Thrasio is the consumer goods company reimagining omnichannel commerce and consumer products, and boasts an innovation engine that brings high-quality products to market across digital marketplaces, channels, and retailers globally.
With the experience of evaluating more than 6,000 Amazon companies, acquiring over 130 top-rated brands, and managing the scale of 22,000 products, Thrasio is the largest acquirer of Amazon FBA brands. Since our founding in 2018, the team has grown to more than 1,000 people globally--most of that growth has occurred during the COVID-19 pandemic. Hiring people who share a passion for their craft in the eCommerce space is the reason we’re projected to grow more than 10x in the next few years. This growth is supported by investors whose portfolios include Facebook, Google, Jet.com, StitchFix, and Lululemon. We do our best work when we’re surrounded by people who are insatiably curious, agile, and who thrive in collaborative, check-your-ego-at-the door working environments. Sound like you? We’d love to chat.
We are looking for a CyberSecurity Engineering Manager to help validate that our services, applications, and websites are secured against the latest threats. You will be responsible for managing a team of security engineers conducting security reviews and threat modeling, evolving the security assurance process, and creating metrics to demonstrate your team’s performance. You will help set the direction for a team of security professionals that is responsible for all internally developed (or acquired) products and services. The CyberSecurity Engineering Manager oversees engineers and architects in the development and implementation of security standards and controls in order to ensure that the organization's products are secure. This role combines long term strategic planning to raise the bar on security across the enterprise with the excitement and challenge of quickly reacting to new threat scenarios.
• Serve as a technical expert for project teams throughout the implementation and maintenance of assigned information security solutions
• Define and oversee the documentation of detailed standards (e.g., guidelines, processes, procedures).
• Provide CyberSecurity subject matter expertise to the day-to-day operational aspects of the engineering team including improvement of current security controls; identify areas of improvement, etc.
• Design and manage the technical evaluation of new security technologies
• Threat hunting for Cybersecurity:
‣ Identify security gaps across the IT and Engineering environments and develop solutions to rectify those gaps
‣ Design and manage internal and external penetration testing
What You Bring to the Party:
- Minimum of 7 years of relevant technical experience, with the majority of this in a formalized information security team
- Bachelor's degree in Information Security, Computer Science or related field preferred
- Strong understanding and familiarity with cloud security controls and best practices;
- Strong experience in security automation and tool development to secure the cloud;
- Familiarity with common security libraries, security controls, and common security flaws;
- Experience with OWASP, static/dynamic analysis, and common exploit tools and methods;
- Strong understanding of network and web related protocols (such as, TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols)
- Certifications: Information Security certifications (CISSP, SANS GIAC, CISA, etc.)
Projects and Delivery:
- Strong background in technical engineering and architecture, such as infrastructure/cloud engineering or software development
- Proven ability to build partnerships and collaboration between stakeholder teams
- Strong written and verbal communication skills and ability to outline security risks and technical concepts to stakeholders in user-friendly language
- Experience managing security vendors and managed services providers
- Experience managing a team
Approach to Work:
- Experience working in a fast-paced, high-tech and customer obsessed environment
- Demonstrated leadership, team management, and decision-making skills
- Ability to manage and participate in an on-call rotation performing weekend and after-hours support
Not Sure You Check Every Box?
Research shows that while men apply to jobs when they meet an average of 60% of the criteria, women and other marginalized folx tend only to apply if they meet 100% of the qualifications. At Thrasio, we need people who think rigorously and aren’t afraid to challenge assumptions, so we’re looking for diverse perspectives, as long as you meet the minimum criteria.
You’re encouraged to apply even if your experience doesn’t precisely match the job description. Join us!
THRASIO IS PROUD TO BE AN EQUAL OPPORTUNITY EMPLOYER AND CONSIDERS ALL QUALIFIED APPLICANTS FOR EMPLOYMENT WITHOUT REGARD TO RACE, COLOR, RELIGION, SEX, GENDER, SEXUAL ORIENTATION, GENDER IDENTITY, ANCESTRY, AGE, OR NATIONAL ORIGIN. FURTHER, QUALIFIED APPLICANTS WILL NOT BE DISCRIMINATED AGAINST ON THE BASIS OF DISABILITY, PROTECTED CLASSES, OR PROTECTED VETERAN STATUS. THRASIO PARTICIPATES IN E-VERIFY.
Thrasio does not accept agency resumes. Please do not forward resumes to our jobs alias, Thrasio employees or any other organization location. Thrasio is not responsible for any fees related to unsolicited resumes.