ForgeApply
Try it free

ForgeApply · Job listing

Senior Manager - Security Engineering

Ferguson

Remote · US

See all 287 open roles at Ferguson

Tailor your resume for this Ferguson job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Ferguson's site. Free trial, no card required.

About this role

Job Posting: Since 1953, Ferguson has been a source of quality supplies for a variety of industries. Together We Build Better infrastructure, better homes and better businesses. We exist to make our customers’ complex projects simple, successful, and sustainable. We proactively solve problems, adapt and grow to continuously serve our customers, communities and each other. Ferguson, a Fortune 500 company, is proud to provide best-in-class products, service and capabilities across the following industries: Commercial/Mechanical, Facilities Supply, Fire and Fabrication, HVAC, Industrial, Residential Trade, Residential Building and Remodel, Waterworks and Residential Digital Commerce. Ferguson has approximately 36,000 associates across 1,700 locations. Ferguson is a community of proud associates who operate with the shared purpose of building something meaningful. You will build a career that you are proud of, at a company you can believe in.

Senior Manager - Security Engineering Department: Ferguson, Information Security Reports To: Director, Information Security

The Senior Manager, Security Engineering provides vision, leadership, and operational accountability for Ferguson’s enterprise security engineering capabilities. This role leads the teams and services responsible for identifying, reducing, and reporting technology risk across applications, infrastructure, cloud platforms, endpoints, identity-integrated services, email, edge protections, and emerging AI-enabled attack surfaces. The leader is accountable for ensuring Ferguson has the people, processes, tooling, and partnerships required to continuously assess risk, harden technology baselines, validate defenses, support secure delivery, and drive remediation in partnership with Technology, Security, business, and third-party participants. This position requires deep technical judgment, collaborative leadership, and operational rigor. It also requires the ability to translate complex security risks into actionable priorities. These priorities help Ferguson complete its business plans securely.

Location: This role is approved to be either Remote within the United States or Hybrid for associates in Newport News, VA, in accordance with company policy.

Duties and Responsibilities: Leadership and Strategy (40%) • Build, lead, and develop a high-performing Security Engineering team through recruiting, hiring, coaching, mentorship, performance management, and career development. • Define and maintain the operating model, service ownership, roadmap, and measurable objectives related to Security Engineering capabilities across vulnerability management, DevSecOps, penetration testing, edge security, email security, endpoint security, cloud and configuration posture, and related engineering services. • Represent Security Engineering performance, risks, resource needs, and strategic opportunities with Information Security leadership and multi-functional Technology leadership forums. • Partner with Security Architecture, Security Operations, GRC, Identity, Infrastructure, Application Development, Cloud, and business technology teams to align engineering priorities to enterprise risk reduction and business enablement. • Continuously assess team skills, capacity, vendor support, and tooling maturity against current and emerging threats, including AI-enabled attack techniques and post-quantum readiness considerations. • Drive a culture of secure-by-default engineering, shared accountability, transparency, and practical risk-based decision making across Ferguson technology teams. • Establish clear metrics, performance indicators, reporting routines, and executive-ready narratives that communicate risk posture, control effectiveness, remediation progress, service value, and investment needs.

Security Engineering Management (60%) • Own and mature Security Engineering service areas including vulnerability management, DevSecOps, penetration testing and adversarial validation, edge security, email security, endpoint detection and response, cloud security posture, configuration risk, application security testing, and security tooling integrations. • Lead Ferguson’s risk-based vulnerability management capability, ensuring asset visibility, authenticated scanning, application and infrastructure assessment, risk contextualization, remediation tracking, exception management, and leadership reporting are operating effectively. • Advance secure software delivery by integrating security testing and guidance into development workflows, including static analysis, software composition analysis, container security, secrets protection, code signing, secure repository practices, and developer-facing remediation support. • Run penetration testing, AI-enabled security testing, purple team support, and continuous adversarial validation activities for critical applications, APIs, external assets, cloud services, identity entry points, and business-critical technology platforms. • Ensure public-facing applications and digital channels are protected through effective use of edge security capabilities, including WAF, bot management, CDN security, origin protection, API protections, and secure traffic patterns. • Provide engineering ownership and oversight for email and endpoint security capabilities, including migration planning, policy tuning, telemetry quality, detection support, deployment health, and operational readiness. • Drive enterprise configuration and posture management across cloud, infrastructure, endpoints, applications, and identity-adjacent services to identify deviations from hardened baselines and support timely remediation. • Partner with Identity, PAM, SSO, certificate, and non-human identity teams where security engineering capabilities depend on identity controls, privileged access, machine identity, key management, or cryptographic services. • Support pivotal initiatives such as AI resilience, post-quantum readiness, enterprise cryptographic visibi

Tailor your resume for this Ferguson role before you apply.

Tailor my resume for this job

Similar jobs

More like this: Security & Cybersecurity Jobs · Remote Security & Cybersecurity Jobs · Browse all jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)