- Salary
- $190k – $220k
- Location
- New York, United States of America
- Workplace
- Hybrid
- Type
- Full-time
- Department
- IT
- Seniority
- Senior
- Visa
- Not sponsored
- Source
- Workday
Description
The Senior Manager, Infrastructure Security, is responsible for defining, maturing, and advancing the Firm's infrastructure security strategy across servers, operating systems, cloud platforms, data protection technologies, core infrastructure networks, and foundational technology services. This leader will establish security standards, drive engineering excellence, and ensure security controls are consistently designed, implemented, measured, and continuously improved across on-premises, cloud, and hybrid environments. The role partners closely with Infrastructure Engineering, Cloud Engineering, Architecture, Identity & Access Management, Network Engineering, Risk Management, and Technology Operations teams to reduce cyber risk while enabling business growth and innovation.
The successful candidate combines deep technical expertise with strong leadership skills and is equally comfortable developing long-term security roadmaps and rolling up their sleeves to solve technical challenges. This individual must be highly analytical, detail-oriented, adaptable, and capable of navigating ambiguity while driving measurable security outcomes in a fast-paced enterprise environment.
ESSENTIAL JOB DUTIES & RESPONSIBILITIES
- Define and execute the Firm's infrastructure security strategy, roadmap, and operating model.
- Develop and maintain plans to mature infrastructure security capabilities aligned with business objectives and enterprise risk priorities.
- Establish security standards, architectural patterns, engineering principles, and technical guardrails across infrastructure platforms.
- Lead the design, implementation, and management of security controls across: Windows and Linux server environments, Endpoint platforms (Windows, macOS, mobile), Cloud environments (Azure, SaaS/PaaS etc.), Storage and data protection platforms, Network security technologies (Firewalls, IDS/IPS etc.), Virtualization and container platforms, Remote access technologies
- Partner with cloud and infrastructure engineering teams to ensure secure deployment patterns for compute, storage, identity integration, and networking.
- Establish and execute governance and monitoring processes for cloud security posture management and workload protection
- Provide strategic oversight for network security controls, segmentation, secure connectivity, and perimeter defense technologies.
- Govern and oversee optimization of security technologies such as firewalls, intrusion detection/prevention systems, network access control, and remote access (VPN).
- Drive automation and engineering excellence through infrastructure-as-code, policy-as-code, and security automation initiatives.
- Evaluate, select, and manage lifecycle of security-owned infrastructure protection technologies in partnership with enterprise infrastructure and application teams.
- Identify and drive remediation of infrastructure security risks including misconfigurations, missing controls, unpatched systems, and excessive system-level privileges.
- Support secure adoption of new infrastructure technologies including container platforms, platform services, and automation frameworks.
- Establish metrics, key performance indicators (KPIs), and key risk indicators (KRIs) to measure program effectiveness and security maturity.
- Influence engineering and technology decisions to ensure security requirements are integrated early in the design and delivery lifecycle.
- Communicate infrastructure security risks, tradeoffs, and recommendations to senior leadership and technical stakeholders.
- Stay current on emerging infrastructure threats, vulnerabilities, and defensive technologies.
- Drive continuous improvement of infrastructure security controls and detection capabilities.
- Build, mentor, and lead a high-performing team of infrastructure security engineers.
- Promote a security engineering culture focused on automation, resilience, and measurable risk reduction.
- Participate in on-call rotation to support after-hours incident response and critical security operations as needed.
EDUCATION
- Bachelor’s degree in information security, IT, risk management, related discipline, or equivalent experience
- Professional certifications such as CISSP, CISM, or similar preferred
SKILLS AND EXPERIENCE
- 10+ years of progressive experience in infrastructure security, network security, cloud security, or related cybersecurity disciplines, including experience within complex, large-scale enterprise environments
- Proven experience developing, implementing, and maturing security programs that protect critical infrastructure across on-premises, cloud, and hybrid technology environments.
- Demonstrated success leading security engineering initiatives that reduce risk, improve security posture, and strengthen resilience across enterprise technology platforms.
- Experience partnering closely with infrastructure, cloud, network, and application engineering teams to design and implement security controls at scale while enabling business and technology objectives.
- Deep technical knowledge across several of the following domains: Operating system security (Windows and Linux), Network security including firewalls, segmentation, remote access technologies, intrusion detection and prevention systems, and Zero Trust principles, Cloud security controls and configuration management for Azure and Saas/PaaS environments, Data protection and DLP technologies, Infrastructure logging, monitoring, and telemetry pipelines, Security automation and scripting using technologies such as PowerShell, Python, Terraform, or similar tools
- Experience evaluating and implementing enterprise security tooling for infrastructure protection.
- Proven people leadership experience, including building, developing, mentoring, and managing high-performing technical teams.
- Demonstrated ability to influence senior executives and cross-functional stakeholders.
- Exceptional organizational, planning, and program management skills.
- Ability to manage multiple priorities, make sound decisions under pressure, balance strategic planning with hands-on technical engagement, and communicate effectively with both technical and business audiences.
- Highly analytical with exceptional problem-solving and critical-thinking abilities.
- Demonstrated ability to lead through ambiguity and drive results in complex, fast-paced environments.
Salary Information
NY Only: The estimated base salary range for this position is $190,000 to $220,000 at the time of posting.
The actual salary offered will depend on a variety of factors, including without limitation, the qualifications of the individual applicant for the position, years of relevant experience, level of education attained, certifications or other professional licenses held, and if applicable, the location in which the applicant lives and/or from which they will be performing the job. This role is exempt meaning it is not overtime pay eligible.
Simpson Thacher will not sponsor applicants for work visas for this position.
Privacy Notice
For information about how Simpson Thacher & Bartlett LLP collects and processes your personal information, please refer to our Privacy Notice available at https://www.stblaw.com/other/privacy-notice.
Simpson Thacher & Bartlett is committed to a collegial work environment in which all individuals are treated with respect and dignity. The Firm prohibits discrimination or harassment based upon race, color, religion, gender, gender identity or expression, age, national origin, citizenship status, disability, marital or partnership status, sexual orientation, veteran’s status or any other legally protected status. This Policy pertains to every aspect of an individual’s relationship with the Firm, including but not limited to recruitment, hiring, compensation, benefits, training and development, promotion, transfer, discipline, termination, and all other privileges, terms and conditions of employment.
#LI-Hybrid