Security Operations Team Lead building Safe Software’s cybersecurity operations for FME, its enterprise data integration platform. Leading incident response, security tooling, compliance, and team growth.
Responsibilities
Build and lead the security operations team, including hiring, onboarding, coaching, performance, and career development
Own the incident response program end to end, including processes, runbooks, on-call rotation, tabletop exercises, and post-incident reviews
Act as incident commander for significant events and carry a share of the on-call rotation
Own the security operations roadmap and delivery, translating strategy into prioritized, resourced work with clear outcomes
Report on progress, risk, and support needs
Drive maturity of automated patch management, CIS benchmark adoption, system hardening, configuration management, device trust, conditional access, vulnerability management, and resiliency planning
Set technical direction for security tooling, including Rapid7 InsightVM, InsightIDR, Cisco Secure Endpoint, Cisco Umbrella, Active Directory, JumpCloud, Google Workspace, and AWS security controls
Define and track detection and response times, remediation SLAs, hardening and patch coverage, and alert quality
Champion AI and automation across security workflows and establish guardrails for AI use
Own Security Operations' contribution to ISO 27001, SOC 2, and future compliance frameworks
Partner with IT and teams across Safe to embed security into existing workflows
Represent Security Operations to leadership and communicate risk, incidents, and program status to technical and non-technical audiences
Requirements
5+ years in security operations, incident response, or a closely related security engineering discipline
1–2 years leading a team as a manager, team lead, or technical lead with formal ownership of others' work
Meaningful ownership of a security program taken from immature to reliably operating
Deep hands-on SIEM and EDR experience, including building and tuning detections, running investigations, and improving signal-to-noise
Strong incident response background, including leading or coordinating significant incident response, post-incident reviews, and maintaining runbooks
Familiarity with MITRE ATT&CK
Practical experience with vulnerability and patch management at scale
Experience with hardening and configuration management against a recognized standard such as the CIS Benchmarks
Solid network security knowledge, including protocols, architecture, and securing on-premises and cloud environments
Solid cloud security knowledge, ideally AWS, including IAM, logging, network controls, and posture management
Experience securing and administering a cloud productivity suite such as Google Workspace
Working knowledge of identity and access: SSO, MFA, conditional access, device trust, and least-privilege design
Experience supporting or operating controls for ISO 27001, SOC 2, or comparable frameworks
Comfort with compliance evidence and audits
Excellent written and verbal communication
Desired: Direct experience with Rapid7 InsightVM, Rapid7 InsightIDR, Google Workspace security and admin, Active Directory, AWS, Cisco Umbrella, and Cisco Secure Endpoint
Desired: Experience standing up or significantly maturing an incident response program, including on-call design and tabletop exercises
Desired: Experience building AI or automation into security operations
Desired: Experience with business continuity, disaster recovery, or resiliency planning
Desired: Experience hiring, growing, and developing a technical team from a small base
Desired: Scripting or development skills in Python, PowerShell, or similar
Desired: Relevant certifications or a plan to complete CISSP, CISM, GIAC, or equivalent
A Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field is listed as a desired skill/bonus point, not a requirement
Legally eligible to work in Canada
Benefits
Offers bonus
Paid time off to volunteer for Safe-organized opportunities
Annual learning budget
Training programs paid for by Safe
Flexible working hours
Flexible and remote-friendly work arrangements
3 weeks of vacation
Additional paid 6 seasonal days off per year
Extended health benefits from day 1
Dental benefits from day 1
Health or lifestyle spending benefits from day 1
Counseling benefits from day 1
Parental Leave Top-Up Program for new parents through childbirth or adoption
Cyber Defender protecting Ontinue’s AI - powered MXDR customers through SOC threat detection and response. Investigating threats across identity, endpoint, network, and cloud environments.
SOC analyst monitoring and responding to cyber threats for Wepoint’s digital transformation clients. Investigating escalated alerts and improving 24×7 security operations.
SOC cybersecurity analyst monitoring and responding to cyber threats for Wepoint’s digital transformation clients. Improving 24×7 detection, investigation, and incident response capabilities.
Senior Security Operations Engineer monitoring incidents and leading forensics for Samsara’s IoT - connected operations platform. Building security automation and supporting insider - threat investigations.
Senior SOC analyst leading threat detection, investigations, and incident response for Financeit, a Canadian point - of - sale financing provider. Building its new SOC’s automation, AI - threat coverage, and operational standards.