ForgeApply · Job listing
Senior Engineering Manager, Security
Imprint
Tailor your resume for this Imprint job in about a minute.
ForgeApply rewrites your resume for this exact posting, then autofills the application on Imprint's site with it. You review everything before it's sent. Free trial, no card required.
About this role
WHO WE ARE
Imprint helps the world's best brands grow the lifetime value of their customers. We started with co-branded credit cards and rebuilt them to be smarter, more rewarding, and brand-first. We partner with companies like Crate & Barrel, Rakuten, Booking.com http://Booking.com, H-E-B, Fetch, and Shell to launch modern credit programs that deepen loyalty, unlock savings, and drive growth. But the card is just the beginning. We combine advanced payments infrastructure, intelligent underwriting, and deep customer data to create delightful and personalized experiences for members as well as efficient and profitable relationships for our brand partners. Our robust technology and world-class operations allow us and our brand partners to offer powerful financial products without becoming a bank.
In the U.S., co-branded cards alone account for over $300 billion in annual spend, and most still run on decades-old legacy bank systems. Imprint is the modern alternative: flexible, embeddable, and built for how people actually pay today. Backed by Kleiner Perkins, Thrive Capital, Ribbit, and Khosla Ventures, we're building a world-class team to redefine how people pay and how brands grow. If you want to move fast, solve hard problems, and own real outcomes, we want to meet you.
THE ROLE
As Imprint's Senior Engineering Manager for Security, you will report to the Director of Engineering for Trust & Security. You will own the entire security engineering foundation. This includes AI security governance, application security, cloud infrastructure, detection and response, and identity management. You'll build this with AI leverage from day one, scaling a small team's impact with modern tooling.
Imprint is deliberately small and talent-dense. We use AI and tooling to give every person outsized leverage. This is a role where you can stay hands-on for as long as it makes sense. You set the strategic direction and do the work. Whether that balance shifts over time depends on what the business needs and what you want to build.
We power co-branded credit card programs for 10+ enterprise partners, with AI embedded across the business: underwriting, servicing, and how we build software. That AI leverage is core to how Imprint operates, and it creates a security challenge worth solving: how do you build an AI-forward security posture for an organization that moves this fast?
WHY THIS ROLE IS SPECIAL
- Stay Hands-On: Write detection rules, review PRs, file hardening commits, and threat-model features alongside engineering teams. If you've been pushed into pure management and miss building, this role gives you permission to get back to it while still setting strategic direction.
- AI-Native Security: Build security capabilities using AI agents for detection triage, compliance automation, and dependency management. You'll secure AI products and use AI to multiply your own leverage. This is how a small team operates at the standards of a company 10x its size.
- Full-Stack Ownership: Own the entire security domain: application security, cloud infrastructure, detection engineering, and AI governance.
- Preventative, Not Reactive: Build security that scales with the business rather than firefighting inherited problems. Do it right from the start, before bad patterns harden.
- Series D Sweet Spot: We have product-market fit and real traction, but we're still small enough for you to shape everything. Your decisions will drive our security posture for years to come.
- High-Trust Domain: Co-branded credit cards in regulated fintech (PCI, SOC 2, ISO). Security isn't a tax here; it's what enables every partner launch and every customer interaction.
WHAT YOU WILL OWN
- AI security: threat-model Imprint's agent surfaces for prompt injection, tool misuse, and authorization boundaries.
- AI for security: build AI-native capabilities that scale a small team's impact: AI-powered detection triage, automated compliance evidence collection, and threat-modeling assistance.
- Application security: threat modeling for new features, secure code review, SAST/SCA/DAST in CI, SDL design, dependency management, and secrets management. You read Go and TypeScript well enough to review PRs and catch the bugs that external audits should not have to find.
- Cloud and infrastructure security: IAM partitioning across multiple AWS accounts, least-privilege access, JIT elevation, cross-account trust hardening, KMS boundaries, SCP design, Kubernetes pod security, egress filtering, and Terraform security review.
- Detection and response: build the SIEM/SOAR pipeline from log sources through triage, write correlation rules, enable AI-powered triage, stand up on-call rotation, and create incident response runbooks.
- Identity and access: drive SSO coverage, access reviews, and JIT elevation in partnership with IT.
- Compliance partnership: design and implement the controls that satisfy SOC 2, PCI, and ISO evidence requirements. GRC runs the audit cycle. You own the underlying controls and make sure they actually hold up, not just pass sampling.
- Partner and customer trust: lead technical responses to third-party questionnaires and partner security reviews alongside GRC.
WHAT WE LOOK FOR
- 8+ years in security engineering, with experience building a security function from early stages
- Someone who builds and ships controls, not just identifies problems for others to fix
- Reads and reviews code in production languages (Go, TypeScript, Python, or similar)
- Detection engineering experience: has built a SIEM or SOAR pipeline from log sources through triage at least once
- Deep AWS security knowledge: IAM policy design, multi-account strategies, and how cloud privilege escalation works
- Has operated inside PCI DSS scope and shipped controls that survived a real audit
- Good judgment on scope: knows when to fix something directly versus set a
Salary insight
The midpoint of this range ($228k) is about 13% above the median disclosed salary for San Francisco roles listed on ForgeApply ($201k across 7,187 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Tailor your resume for this Imprint role before you apply.
Tailor my resume for this jobSimilar jobs
- Senior Engineering Manager, Security — Asana · San Francisco
- Senior Engineering Manager, Security Products — Digitalocean98 · Seattle
- Senior Engineering Manager, Security Products — Digitalocean98 · Remote
- Senior Engineering Manager, Product Security — Monarchmoney · Remote
- Senior Security Engineering Manager, Product Security — Upstart · Remote
- Senior Security Engineering Manager, Enterprise Security — Upstart · Remote
- Manager, Security Engineering — Cohere · United States
- Manager, Security Engineering — Thetradedesk · Bellevue; Denver; Los Angeles; Seattle; Ventura
More like this: More jobs at Imprint · Browse all jobs
Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)