Senior Manager, Security Assurance Engineering

Redwood City, CA, United States

⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️

Box

The intelligent Content Cloud makes it easy to automate workflows, collaborate internally and externally, and protect your sensitive data, all on one platform.

View all jobs at Box

Apply now Apply later

WHAT IS BOX? 

Box (NYSE:BOX) is the leader in Intelligent Content Management. Our platform enables organizations to fuel collaboration, manage the entire content lifecycle, secure critical content, and transform business workflows with enterprise AI. We help companies thrive in the new AI-first era of business. Founded in 2005, Box simplifies work for leading global organizations, including AstraZeneca, JLL, Morgan Stanley, and Nationwide. Box is headquartered in Redwood City, CA, with offices across the United States, Europe, and Asia.

By joining Box, you will have the unique opportunity to continue driving our platform forward. Content powers how we work. It’s the billions of files and information flowing across teams, departments, and key business processes every single day: contracts, invoices, employee records, financials, product specs, marketing assets, and more. Our mission is to bring intelligence to the world of content management and empower our customers to completely transform workflows across their organizations. With the combination of AI and enterprise content, the opportunity has never been greater to transform how the world works together and at Box you will be on the front lines of this massive shift.

 

WHY BOX NEEDS YOU

As Senior Manager of Security Assurance Engineering at Box, you will lead a high-impact team dedicated to elevating the security posture of our core products through an engineering-first and product-centric approach. Your mission is to deeply understand Box’s complex product ecosystem and internal stakeholders to identify critical security risks and build scalable, automated controls that enable rapid, secure innovation. You will drive the evolution of our design reviews, secure component development, penetration testing, and bug bounty programs with a strong emphasis on automation, developer enablement, and measurable risk reduction.

 

WHAT YOU'LL DO 

  • Lead and grow a talented, hybrid team of security engineers focused on embedding application security into the product lifecycle through engineering rigor and automation.

  • Develop deep expertise in Box’s diverse product platforms and collaborate closely with product and engineering leaders to prioritize high-impact security initiatives aligned with business goals.

  • Drive right-sized, actionable security guidance and support that empowers engineering teams to reduce risk without slowing velocity.

  • Champion automation and tooling to streamline security assurance activities such as design reviews, threat modeling, penetration testing, and vulnerability management.

  • Navigate ambiguity and open-ended challenges inherent in securing fast-evolving AI-native applications and services.

  • Foster a culture of continuous learning, mentorship, and technical excellence within your team.

  • Build and maintain strong cross-functional partnerships across Product, Engineering, Security Architecture, and external security researchers to amplify impact.

  • Own and evolve metrics and KPIs and KRIs that demonstrate the effectiveness of security assurance efforts and inform strategic decisions.

 

WHO YOU ARE 

We are an AI-first company. This means you approach your work with a growth mindset and find ways to leverage AI to help make faster, smarter decisions that will 10X your impact at Box.

  • An engineering leader passionate about building secure products and enabling developers through practical, scalable security solutions.

  • Experienced in leading application security functions with a strong foundation in offensive security practices and secure software development.

  • Skilled at balancing security rigor with product velocity, delivering pragmatic and impactful risk mitigation strategies.

  • Adept at managing distributed teams, fostering collaboration, and driving results in ambiguous, fast-paced environments.

  • Excellent communicator who can translate complex security concepts into clear, actionable guidance for both technical and non-technical audiences.

  • Deep knowledge of modern application architectures, cloud environments, and security testing methodologies.

  • Has hands-on experience with penetration testing, threat modeling and conducting secure design reviews.

 

Preferred Skills: 

  • Experience with developing and shipping secure software components

  • Familiarity with emerging technologies including AI-assisted security and software development tooling.

  • Proven track record of partnering effectively with product and engineering teams to embed security as a foundational element of product development.

 

Box lives its values, with community and in-person collaboration being a core part of our culture. Boxers are expected to work from their assigned office a minimum of 3 days per week, with a focus on Tuesdays, Wednesdays, and Thursdays. Your Recruiter will share more about how we work and company culture during the hiring process.

At Box, we believe unique and diverse experiences benefit our culture, our products, our customers, our company, and our world. We aim to recruit a passionate, high-performing workforce that reflects the world we live in. If you are head-over-heels about this role but unsure if you meet all the requirements, we encourage you to apply!

#LI-RT

 

EQUAL OPPORTUNITY

We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, disability, and any other protected ground of discrimination under applicable human rights legislation. Box strives to respect the dignity and ‎‎independence of people with disabilities and is committed to giving them the same ‎‎opportunity to succeed as all other employees. Inclusiveness is core to our culture at Box, and we strive to ensure you get the most from your interview experience.

Box makes reasonable accommodations for applicants with disabilities. If a reasonable accommodation is needed to participate in the job application or interview process, please complete this form. Reasonable accommodations may include scheduling adjustments, document dictation and beyond.

 

Notice to applicants in Los Angeles:  Box, Inc and its related branches will consider for employment, qualified applicants with criminal histories in a manner consistent with the Los Angeles Fair Chair Ordinance.  The Fair Chance Ordinance is provided here

 

Notice to applicants in San Francisco:  Box, Inc and its related branches will consider for employment, qualified applicants with criminal histories in a manner consistent with the San Francisco Fair Chair Ordinance.  The Fair Chance Ordinance is provided here

 

For details on how we protect your information when you apply, please see our Personnel Privacy Notice. If you are a California-resident, please read our California Applicant & Candidate Privacy Notice here.

Box is committed to fair and equitable compensation practices. Actual base salary (or OTE if commissionable role) is dependent upon factors such as: knowledge, skill level, experience, and work location. This role is also eligible for equity and benefits. For more information on benefits, check out our healthcare benefits and additional Box Benefits + Perks.   In accordance with OFCCP compliance, here is the Pay Transparency Provision United States Pay Range$245,000—$306,500 USD
Apply now Apply later
Job stats:  0  0  0

Tags: Application security Automation Cloud Compliance KPIs Offensive security Pentesting Privacy Vulnerability management

Perks/benefits: Career development Equity / stock options Startup environment Team events Transparency

Region: North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.