Senior Information Security Manager leading security operations, application security, and AI security. Protecting Benevity’s cloud-native platform that helps companies and employees take social action.
Responsibilities
Lead and coach a multi-disciplinary security team
Drive team development, hiring, and a sustainable operating cadence
Own critical security KPIs and continuously improve security posture metrics
Drive the information security roadmap and manage security vendors in alignment with CISO strategy
Oversee end-to-end security operations and incident response
Serve as senior escalation lead during major security events
Hold external security partners, including MDR providers, accountable for coverage, triage quality, and rapid response
Establish AI security standards for LLM integrations, RAG pipelines, and agentic workflows using OWASP and MITRE ATLAS
Operationalize AI for triage, threat detection, investigation, and reporting
Embed security into the SDLC through CI/CD automation, SAST/SCA/DAST tooling, secure API patterns, and threat modeling
Maintain the enterprise security risk register and vulnerability management lifecycle
Prioritize remediation based on real-world risk
Direct corporate security hygiene, phishing simulations, security awareness training, and the Responsible Disclosure Program
Partner with DevOps and GRC on infrastructure-as-code security, audit compliance, and posture metrics
Requirements
10+ years of progressive experience in information security, including 5+ years leading teams
Experience managing managers and individual contributors
Breadth across security operations, product and application security, and cloud security
Hands-on experience managing security operations on AWS and other cloud providers
Hands-on experience leading major incident response as incident commander
Practical understanding of AI and LLM security risks, including OWASP Top 10 for LLMs, prompt injection, and agentic systems
Working knowledge of SAST, SCA, DAST, API and microservices security
Deep understanding of cloud security, threat detection, and modern attacker tactics in containerized, API-driven environments
Hands-on WAF experience
Experience owning budgets, vendor selection, and managed-service relationships
Experience building or scaling security awareness and developer security champions programs
Familiarity with NIST CSF, ISO 27001, SOC 2 Type II, CIS Controls, and OWASP SAMM or BSIMM
Strong problem-solving and analytical skills
Ability to communicate security concepts to technical and non-technical audiences
Strong ownership and accountability
Bachelor's degree in Computer Science, Information Security, or equivalent practical experience
Relevant certifications such as CISSP, CISM, or GCIH are nice to have
IC-level credentials such as OSCP, CSSLP, or GWAPT are nice to have
Prior SaaS product company experience is nice to have
Experience in a regulated or high-trust environment is nice to have
Benefits
Flexible hybrid approach to where employees work
Innovative work
Growth opportunities
Caring co-workers
Employee resource groups
Equal opportunities and accessible hiring process
Accommodations throughout the hiring or assessment process
TD bank security lead overseeing audits, technology controls, and operational compliance for Business Banking platforms. Automating audit response and managing security risk remediation.
Senior security professional overseeing Canadian government contract security, controlled goods, audits, and clearances. Supporting Honeywell’s automation, aerospace, energy, and industrial solutions.
Senior information security manager leading operations, application, cloud, and AI security. Securing Benevity’s technology platform for corporate social - impact programs.
Conseiller senior en architecture de sécurité chez Exposant 3, firme de conseil en affaires et technologies de l’information. Évaluation des risques, gouvernance et architectures de sécurité numérique.
Conseiller senior en sécurité de l’information chez Exposant 3, firme de conseil en gestion et technologies. Gouvernance, risques, conformité et gestion des identités pour des projets d’envergure.
Conseiller en solution de sécurité chez Exposant 3, firme de conseil en TI et transformation numérique. Analyse des risques, durcissement des environnements et automatisation PowerShell.
Lead agentic AI cybersecurity initiatives, building automated vulnerability discovery and remediation pipelines. Requires deep expertise in offensive security, software engineering, and AI tools.
Security director at Intact, an insurer, protecting customer and broker digital channels and third - party risk platforms. Leading technical teams, governance, strategy, and security operations.