
  • Strong presentation, facilitation, and written/verbal communication skills, with the capability to interface with multiple levels of the organization and serve as an influencer.
  • Industry certifications such as CISSP, CISM, CEH, or GIAC are a plus.
  • Turo Recruiting Scam Alert:
  • We've learned that there are scammers targeting job candidates by impersonating Turo and its employees. We ask candidates to be careful of fraudulent job postings or suspicious recruiting activity during their job search, especially if they're contacted thro

Benefits

Equity / stock options

Your Match

How well this role fits your profile.

Company Intel

What employees say

Worked at turo? Share your experience

Interested in this role?

Apply on the company's website.

Cover LetterConnect