Manager, Security Operations

atForward FinancingRemoteCA flagCanadaFull-timeSecurity OperationsSeniorLeadC$172k – C$237k/year

Posted Aug 18

This is a fully remote position, open to applicants in Canada.

📋 Description

• Recruit, nurture, and enhance a team of security engineers tasked with defending endpoints, SaaS, and infrastructure.

• Take ownership of corporate systems security, focusing on configuration hardening and overseeing vulnerabilities and patches.

• Direct security operations and incident response as the senior Incident Commander for the SIRT.

• Manage and optimize the detection and response funnel, along with the CrowdStrike detection platform.

• Develop and sustain detection coverage across endpoints, SaaS, identity, logs, proxy traffic, DLP events, and access trails.

• Collaborate with teams to establish network allowlists, egress proxies, and proxy-level DLP controls.

• Work alongside AppSec to identify detection opportunities arising from penetration tests.

• Define detection and response quality standards and coverage metrics, and provide reporting on these metrics.

• Conduct comprehensive cybersecurity risk assessments across the enterprise.

• Enhance Forward's AI security capabilities, including the development of detection tools, response processes, and a specialized team.


⛳️ Requirements

• A minimum of 7 years in detection engineering, security operations, or incident response, with leadership experience.

• Profound understanding of adversary TTPs, MITRE ATT&CK, event correlation, and the design of high-signal detection.

• Practical experience with EDR/SIEM platforms and detection-as-code methodologies.

• Experience in incident command encompassing triage, containment, forensics, and communication with stakeholders under pressure.

• Background in securing SaaS environments and endpoint fleets, with a focus on configuration management, access governance, and vulnerability/patch management.

• Strong ability to articulate risk and priorities to both engineers and executives.

• Expertise in cloud control-plane monitoring and identity threat detection using AWS.

• Proficiency in scripting or automation using Python, Ruby, or Go.

• Bachelor’s Degree in Computer Science or a comparable technical field, or equivalent professional experience.

• Familiarity with SSPM or CASB tools.

• Preferred experience in Gen-AI triage or LLM-as-Judge production.

• CISSP and/or CISM certification is preferred.

• Exposure to red-team operations is preferred.

• Must have authorization to work for any employer in the US, as indicated in the application form.


🏝️ Benefits

• Annual bonus potential of 12%

• Medical insurance

• Dental insurance

• Vision insurance

• Flexible time-off policy

• Paid parental leave

• RRSP match

• Wellness reimbursement

• Volunteering days

• Annual professional development budget

• Charitable donation match

• Flexible hours

• Remote-first workplace flexibility

• Access to premiere office locations

• Virtual and in-person team events

People also viewed

Sentinel Blue10 hours ago

SOC Analyst II

US flagUnited States OnlyFull-timeSecurity Operations$70k – $80k/year
ApplyView job
It4us Cyber Security15 hours ago

SecOps Analyst

BR flagBrazil OnlyFreelanceSecurity Operations
ApplyView job
Malwarebytes1 day ago

Manager, Information Security Operations

US flagUnited States OnlyFull-timeSecurity Operations$133k – $190k/year
ApplyView job
ThreatDown1 day ago

Manager, Information Security Operations

US flagUnited States OnlyFull-timeSecurity Operations$133k – $190k/year
ApplyView job
Ontinue1 day ago

Cyber Defender – SOC Analyst

CA flagCanada OnlyFull-timeSecurity Operations
ApplyView job
Unifique1 day ago

SOC Analyst

BR flagBrazil OnlyFull-timeSecurity Operations
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers