Manager, Security Operations
Listed on 2026-08-21
-
IT/Tech
Cybersecurity, Security Management & Operations, Information Security & Data Protection, Network Security
Forward Financing is a financial technology company based in Boston, Massachusetts with team members throughout the United States, Dominican Republic, and Canada. The company is on a mission to unlock the capital that fuels small businesses across America. Recognized as a Best Place to Work by Built In Boston and certified as a Great Place To Work®, Forward is investing in its employees, technology, and customer experience – with long-term success in mind every step of the way.
As Manager, Security Operations, you will defend our infrastructure, SaaS, and endpoints by hiring, growing, and developing a team of high-quality security engineers. You will collaborate closely with cross-functional technical teams, App Sec, and executive stakeholders to advance our AI security strategy and build robust detection controls. You will be the point person to lead incident response as senior Incident Commander, drive cybersecurity risk assessments, and maintain a seamless, hardened security posture against real-world adversaries.
In this role you will:Hire, grow, and develop a team of high-quality security engineers to defend our endpoints, SaaS estate, and infrastructure against real-world adversaries.
Own the security of our corporate systems (SaaS applications and endpoints) including configuration hardening and vulnerability/patch oversight.
Lead security operations and incident response, acting as senior Incident Commander for the Security Incident Response Team (SIRT).
Own and tune our detection and response funnel and our Crowd Strike detection platform.
Build and maintain detection coverage across endpoint, SaaS, and identity signals; audit/usage logs, egress-proxy traffic, DLP events, and access trails.
Partner with other teams to build controls to contain external exposure: network allow lists, egress proxy, and proxy-level DLP.
Partner with App Sec on detection opportunities surfaced by pentesting.
Set quality and coverage standards for detection and response and own reporting on these metrics
Conduct ongoing enterprise-wide cybersecurity risk assessments across infrastructure, endpoints, applications and business processes
Own AI security as a zero-to-one build: build upon our existing detection tooling/response processes and execute our hiring plan to build the specialized team needed to keep pace with Forward's AI deployment
Why you should apply:Make a real difference in our security posture by driving the advancement of our AI security strategy. While this isn't a zero-to-one build from the ground up, you will have the opportunity to make a tangible impact by evolving detection and response processes to defend our critical infrastructure.
Make a high-impact, hands-on impact:
You will have the unique opportunity to lead the advancement of our AI security strategy, evolving our detection tooling and response processes to stay ahead of emerging threats, while owning and tuning our detection/response funnel to defend a critical fintech infrastructure against real-world adversaries.
Flexibility is a top priority:
Our employees are empowered to choose where they want to work (whether that’s from home, in the office, or a combination of both) with flexible hours.
7 or more years in detection engineering, security operations, or incident response, including team leadership.
Deep familiarity with adversary TTPs (MITRE ATT&CK), event correlation, and high-signal detection design.
Hands-on experience with EDR/SIEM platforms and detection-as-code practices.
Incident command experience: triage, containment, forensics, and stakeholder communication under pressure.
Experience securing SaaS environments and endpoint fleets — configuration management, access governance, and vulnerability/patch management.
Ability to communicate risk and priorities crisply to engineers and executives.
Cloud control-plane monitoring and identity threat detection (AWS).
Scripting/automation in Python, Ruby, or Go.
Typically has a Bachelor's Degree in Computer Science or equivalent technical degree, or equivalent industry experience.
Experience with SaaS security posture management (SSPM) or CASB tooling.
It would be nice if you…(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).