Senior Manager, Defensive Security

6 days ago


New York, United States Major League Baseball Full time

As the Senior Manager of Defensive Security, you will be instrumental in Major League Baseball’s effort to embed security into our product design and software delivery lifecycle.You’ll lead the integration of anti-bot, anti-fraud, API, and application security tooling, and automate security controls across our CI/CD pipelines—ensuring our web and mobile platforms remain resilient and trusted by millions of fans and employees alike. Your work will defend the league’s digital assets from emerging threats, ensuring every pitch, stream, and stat is delivered securely to fans around the world. You will also define MLB’s next-generation defensive strategy, including security for agentic AI, MCP infrastructure, and autonomous system-to-system interactions. Responsibilities Security Engineering & Automation Design and implement scalable defensive security controls within CI/CD pipelines, infrastructure-as-code, and cloud-native environments Lead integration of anti-bot, anti-fraud, API security, and application security tools across MLB's digital platforms Improve our security architecture by partnering with DevOps, SRE, Product & Software Engineering teams to embed security early in the software development lifecycle (Shift Left) Threat Defense & Incident Readiness Oversee detection engineering efforts to improve visibility, reduce dwell time, and create actionable security alerts and response automations Partner with the Security Operations and Offensive Security teams to mature incident response playbooks, adversary emulation, and purple team exercises Evaluate threats, vulnerabilities, and attack techniques to ensure proactive defense postures (MITRE ATT&CK, D3FEND-aligned) Take part in the on-call rotation for high-severity incident escalations, particularly during high-profile events such as major game days, ticket launches, or partner broadcasts Vulnerability & Exposure Management Lead vulnerability management activities, ensuring timely identification, triage, and remediation of security findings across infrastructure, applications, and APIs Collaborate with product, IT, and infrastructure teams to prioritize risk-based remediation efforts and report on exposure trends Pilot and integrate agentic AI platforms capable of real-time contextual decision-making (e.g., alert triage, threat hunting, VRM automation) to reduce mean time to respond (MTTR) and analyst fatigue Secure Architecture & Application Hardening Develop and enforce secure design patterns for web, mobile, and API platforms, emphasizing resiliency against modern attack vectors Partner with developers and product teams to conduct architectural threat modeling and review high-impact features or deployments Champion best practices in authentication, session management, data protection, and secure SDLC Define and enforce cloud security architecture standards across AWS, Azure, and GCP, incorporating best practices for workload isolation, IAM, encryption, and control plane monitoring Leadership & Collaboration Mentor and develop a growing team of defensive security engineers and analysts; foster a high-performance, innovation-focused culture Track and report key performance indicators (KPIs) and defensive maturity metrics to security leadership and executive stakeholders Serve as a key security stakeholder across Engineering, IT, Product, Legal, and third-party vendors Develop and maintain operational security playbooks, peer-review standards, and change-control procedures. Act as the primary Defensive Security stakeholder in security governance, risk assessments, and change-advisory board processes Qualifications & Skills Bachelor’s or Master of Computer Science, Software Engineering, or Cybersecurity 4+ years of experience in Dev(Sec)Ops, software engineering, security engineering or a related role Relevant certifications from recognized organizations such as (ISC)², GIAC (SANS), CompTIA, OffSec, ISACA, Security Blue Team, or cloud providers (AWS, Azure, GCP) are a strong plus Experience implementing and managing security tooling in one or more areas: WAF, bot mitigation, RASP, EDR, SIEM, CSPM, SAST/DAST, or API security platforms is required Proficiency in one or more languages such as Python, Go, or Bash for automating security controls and CI/CD workflows is required. Experience with formal SSDLC frameworks (e.g., OWASP SAMM) is a plus Experience securing backend APIs (REST, GraphQL, MCP) developed in languages like Node.js, Java, Python or Go is a plus Deep understanding of modern application architectures (cloud-native, microservices, APIs) and their security implications is required Solid experience with DevOps platforms and IaC (Kubernetes, Terraform, GitHub Actions, etc.) is required Capable of independently driving mission-critical initiatives to completion with accuracy and care, exercising sound judgment and discretion in the handling of sensitive or confidential information Strong written and oral communications skills. Ability to explain technical concepts to audiences at different levels Salary Range: $140,000- $175,000 (Base Salary) + Bonus As a candidate for this position, your salary and related elements of compensation will be contingent upon your work experience, education, skills and any other factors Major League Baseball (MLB) considers relevant to the hiring decision. In addition to your salary, MLB believes in providing a competitive compensation and benefits package for its employees.  Top MLB Perks & Benefits Competitive Benefits Package Company 401K Contribution Paid Time Off and Holidays Paid Parental Leave Access to Free Tickets to Baseball Games &  Discounts at MLB Store |  Employee Assistance Programs (EAP) Onsite/Online Training & Development Programs Tuition Reimbursement Disability Benefits (short term and long term) Life and Accidental Death Insurance Pet Insurance Why MLB? Major League Baseball (MLB) is the most historic of the major professional sports leagues in the United States and Canada. Employees love working at MLB because of the culture of growth, teamwork, and professionalism. Employees who are most successful at MLB take initiative, know how to identify problems and provide solutions, and always put the Team first. For those ready to step up to the plate and join the major leagues, MLB takes the same approach as teams do with their players: empowering our “workforce athletes” to be at their best by engineering experiences that put employees in the best position to succeed. Major League Baseball is looking for candidates who are passionate about growing America’s pastime to best serve its fans for decades to come. California Residents: Please see our for more details. Colorado Residents: Colorado based applicants may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information. Applicants requiring a reasonable accommodation for any part of the application and hiring process, please email us at . Requests received for non-disability related issues, such as following up on an application, will not receive a response.



