--- title: 'Senior Manager, Security Platform Engineering at Todyl' canonical: 'https://feeny.ai/job/senior-manager-security-platform-engineering-todyl-denver-32b23hzjvs4b' type: 'job' last_seen: '2026-09-19' --- # Senior Manager, Security Platform Engineering at Todyl - **Company:** Todyl - **Location:** Denver, CO / Atlanta, GA - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-09-01 - **Last confirmed live:** 2026-09-19 - **Apply:** https://jobs.ashbyhq.com/todyl/a37a6cde-3f4d-489b-ac0d-de99218eb351 ## Job description ## About Us Todyl puts world-class networking and security within reach of every business. The Todyl Security Platform converges SASE, SIEM, Endpoint Security, GRC, MXDR, and more into a cloud-native, single-agent platform specifically built for MSPs, MSSPs, and Mid-Market IT Professionals. We are a fast-paced, dynamic start-up, passionate about simplifying complex networking and security for businesses of all sizes. ## About the Role We are seeking a Senior Manager to lead the two engineering teams that build and operate our core security systems: the Detection Engine, Threat Intelligence Platform, SOAR, and Case Management. These systems power how our SOC, Detection Engineering, and Threat Intelligence functions detect threats, hunt, and work alerts—and how the results of that work are presented to our partners through cases. Their quality is directly visible in the detection and response outcomes our partners receive. This role reports to the Security leader. This is a hands-on engineering leadership role. Roughly 80% of your time is management and delivery leadership; roughly 20% is technical contribution through architecture, design reviews, standards, and prototyping—not critical-path development. Your teams own production operations for these systems, including on-call, and you own their delivery quality, roadmap, and the quality of their partner-visible surfaces. Our security practitioners are your customers: SOC, Detection Engineering, and Threat Intelligence define requirements and serve as the acceptance gate for security-facing functionality. Your teams own and iterate on the platforms themselves. As an AI-first security organization, our security practitioners build agentic workflows—detection authoring, intelligence enrichment, validation automation—directly on these systems, making platform extensibility and workflow support core requirements of what your teams deliver. ## Responsibilities ## Team Leadership & Development (Daily / Weekly) - Manage two system-aligned engineering teams covering the Detection Engine, TIP, SOAR, and Case Management - Own hiring, performance, coaching, and career development for the engineering group, including developing team leads and senior engineers into broader leadership responsibilities - Maintain a high technical bar through design reviews, code review standards, and architectural guidance Delivery Quality & Production Ownership (Daily / Ongoing) - Own the definition of done: establish acceptance criteria for security-facing functionality with operator sign-off from SOC, Detection Engineering, and Threat Intelligence - Own production operations for these systems: on-call rotations, incident review, SLOs, and reliability engineering - Own release quality and delivery predictability across both teams - Coordinate shared infrastructure, deploy tooling, and engineering standards with our central Engineering organization Roadmap & Product Ownership (Weekly / Quarterly) - Own the roadmap for the Detection Engine, TIP, SOAR, and Case Management, balancing operator needs, platform health, and partner-visible improvements - Run product discipline for these systems: quarterly planning, success metrics, and written problem statements for major initiatives - Own the quality and roadmap of partner-visible surfaces—case presentation foremost, as the primary way partners see the value of our security work—drawing partner signal from our customer-facing teams and coordinating with Product Management on go-to-market and the SIEM boundary - Own the alert-working and threat hunting workflows these systems provide: investigation surfaces, hunt tooling and query capabilities, and the alert-to-case lifecycle Technical Contribution (~20%, Ongoing) - Set and evolve the architectural direction for streaming detection infrastructure, intelligence pipelines, and automation