Manager, Infrastructure Security

Simpson Thacher & Bartlett LLP
New York, United States
about 1 month ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$190,000.0 - $220,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Apple Mac Systems Architectural Patterns Microsoft Azure Software as a Service Cloud Computing Security Cloud Engineering Configuration Management Cyber Security Linux Identity and Access Management Intrusion Detection and Prevention
+21 more
Intrusion Detection Systems Virtual Private Networks (VPN) Python (Programming Language) Network Security Linux Servers Platform as a Service (PAAS) Windows PowerShell Remote Access Technology Zero Trust Network Access Virtualization Technology Policy as Code Data Logging Scripting Network Access Control Cloud Platform System Software Security Firewalls (Computer Science) Containerization Terraform Operating System Security Security Orchestration, Automation & Response

Job description

The Senior Manager, Infrastructure Security, is responsible for defining, maturing, and advancing the Firm’s infrastructure security strategy across servers, operating systems, cloud platforms, data protection technologies, core infrastructure networks, and foundational technology services. This leader will establish security standards, drive engineering excellence, and ensure security controls are consistently designed, implemented, measured, and continuously improved across on-premises, cloud, and hybrid environments. The role partners closely with Infrastructure Engineering, Cloud Engineering, Architecture, Identity & Access Management, Network Engineering, Risk Management, and Technology Operations teams to reduce cyber risk while enabling business growth and innovation., * Define and execute the Firm’s infrastructure security strategy, roadmap, and operating model.

  • Develop and maintain plans to mature infrastructure security capabilities aligned with business objectives and enterprise risk priorities.
  • Establish security standards, architectural patterns, engineering principles, and technical guardrails across infrastructure platforms.
  • Lead the design, implementation, and management of security controls across: Windows and Linux server environments, Endpoint platforms (Windows, macOS, mobile), Cloud environments (Azure, SaaS/PaaS etc.), Storage and data protection platforms, Network security technologies (Firewalls, IDS/IPS etc.), Virtualization and container platforms, Remote access technologies
  • Partner with cloud and infrastructure engineering teams to ensure secure deployment patterns for compute, storage, identity integration, and networking.
  • Establish and execute governance and monitoring processes for cloud security posture management and workload protection
  • Provide strategic oversight for network security controls, segmentation, secure connectivity, and perimeter defense technologies.
  • Govern and oversee optimization of security technologies such as firewalls, intrusion detection/prevention systems, network access control, and remote access (VPN).
  • Drive automation and engineering excellence through infrastructure-as-code, policy-as-code, and security automation initiatives.
  • Evaluate, select, and manage lifecycle of security-owned infrastructure protection technologies in partnership with enterprise infrastructure and application teams.
  • Identify and drive remediation of infrastructure security risks including misconfigurations, missing controls, unpatched systems, and excessive system-level privileges.
  • Support secure adoption of new infrastructure technologies including container platforms, platform services, and automation frameworks.
  • Establish metrics, key performance indicators (KPIs), and key risk indicators (KRIs) to measure program effectiveness and security maturity.
  • Influence engineering and technology decisions to ensure security requirements are integrated early in the design and delivery lifecycle.
  • Communicate infrastructure security risks, tradeoffs, and recommendations to senior leadership and technical stakeholders.
  • Stay current on emerging infrastructure threats, vulnerabilities, and defensive technologies.
  • Drive continuous improvement of infrastructure security controls and detection capabilities.
  • Build, mentor, and lead a high-performing team of infrastructure security engineers.
  • Promote a security engineering culture focused on automation, resilience, and measurable risk reduction.
  • Participate in on-call rotation to support after-hours incident response and critical security operations as needed.

Requirements

The successful candidate combines deep technical expertise with strong leadership skills and is equally comfortable developing long-term security roadmaps and rolling up their sleeves to solve technical challenges. This individual must be highly analytical, detail-oriented, adaptable, and capable of navigating ambiguity while driving measurable security outcomes in a fast-paced enterprise environment., * Bachelor’s degree in information security, IT, risk management, related discipline, or equivalent experience

  • Professional certifications such as CISSP, CISM, or similar preferred, * 10+ years of progressive experience in infrastructure security, network security, cloud security, or related cybersecurity disciplines, including experience within complex, large-scale enterprise environments
  • Proven experience developing, implementing, and maturing security programs that protect critical infrastructure across on-premises, cloud, and hybrid technology environments.
  • Demonstrated success leading security engineering initiatives that reduce risk, improve security posture, and strengthen resilience across enterprise technology platforms.
  • Experience partnering closely with infrastructure, cloud, network, and application engineering teams to design and implement security controls at scale while enabling business and technology objectives.
  • Deep technical knowledge across several of the following domains: Operating system security (Windows and Linux), Network security including firewalls, segmentation, remote access technologies, intrusion detection and prevention systems, and Zero Trust principles, Cloud security controls and configuration management for Azure and Saas/PaaS environments, Data protection and DLP technologies, Infrastructure logging, monitoring, and telemetry pipelines, Security automation and scripting using technologies such as PowerShell, Python, Terraform, or similar tools
  • Experience evaluating and implementing enterprise security tooling for infrastructure protection.
  • Proven people leadership experience, including building, developing, mentoring, and managing high-performing technical teams.
  • Demonstrated ability to influence senior executives and cross-functional stakeholders.
  • Exceptional organizational, planning, and program management skills.
  • Ability to manage multiple priorities, make sound decisions under pressure, balance strategic planning with hands-on technical engagement, and communicate effectively with both technical and business audiences.
  • Highly analytical with exceptional problem-solving and critical-thinking abilities.
  • Demonstrated ability to lead through ambiguity and drive results in complex, fast-paced environments., The actual salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job. This role is exempt meaning it is not overtime pay eligible.

Benefits & conditions

NY Only: The estimated base salary range for this position is $190,000 to $220,000 at the time of posting.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

1:34 min

Essential commands for running and testing Terraform configurations

Hennie Francis · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all