  • New York, United States Major League Baseball Full time

    Join to apply for the Senior Manager, Defensive Security role at Major League Baseball (MLB) Join to apply for the Senior Manager, Defensive Security role at Major League Baseball (MLB) Get AI-powered advice on this job and more exclusive features. As the Senior Manager of Defensive Security, you will be instrumental in Major League Baseballs effort to embed...

  • Security Officer

    2 weeks ago


    York, United States Allied Universal Security Full time

    Allied Universal, North America's leading security and facility services company, offers rewarding careers that provide you a sense of purpose. While working in a dynamic, welcoming, and collaborative workplace, you will be part of a team that contributes to a culture that positively impacts the communities and customers we serve.As a Security Officer -...

  • Security Guard

    2 weeks ago


    New York, United States OneService Security Services Full time

    Security GuardWe are looking for a professional security guard to protect our premises, assets and personnel. You will maintain a high visibility presence and prevent all illegal or inappropriate actions. The goal is to detect, deter, observe and report.ResponsibilitiesProtect company’s property and staff by maintaining a safe and secure environmentObserve...


  • New York, United States MKIT Inc Full time

    Join to apply for the Senior Security Specialist role at Mkit 3 days ago Be among the first 25 applicants Join to apply for the Senior Security Specialist role at Mkit Introduccin Mkit was founded in 2008 in Buenos Aires, Argentina. We provide defensive and offensive security solutions, on-demand incident detection and response services, personalized...


  • New York, United States KPMG US Full time

    Overview Join to apply for the Manager, Cyber Defense Architect role at KPMG US. KPMG Advisory practice is currently our fastest growing practice. We are experiencing strong client demand and expect this to continue. Our culture emphasizes collaboration, team-driven work, and opportunities for learning and career development. If you are looking for a firm...


  • New York, New York, United States Center for Family Representation Full time

    CFR provides interdisciplinary family defense with a model that was unique at our founding and that is now being replicated nationally: we assign every client an attorney and a social work staff member. As an agency committed to securing justice for families, we built the Youth Defense practice (YDP) to defend youth at risk of family separation through...


  • New York, United States Bank of China USA Full time

    Chief Information Security Office - Security Services & Cyber Defense - Security Operation Center AVP Join to apply for the Chief Information Security Office - Security Services & Cyber Defense - Security Operation Center AVP role at Bank of China USA. Established in 1912, Bank of China is one of the largest banks in the world, with over $3 trillion in...


  • New York, United States Picus Security Full time

    Join to apply for the Senior Security TAC Engineer role at Picus Security 3 weeks ago Be among the first 25 applicants Are you passionate about technology and enjoy explaining complex solutions in a way that everybody gets excited? If so, read on! About Picus Picus Security, the leading security validation company, gives organizations a clear picture of...

  • Security Officer

    2 weeks ago


    New York, United States Allied Universal Full time

    Job Description As a Security Officer - Defense Armed Patrol in San Diego, CA, you will serve and safeguard clients in a range of industries such as Aero/Defense, and more. Join a leading team where flexibility meets opportunity. As a Part-Time Security Officer, you can build a schedule that works for you and explore new roles using our Claim a Shift...


  • New York, NY, United States J. Katz & Partners, Inc Full time

    Senior Trial Attorney – Litigation Defense Hybrid | New York City J. Katz & Partners is representing a respected New York litigation firm in the search for an experienced Senior Trial Attorney to join its defense-side civil litigation practice. The firm handles high-exposure personal injury and civil defense matters, including premises liability,...