tags.new

Manager, Security Engineering

Remote-United-States

About Acquia

Acquia empowers the world’s most ambitious brands to create digital customer experiences that matter. With open source Drupal at its core, the Acquia Digital Experience Platform (DXP) enables marketers, developers, and IT operations teams at thousands of global organizations to rapidly compose and deploy digital products and services that engage customers, enhance conversions, and help businesses stand out.

Headquartered in Boston, MA, Acquia is a Great Place to Work-CertifiedTM company, is listed as one of the world’s top software companies by The Software Report, and is positioned as a market leader by the analyst community. We are Acquia. We are building for the future and we want you to be a part of it! 

Career Exploration at Acquia 

Our recruitment process is designed to empower you in making the most informed decisions. Acquia is committed to providing an inclusive, transparent, efficient, and educational interview experience that cultivates exploration into career opportunities at Acquia

You will discover the opportunity to grow your career here and learn from a global team that empowers you to exceed boundaries and achieve the extraordinary.

Role Overview

As the Manager of Security Engineering, you lead a specialized team of security engineers focused on application security, cloud security, and AI system security across Acquia's product portfolio. Operating on an evidence-based engineering model, your team proactively researches and identifies systemic security gaps to build automated controls and guardrails. By securing cloud-native applications and services across AWS, you enable Acquia's Product teams to inherit a “secure by default” foundation. You act as the critical nexus between Security Operations and Product Engineering, translating complex technical risks into actionable roadmaps that align with overarching business objectives—including the secure adoption of AI technologies.

Key Responsibilities

Team Leadership & People Management

  • Manage, mentor, and grow a dedicated team of security engineers.
  • Conduct continuous performance evaluations (quarterly and annually) to guide professional development and advocate for promotions.

Technical Strategy & Roadmap Execution

  • Define and execute a forward-looking security engineering roadmap aligned with Product Engineering needs and broader business initiatives, including the secure enablement of AI technologies.
  • Translate high-level business direction into actionable quarterly deliverables for the team.
  • Establish and measure team success against the completion of quarterly goals and the continuous improvement of annual compliance audit results.

Application Security & Secure SDLC

  • Champion shift-left security practices, including threat modeling, secure code review, and developer security training embedded in the software development lifecycle.
  • Own and scale application security tooling—SAST, DAST, and SCA platforms—to systematically surface and remediate vulnerabilities across product codebases.
  • Shift the security paradigm from manual operational cleanup to building automated solutions and guardrails that eliminate entire classes of vulnerabilities.

Evidence-Based Engineering & Cloud Security Architecture

  • Lead “research spikes” to proactively investigate cloud-native environments and identify systemic security gaps before they become incidents.
  • Ensure all security initiatives are rooted in clear findings and deliver exact, architectural fixes (code or configuration) to resolve them.
  • Define and enforce cloud security standards spanning IAM, API security, secrets management, and container workloads across AWS environments.

Agentic AI & LLM Security

  • Define and enforce security standards for internal enterprise AI systems, including LLM-based agents, RAG pipelines, and AI-integrated workflows—covering risks such as prompt injection, data exfiltration, and privilege escalation.
  • Lead threat modeling for agentic AI systems where models have access to tools, APIs, or sensitive data.
  • Partner with AI/ML engineering teams to embed security review into AI development lifecycles, from model selection through deployment.
  • Evaluate and deploy AI-native security tooling to augment the team’s detection, triage, and remediation capacity.

Cross-Functional Collaboration & Influence

  • Act as an internal consultant and advisory body to Product Engineering teams, guiding them on secure implementation practices.
  • Communicate complex, highly technical security risks effectively to non-technical project managers and stakeholders.
  • Influence and negotiate with software developers to prioritize and remediate vulnerabilities within their workflows.
  • Serve as the primary technical bridge between Product Engineering and Security Operations, providing guidance on cloud and Kubernetes security configurations.

Qualifications & Technical Requirements

  • Application Security: Hands-on experience with SAST, DAST, and SCA tooling (e.g., Semgrep, Snyk, Veracode, or equivalents) and guiding engineering teams on remediation.
  • Cloud Security: Deep understanding of securing cloud-native applications and services on AWS, including IAM, API Gateway, secrets management, and container workloads.
  • AI Security: Working knowledge of OWASP LLM Top 10, agentic AI attack surfaces (tool abuse, prompt injection, memory poisoning), and security considerations for AI systems with external integrations.
  • AI Tooling: Experience using AI-assisted security tools—such as AI-powered SAST, copilot-assisted code review, or agentic vulnerability triage—to scale team output.
  • Compliance Acumen: Strong working knowledge of the technical implications of operating within strict compliance frameworks, including ISO/SOC, PCI, and FedRAMP.
  • Communication Skills: Exceptional ability to translate highly technical concepts for non-technical stakeholders and the interpersonal skills required to influence engineering teams without direct reporting authority.

We are an organization that embraces innovation and the potential of AI to enhance our processes and improve our work. We are always looking for individuals who are open to learning new technologies and collaborating with AI tools to achieve our goals.

Acquia is proud to provide best-in-class benefits to help our employees and their families maintain a healthy body and mind. Core Benefits include: competitive healthcare coverage, wellness programs, take it when you need it time off, parental leave, recognition programs, and much more! 

Final compensation will be commensurate with your experience and will be determined by a variety of factors, including city of residence, relevant skillset, and job-related knowledge.

Acquia is an equal opportunity (EEO) employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veterans status or any other protected status or characteristic under federal, state or local law unrelated to the ability to perform the job.

We are seeking an AI-Native candidate who treats AI not as an external tool, but as a fundamental extension of their cognitive workflow. The ideal candidate possesses an orchestration mindset—the ability to skillfully prompt, manage, and direct AI to navigate complexity—and maintains a high degree of AI fluency.

You should be characterized by radical adaptability and a "builder" mentality, showing a restless drive to transform traditional work processes into agentic workflows. Beyond technical proficiency, we value intellectual humility: the willingness to constantly unlearn old methods in favor of more efficient, AI-augmented processes. You don't just use AI to do your job; you use it to redefine what your job can achieve.

Pay Range

$150,000 - $169,750 USD

Create a Job Alert

Interested in building your career at Acquia? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification of Disability

Form CC-305

Page 1 of 1

OMB Control Number 1250-0005

Expires 04/30/2026

 

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunities to qualified people with disabilities. To measure this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.

Select...

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.