Senior information security manager leading operations, application, cloud, and AI security. Securing Benevity’s technology platform for corporate social-impact programs.
Responsibilities
Lead and coach a multi-disciplinary security team, including team development and hiring
Own critical security KPIs and drive continuous improvement
Drive the information security roadmap and manage security vendors in alignment with CISO strategy
Oversee security operations and incident response as senior escalation lead during major events
Hold external security partners and MDR providers accountable for coverage, triage quality, and response
Establish AI security standards for LLM integrations, RAG pipelines, and agentic workflows using OWASP and MITRE ATLAS
Operationalize AI for security triage, threat detection, investigation, and reporting
Embed security into the SDLC through CI/CD automation, SAST/SCA/DAST tooling, secure API patterns, and threat modeling
Maintain the enterprise security risk register and vulnerability management lifecycle, prioritizing remediation by real-world risk
Direct corporate security hygiene, phishing simulations, security awareness training, and the Responsible Disclosure Program
Partner with DevOps and GRC on infrastructure-as-code security, audit compliance, and posture metrics
Requirements
10+ years of progressive experience in information security, including 5+ years leading teams
Experience managing managers and individual contributors, with a track record of developing both
Breadth across security operations, product and application security, and cloud security
Hands-on experience managing security operations on AWS and other cloud providers
Hands-on experience leading major incident response as incident commander
Practical understanding of AI and LLM security risks, including OWASP Top 10 for LLMs, prompt injection, and agentic systems
Evidence-based understanding of AI’s value and limitations in security work and production readiness
Working knowledge of SAST, SCA, DAST, API and microservices security
Deep understanding of cloud security, threat detection, and attacker tactics in containerized, API-driven environments
Hands-on WAF experience
Experience owning budgets, vendor selection, and managed-service relationships
Experience building or scaling security awareness and developer security champions programs
Familiarity with NIST CSF, ISO 27001, SOC 2 Type II, CIS Controls, and OWASP SAMM or BSIMM
Strong problem-solving and analytical skills
Ability to communicate security concepts to technical and non-technical audiences
Bachelor's degree in Computer Science, Information Security, or equivalent practical experience
Relevant certifications such as CISSP, CISM, or GCIH are nice to have
IC-level credentials such as OSCP, CSSLP, or GWAPT are nice to have
Prior SaaS product-company experience is nice to have
Experience in a regulated or high-trust environment is nice to have
Benefits
Flexible hybrid approach to where we work
No set requirement for in-office time for those located near an office
Growth opportunities
Caring co-workers
Employee resource groups
Investment in diversity, equity, inclusion and belonging
Accessible hiring process and accommodations for candidates with disabilities
TD bank security lead overseeing audits, technology controls, and operational compliance for Business Banking platforms. Automating audit response and managing security risk remediation.
Senior security professional overseeing Canadian government contract security, controlled goods, audits, and clearances. Supporting Honeywell’s automation, aerospace, energy, and industrial solutions.
Senior Information Security Manager leading security operations, application security, and AI security. Protecting Benevity’s cloud - native platform that helps companies and employees take social action.
Conseiller senior en architecture de sécurité chez Exposant 3, firme de conseil en affaires et technologies de l’information. Évaluation des risques, gouvernance et architectures de sécurité numérique.
Conseiller senior en sécurité de l’information chez Exposant 3, firme de conseil en gestion et technologies. Gouvernance, risques, conformité et gestion des identités pour des projets d’envergure.
Conseiller en solution de sécurité chez Exposant 3, firme de conseil en TI et transformation numérique. Analyse des risques, durcissement des environnements et automatisation PowerShell.
Lead agentic AI cybersecurity initiatives, building automated vulnerability discovery and remediation pipelines. Requires deep expertise in offensive security, software engineering, and AI tools.
Security director at Intact, an insurer, protecting customer and broker digital channels and third - party risk platforms. Leading technical teams, governance, strategy, and security operations.