Director leading incident management, vulnerability operations, and technology risk reporting at Lightspeed. Enabling executive decisions for a global cloud commerce platform.
Responsibilities
Establish a consistent Product & Technology-wide incident management framework with standards, roles, severity definitions, escalation paths, communications, and follow-through expectations
Consolidate existing incident practices across teams while preserving effective approaches
Strengthen post-incident practices by assigning and tracking actions through completion
Partner with Engineering and Security leaders to improve incident readiness, response effectiveness, and operational resilience
Strengthen operating mechanisms for security incidents and vulnerability management, including intake, prioritization, ownership, remediation tracking, escalation, and reporting
Provide visibility into material vulnerabilities, remediation progress, aging, exceptions, and leadership intervention needs
Connect security incidents and vulnerabilities to broader incident, risk, and executive reporting mechanisms
Identify recurring process, ownership, or control breakdowns and drive cross-functional improvements
Build mechanisms for actionable views of material technology and operational risks, trends, mitigations, and required decisions
Partner with owners across responsible AI, application and infrastructure security, digital supply-chain risk, identity and access management, Zero Trust, data protection, shadow IT/AI, security compliance, and operational resilience
Translate complex risk information into priorities, tradeoffs, and actions
Identify patterns across incidents, vulnerabilities, and risk signals to inform priorities and systemic improvement
Define metrics and reporting for incident health, vulnerability exposure, remediation progress, risk trends, and operational resilience
Develop executive-level views and materials for CTO, Security leadership, and board-committee discussions
Improve communications across technical teams, business stakeholders, executives, and partners
Lead complex cross-functional work across Engineering, Security, Product, Legal, Compliance, and other teams through influence
Create ownership and accountability for cross-functional actions
Establish operating cadences that advance material incidents, vulnerabilities, and risks toward resolution
Continuously improve processes, tooling, data, and organizational interfaces
Set the vision and operating model for incident management and technology risk operations within P&T Operations
Build partnerships with Engineering and Security leadership and advise on operational readiness, risk visibility, and organizational response
Develop the capabilities, processes, and team as the scope matures while remaining hands-on when needed
Requirements
Significant experience leading incident management, technology operations, security operations, risk programs, or a closely related function in a complex technology organization
Demonstrated experience designing or materially improving incident management processes, standards, communications, reporting, and post-incident follow-through across multiple teams
Working knowledge of security incident response and vulnerability management
Ability to partner credibly with Security and Engineering leaders without needing to be the deepest technical expert in every domain
Experience building executive-level risk, incident, or operational reporting
Strong understanding of how technology and security risks are identified, prioritized, mitigated, tracked, and communicated in an enterprise environment
Experience leading cross-functional change and driving accountability across teams without direct authority
Strong executive communication skills, including judgment to tailor communications for technical teams, senior executives, and board-level audiences
Ability to bring structure to ambiguity, identify systemic issues, and build durable operating mechanisms
Strong judgment, calm under pressure, and ability to operate effectively during high-severity or high-visibility incidents
Collaborative leadership style and ability to build trust across Product, Engineering, Security, Legal, Compliance, and executive leadership
Applicants must disclose any criminal convictions; criminal record checks are part of the hiring process
Legal eligibility to work in Canada and visa sponsorship requirements may apply
Benefits
Continuous learning opportunities
Global mobility
Benefits designed to support employees
Diverse and inclusive team
Accommodations available on request for candidates with disabilities
Restricted Insurance Agency Licensing Analyst reviewing and approving insurance agency licences for British Columbia’s regulator. Managing applications, amendments, compliance reviews, and stakeholder guidance on a 24 - month contract.
Senior Analyst strengthening operational risk management at BDC, Canada’s bank dedicated to entrepreneurs. Improving risk frameworks, controls, reporting, and resilience across the organization.
Senior advisor pricing group insurance products for Desjardins Group. Setting renewal and contract rates while supporting growth, profitability and client decisions.
Senior P&C insurance advisor leading complex strategic projects for Desjardins. Advising stakeholders and shaping insurance policies, programs, and initiatives.
Senior underwriting manager analyzing and authorizing complex commercial loans for BDC, the bank dedicated to Canadian entrepreneurs. Applying credit judgment, structuring financing, and supporting responsible portfolio growth.
Commercial insurance agent evaluating business risks and managing quotes, renewals, and policy changes for Beneva. Advising clients and affiliated agents on business insurance coverage.
ERM intern using AI, programming, and analytics to manage fraud risk at AIMCo, Alberta’s investment manager. Supporting fraud assessments, risk registers, and enterprise risk software.