systems - Contribute through design documents, prototypes, and technical standards—staying out of critical-path delivery - Guide how these platforms support practitioner-built automation: the APIs, workflow primitives, and extensibility that let security teams build detection authoring, enrichment, and validation workflows on the systems - Ensure the Detection Engine, Case Management, and supporting systems expose the data, APIs, and integration points our AI SOC capabilities depend on, in close partnership with the AI/ML team that owns that initiative Security Team Partnership (Daily / Ongoing) - Work directly with Detection Engineering, Threat Intelligence, and MXDR as the customers of these systems: intake their requirements, close feedback loops, and treat operator effectiveness as the primary measure of success - Translate operational pain into engineering priorities, and engineering trade-offs back into terms practitioners can act on - Partner with these teams on telemetry, alert-working workflows, hunt tooling, and case presentation improvements Accountability (Ongoing) Own outcomes including: - System reliability and SLO attainment for the Detection Engine, TIP, and SOAR - Delivery predictability and quality across both teams - Team health, retention, and leadership development - Track and improve metrics such as: - Operator-reported tooling effectiveness (SOC, DE, TI acceptance and satisfaction) - Incident frequency and time-to-recovery for owned systems - Cycle time from accepted requirement to production ## Requirements Education & Experience - Bachelor's degree in Computer Science, Cybersecurity, or a related field, or equivalent practical experience - 8+ years in software or security engineering, including significant experience building security products or detection/response tooling - 3+ years managing engineering teams, with experience managing 8+ engineers or multiple teams - Experience developing team leads or first-line managers Engineering Leadership - Track record of owning production systems: on-call programs, incident management, SLOs - Experience establishing delivery quality practices: acceptance criteria, review standards, release discipline - Proven ability to set architectural direction while staying out of the critical path - Experience running roadmap and prioritization processes across multiple teams Technical Skills & Domain Expertise - Strong background in data-intensive systems: streaming and log pipelines (Kafka, Logstash), analytical data stores (ClickHouse, MySQL), and parsing/enrichment (GROK) - Proficiency with Go and Python service development, SQL, Git, and CI/CD tooling (Argo or similar) - Experience with LLM/agent infrastructure: building or overseeing agentic workflows, model integration, or AI-assisted automation in production - Working knowledge of the detection and response domain: how SOCs, detection engineering, and threat intelligence teams operate, how analysts work alerts, hunt, and manage cases, and what they need from their tooling Collaboration & Influence - Experience operating across organizational boundaries with shared infrastructure and platform teams - Strong written communication: design documents, roadmaps, and decision records - Ability to represent engineering trade-offs to security practitioners and security needs to engineering organizations ## Nice to Have - Experience at a security vendor building detection, SIEM, SOAR, or intelligence products - Experience in an enterprise detection & response organization that built its own tooling - Experience with MSP/MSSP or multi-tenant platform delivery ## About Todyl ## Company Overview - **One-liner**: Todyl provides a unified cybersecurity platform integrating SASE, SIEM, endpoint security, GRC, and MXDR, delivered exclusively through managed service providers (MSPs) to protect small and mid-sized businesses. - **Entity Type**: Private (Series B) - **Headquarters**: Denver, Colorado, USA - **Founded**: 2015 - **Founders**: John Nellen, Chris Weibel, and James Pellizzi ## Core Business - **Primary industry**: Cybersecurity - **Target customers**: B2B – specifically Managed Service Providers (MSPs), IT professionals, and security professionals who serve small and medium-sized businesses (SMBs) across healthcare, financial services, manufacturing, and education sectors. - **Mission statement**: “Empower every business