Manager, Information Security
- Full-time
- Workplace Type: Hybrid
- Career Track & Grade: MR3/9
- Department: Engineering
Company Description
LinkedIn is the world's largest professional network, built to create economic opportunity for every member of the global workforce. Our products help people make powerful connections, discover exciting opportunities, build necessary skills, and gain valuable insights every day. We're also committed to providing transformational opportunities for our own employees by investing in their growth. We aspire to create a culture that's built on trust, care, inclusion, and fun – where everyone can succeed.
Join us to transform the way the world works.
Job Description
At LinkedIn, our approach to flexible work is centered on trust and optimized for culture, connection, clarity, and the evolving needs of our business. The work location of this role is hybrid, meaning it will be performed both from home and from a LinkedIn office on select days, as determined by the business needs of the team.
About the team
LinkedIn's members entrust us with their information every day and we take their security seriously. Our core value of putting our members first powers all the decisions we make, including how we manage and protect the data of our members and customers. Information Security at LinkedIn is dedicated to protecting and securing business-critical member data and company assets. Our core mission is to empower LinkedIn to create a secure and thriving platform for every member of the global workforce.
The product and platform security team is responsible for securing all of LI’s services be it on-prem or cloud. As a technically adept and product-centric leader, you will oversee the creation of features and systems designed to enhance platform integrity and user confidence. In this capacity, you are accountable for the secure software development lifecycle (SSDLC) and the security of CI/CD pipelines for both member-facing and internal products.
You will partner with engineering to mitigate security risks through the design and implementation of robust security controls and processes, ensuring that product development is secure by default while supporting business objectives. You will own and evolve the secure software development lifecycle (SSDLC) by integrating leading security practices into every phase, from planning and architecture reviews to continuous testing and maintenance. In this capacity, you will oversee developer guardrails—including secure coding criteria, architectural designs, and code reviews—while driving the adoption of paved paths within the CI/CD pipeline. By automating scanning, testing, and compliance checks at every stage, you will ensure software supply chain security and code integrity from development through production, reducing systemic risk and driving high-value security outcomes. Act as a force multiplier by championing AI-assisted security workflows and utilizing AI-native systems that offer deep architectural reasoning. By integrating these advanced guardrails, you will eliminate classes of vulnerabilities ranging from traditional risks like the OWASP Top 10 to emerging, sophisticated threats like prompt injections targeting agentic applications.
Responsibilities:
Own, evolve, and drive the secure development lifecycle. Drive “shift-left” and “shift-down” initiatives across architecture reviews, threat modeling, SAST/DAST, continuous end to end testing, fuzzing, etc.
Drive adoption of paved paths by focusing on safe coding, cryptographic hygiene, software supply chain security
Design security paved roads and developer guardrails to eliminate classes of vulnerabilities
Force multiplier and champion for AI assisted security workflows
Lead, empower, and grow a high performing team of security engineers and scale
Lead the penetration testing efforts internally or partner with external firms for the same to drive the right outcomes
Collaborate with engineering to mitigate security risks, and support shipping quickly
Evaluate and enhance security tooling and automation to bolster technical rigor while driving operational efficiency and high-value security insights
Cultivate and sustain profound technical proficiency across all facets and functionalities within the broader product landscape
Stay at the forefront of the field by maintaining rigorous expertise in evolving security risks, landscape shifts, and cutting-edge defensive methodologies
Act as the principal escalation authority for intricate or high-impact security risks; spearhead systemic enhancements across architecture and workflows by leveraging post-incident insights
Act as a key technical advisor to engineering leadership; communicate complex security risks and recommendations effectively by articulating business impacts and navigating critical trade-offs
Establish and report on meaningful security engineering and operations metrics, including program health, control effectiveness, availability performance, remediation progress, and risk reduction outcomes
Evaluate and improve security tooling, processes, and controls to reduce systemic risk, increase operational efficiency, and ensure the team is focused on the highest-value security work
Qualifications
Basic Qualifications
BS (or higher, e.g., MS, or PhD) in Computer Science, Cybersecurity, Information Security, or related technical field, or equivalent technical experience.
1+ year(s) of management experience or 1+ year(s) of staff level engineering experience with management training
7+ years of experience in software development, security development lifecycle, security automation, product and platform security, bug bounty program
Experience defining strategic roadmaps, managing deliverables, and driving operational excellence for complex initiatives involving multiple stakeholders
Experience conducting code and architecture reviews, pressure-test designs, and guide tradeoffs across correctness, performance, scale, and operability
Experience in on-prem and cloud infrastructure
Experience owning security critical production systems where reliability, auditability, and operational rigor are essential
Preferred Qualifications
Track record turning complex infrastructure/software problems into adopted platforms across Engineering, Security, IT, and internal teams
High bar for engineering quality, operational discipline, and long-term ownership
Knowledge of Azure, AWS, Kubernetes, CI/CD security, endpoint security, identity and access management, vulnerability management, observability, logging pipelines, and modern security engineering practices
Fluency in at least one programming language (GO, Python, Java) to facilitate code reviews, security tool development and automation. Bonus if coming from SWE background
Ability to communicate security risk, tradeoffs, and recommendations clearly to technical, non-technical, and senior leadership audiences
Experience improving product and platform security programs
Growth oriented mindset where you love to build not just maintain
Suggest Skills:
Technical Leadership
Product Security
Platform Security
You will Benefit from our Culture
We strongly believe in the well-being of our employees and their families. That is why we offer generous health and wellness programs and time away for employees of all levels.
Software Engineering
Additional Information
India Disability Policy
LinkedIn is an equal employment opportunity employer offering opportunities to all job seekers, including individuals with disabilities. For more information on our equal opportunity policy, please visit https://legal.linkedin.com/content/dam/legal/Policy_India_EqualOppPWD_9-12-2023.pdf
Global Data Privacy Notice and Compliance Posters for Job Candidates
Please use this link to access documents that provide information about how LinkedIn handles the personal data of employees and job applicants, as well as the E-Verify Participation Notice and the Department of Justice Immigrant and Employee Rights Section Right to Work posters: https://www.linkedin.com/legal/candidate-portal.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply