- Company Name
- Major League Baseball (MLB)
- Job Title
- Senior Manager, Defensive Security
- Job Description
-
Job title: Senior Manager, Defensive Security
Role Summary:
Lead MLB’s enterprise defensive security program, embedding security into product design, CI/CD pipelines, and cloud infrastructure. Drive automation, threat defense, and incident readiness to protect digital assets.
Expectations:
* Deliver measurable improvements in security posture and MTTR.
* Lead cross‑functional teams in a shift‑left environment.
* Mentor and grow defensive security staff.
Key Responsibilities:
* Design and automate CI/CD security controls (IaC, AWS, Azure, GCP).
* Integrate anti‑bot, anti‑fraud, API, and application security tools across web, mobile, and backend services.
* Oversee detection engineering, threat modeling, and incident response playbook development.
* Manage vulnerability lifecycle: identification, triage, remediation, and reporting.
* Pilot agentic AI for real‑time triage, hunting, and VRM automation.
* Enforce secure architecture standards, authentication, session management, and encryption best practices.
* Participate in on‑call rotation for high‑severity incidents, especially during major events.
* Develop operational playbooks, peer‑review standards, and change‑control procedures.
Required Skills:
* 4+ years in Dev(Sec)Ops, security engineering, or software engineering.
* Experience with WAF, bot mitigation, RASP, EDR, SIEM, CSPM, SAST/DAST, API security platforms.
* Automation skills in Python, Go, or Bash; CI/CD tooling (GitHub Actions, Terraform, Kubernetes).
* Knowledge of secure SDLC frameworks (e.g., OWASP SAMM).
* Backend API security for REST, GraphQL, or MCP.
* Strong communication and leadership abilities.
Required Education & Certifications:
* Bachelor’s or Master’s in Computer Science, Software Engineering, or Cybersecurity.
* Professional certifications (ISC)², GIAC, CompTIA, OffSec, ISACA, Security Blue Team, or cloud (AWS, Azure, GCP) are strongly preferred.