Staff Engineering Manager, Cloud Security
GitHub is the world’s leading platform for agentic software development — powered by Copilot to build, scale, and deliver secure software. Over 180 million developers, including more than 90% of the Fortune 100 companies, use GitHub to collaborate, and more than 77,000 organisations have adopted GitHub Copilot.
Locations
In this role you can work from Remote, United States
Overview
GitHub is seeking a Staff Engineering Manager to lead the Cloud Security engineering team. This team is responsible for helping protect the cloud infrastructure that power GitHub at global scale.
In this role, you will lead a team of security-focused engineers working across multi cloud security posture, infrastructure security, secure-by-default platform capabilities, and risk reduction across GitHub's production environments. You will partner closely with engineering, security, infrastructure, compliance, and product teams to identify high-impact risks, build durable technical solutions, and improve the security of GitHub's cloud ecosystem.
You will create the conditions for a high-performing team to do its best work: setting clear priorities, building strong partnerships, coaching engineers, improving execution, and ensuring the team delivers security outcomes that are technically sound, scalable, measurable, and aligned with GitHub's business needs.
Responsibilities
- Lead and grow a distributed Cloud Security engineering team, creating clarity around priorities, ownership, execution, and impact.
- Partner with Security, Infrastructure, Platform, Product, and Engineering leaders to define and deliver a technical roadmap that reduces cloud security risk across GitHub.
- Drive cloud security initiatives across areas such as secure infrastructure configuration, identity and access, vulnerability and exposure management, incident response readiness, and secure-by-default platform capabilities.
- Guide the team in designing scalable, reliable, and observable security systems that integrate effectively with GitHub's engineering workflows.
- Build strong operating mechanisms for prioritization, execution, stakeholder communication, dependency management, and measurable security outcomes.
- Coach and develop engineers, support career growth, manage performance, and foster a culture of ownership, learning, inclusion, and continuous improvement.
- Champion engineering excellence through automation, tooling, standardization, and operational practices that make secure outcomes easier for GitHub engineering teams.
- Partner with incident response, governance, risk, and compliance teams to ensure cloud security investments improve both real-world security posture and auditability.
- Help the team balance proactive risk reduction with responsive security work, ensuring urgent issues are handled effectively without losing sight of long-term strategic goals.
Qualifications
Required Qualifications:
- 10+ years experience in security analysis, security research, cyber security, security engineering, or relevant area,
- OR Associate's Degree AND 9+ years experience in security analysis, security research, cyber security, security engineering, or relevant area,
- OR Bachelor's Degree AND 8+ years experience in security analysis, security research, cyber security, security engineering, or relevant area,
- OR Master's Degree AND 6+ years experience in security analysis, security research, cyber security, security engineering, or relevant area,
- OR Doctorate AND 4+ years experience in security analysis, security research, cyber security, security engineering, or relevant area,
- OR equivalent experience.
- 2+ years people management experience.
Preferred Qualifications:
- 5+ years experience with securing one or more cloud platforms, such as Azure, AWS, or Google Cloud.
- 3+ years experience with cloud security posture management, IaC security, container/Kubernetes security, IAM, secrets management, vulnerability management, detection engineering, or incident response.
- 2+ years experience operating in large-scale SaaS, developer platform, enterprise software, or high-compliance environments.
- 2+ years experience working with application security tools (SAST, DAST, SCA) and/or performing security review activities (threat modeling, security design and architecture review, application security testing and code review) within the development lifecycle.
Compensation Range
The base salary range for this job is USD $140,400.00 - USD $372,300.00 /Yr.
These pay ranges are intended to cover roles based across the United States. An individual's base pay depends on various factors including geographical location and review of experience, knowledge, skills, abilities of the applicant. At GitHub certain roles are eligible for benefits and additional rewards, including annual bonus and stock. These rewards are allocated based on individual impact in role. In addition, certain roles also have the opportunity to earn sales incentives based on revenue or utilization, depending on the terms of the plan and the employee's role.
This position will be open for a minimum of 3 days, with applications accepted on an ongoing basis until the position is filled.
GitHub values
- Customer-obsessed
- Ship to learn
- Growth mindset
- Own the outcome
- Better together
- Diverse and inclusive
Manager fundamentals
- Model
- Coach
- Care
Leadership principles
- Create clarity
- Generate energy
- Deliver success
Who We Are
GitHub is the world’s leading AI-powered developer platform with 150 million developers and counting. We’re also home to the biggest open-source community on earth (and 99% of the world’s software has open-source code in its DNA). Many of the apps and programs you use every day are built on GitHub.
Our teams are dreamers, doers, and pioneers, leading the way in AI, driving humanitarian efforts around the globe, and even sending open source to Mars (and beyond!). At GitHub, our goal is to create the space you need to do your best work. We’re remote-first and offer competitive pay, generous learning and growth opportunities, and excellent benefits to support you, wherever you are—because we know that people flourish when they can work on their own terms.
Join us, and let’s change the world, together.
EEO Statement
GitHub is made up of people from a wide variety of backgrounds and lifestyles. We embrace diversity and invite applications from people of all walks of life. We don't discriminate against employees or applicants based on gender identity or expression, sexual orientation, race, religion, age, national origin, citizenship, disability, pregnancy status, veteran status, or any other differences. Also, if you have a disability, please let us know if there's any way we can make the interview process better for you; we're happy to accommodate!