Senior Manager, Information Security

Posted yesterday

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Senior Information Security Manager leading security operations, application security, and AI security. Protecting Benevity’s cloud-native platform that helps companies and employees take social action.

Responsibilities

  • Lead and coach a multi-disciplinary security team
  • Drive team development, hiring, and a sustainable operating cadence
  • Own critical security KPIs and continuously improve security posture metrics
  • Drive the information security roadmap and manage security vendors in alignment with CISO strategy
  • Oversee end-to-end security operations and incident response
  • Serve as senior escalation lead during major security events
  • Hold external security partners, including MDR providers, accountable for coverage, triage quality, and rapid response
  • Establish AI security standards for LLM integrations, RAG pipelines, and agentic workflows using OWASP and MITRE ATLAS
  • Operationalize AI for triage, threat detection, investigation, and reporting
  • Embed security into the SDLC through CI/CD automation, SAST/SCA/DAST tooling, secure API patterns, and threat modeling
  • Maintain the enterprise security risk register and vulnerability management lifecycle
  • Prioritize remediation based on real-world risk
  • Direct corporate security hygiene, phishing simulations, security awareness training, and the Responsible Disclosure Program
  • Partner with DevOps and GRC on infrastructure-as-code security, audit compliance, and posture metrics

Requirements

  • 10+ years of progressive experience in information security, including 5+ years leading teams
  • Experience managing managers and individual contributors
  • Breadth across security operations, product and application security, and cloud security
  • Hands-on experience managing security operations on AWS and other cloud providers
  • Hands-on experience leading major incident response as incident commander
  • Practical understanding of AI and LLM security risks, including OWASP Top 10 for LLMs, prompt injection, and agentic systems
  • Working knowledge of SAST, SCA, DAST, API and microservices security
  • Deep understanding of cloud security, threat detection, and modern attacker tactics in containerized, API-driven environments
  • Hands-on WAF experience
  • Experience owning budgets, vendor selection, and managed-service relationships
  • Experience building or scaling security awareness and developer security champions programs
  • Familiarity with NIST CSF, ISO 27001, SOC 2 Type II, CIS Controls, and OWASP SAMM or BSIMM
  • Strong problem-solving and analytical skills
  • Ability to communicate security concepts to technical and non-technical audiences
  • Strong ownership and accountability
  • Bachelor's degree in Computer Science, Information Security, or equivalent practical experience
  • Relevant certifications such as CISSP, CISM, or GCIH are nice to have
  • IC-level credentials such as OSCP, CSSLP, or GWAPT are nice to have
  • Prior SaaS product company experience is nice to have
  • Experience in a regulated or high-trust environment is nice to have

Benefits

  • Flexible hybrid approach to where employees work
  • Innovative work
  • Growth opportunities
  • Caring co-workers
  • Employee resource groups
  • Equal opportunities and accessible hiring process
  • Accommodations throughout the hiring or assessment process

Job type

Full Time

Experience level

Senior

Salary

Not specified

Degree requirement

Bachelor's Degree

Tech skills

AWSCloudMicroservicesSDLC

Location requirements

HybridCalgaryCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.