with the tools, insights, and automation needed to defend against ever-changing threats.” Also expressed as “Protect the builders.” ## Products & Services - **Todyl Platform (V2)**: A cloud-native, single-agent unified platform that combines Secure Access Service Edge (SASE), Security Information and Event Management (SIEM), Endpoint Detection and Response (EDR) + Next-Gen Antivirus (NGAV), Governance, Risk, and Compliance (GRC), and Managed Extended Detection and Response (MXDR) into one offering. - **Janus (Agentic AI)**: An AI-powered tool for automated incident investigation launched in 2026. - **Unified Assurance**: A new offering launched in 2026 combining security and cyber insurance assurance for MSPs. - **Todyl Marketplace**: A platform launched in April 2026 enabling MSPs and businesses to access unified security and assurance services. ## Market Standing - **Valuation/Market Cap**: Not publicly disclosed. - **Key Metric**: Total funding raised is **$80.3M** (as of Series B). - **Notable Investors/Partners**: TechOperators, Anthos Capital, StoneMill Ventures, Base10 Partners, and Blu Venture Investors. - **Growth Signals**: - Raised a **$50M Series B** in 2024. - Opened a new office in **Augusta, GA** in 2024. - Moved into a dedicated HQ in Denver in 2023. - Launched multiple new products (Unified Assurance, Janus AI, Marketplace) in 2025–2026. - Holds 1 patent. ## Competitive Advantages - **Channel-only model**: Todyl never competes with its MSP partners, positioning itself as a true partner rather than a direct seller. - **Unified platform**: Combines SASE, SIEM, EDR, GRC, and MXDR into a single cloud-native, single-agent platform, reducing complexity and cost for SMBs. - **Focus on SMBs**: Delivers enterprise-grade security tailored for small and mid-market businesses, a segment often underserved by large cybersecurity vendors. - **24/7 expert support**: Backed by a dedicated MXDR team and strong channel support (GTM, technical, and security resources). ## Strategic Focus - **Product expansion**: Continuing to launch new integrated offerings (Assurance, AI-driven investigation, Marketplace) to deepen the platform’s value. - **Channel growth**: Scaling partner programs, training, and enablement to drive MSP adoption and revenue. - **Geographic expansion**: Growing presence with offices in Denver (HQ) and Augusta, GA, and hiring across the U.S. - **Innovation in AI**: Leveraging agentic AI (Janus) to automate security operations for partners. ## Why Work Here - **Culture**: Values include “Security First” and “Protect the Builders.” The company emphasizes a collaborative, high-performance culture with cross-functional teamwork. - **Work policy**: Hybrid and remote options available depending on role. The Denver and Augusta offices are “fully stocked” to catalyze in-person collaboration. Some roles (e.g., Sales Development Representative) are in-office, while engineering roles (e.g., Staff Software Engineer) can be remote or hybrid. - **Career growth**: Todyl promotes unmatched career growth opportunities, role-based training, and enablement. Employees are encouraged to lead innovation in security. - **Perks**: Fully stocked offices, role-based training, and a focus on work-life balance with flexible arrangements. ## Sources 1. [todyl.com](https://www.todyl.com/) 2. [todyl.com/about-us](https://www.todyl.com/about-us) 3. [todyl.com/careers](https://www.todyl.com/careers) 4. [builtin.com](https://builtin.com/company/todyl) 5. [cbinsights.com](https://www.cbinsights.com/company/todyl) ## Other roles at Todyl - [Site Reliability Engineer II](https://feeny.ai/job/site-reliability-engineer-ii-todyl-denver-nw1fk7v8a2c1) — Denver, CO - [Account Executive](https://feeny.ai/job/account-executive-todyl-denver-yns26341kyb5) — Denver, CO - [Detection & Response Account Manager I](https://feeny.ai/job/detection-response-account-manager-i-todyl-augusta-sptbmq44cjs5) — Augusta, GA - [Staff Software Engineer - Data Engineering](https://feeny.ai/job/staff-software-engineer-data-engineering-todyl-denver-s8bx50c3eam8) — Denver, CO - [Tier III – Technical Support & Network Engineer](https://feeny.ai/job/tier-iii-technical-support-network-engineer-todyl-atlanta-zrtpbwa6w7h4) — Atlanta, GA - [Quality Assurance Engineer (Web Portal)](https://feeny.ai/job/quality-assurance-engineer-web-portal-todyl-denver-2hvtpt0pzm02) — Denver, CO