
Manager, Security Operations
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Canada.
• Recruit, nurture, and enhance a team of security engineers tasked with defending endpoints, SaaS, and infrastructure.
• Take ownership of corporate systems security, focusing on configuration hardening and overseeing vulnerabilities and patches.
• Direct security operations and incident response as the senior Incident Commander for the SIRT.
• Manage and optimize the detection and response funnel, along with the CrowdStrike detection platform.
• Develop and sustain detection coverage across endpoints, SaaS, identity, logs, proxy traffic, DLP events, and access trails.
• Collaborate with teams to establish network allowlists, egress proxies, and proxy-level DLP controls.
• Work alongside AppSec to identify detection opportunities arising from penetration tests.
• Define detection and response quality standards and coverage metrics, and provide reporting on these metrics.
• Conduct comprehensive cybersecurity risk assessments across the enterprise.
• Enhance Forward's AI security capabilities, including the development of detection tools, response processes, and a specialized team.
• A minimum of 7 years in detection engineering, security operations, or incident response, with leadership experience.
• Profound understanding of adversary TTPs, MITRE ATT&CK, event correlation, and the design of high-signal detection.
• Practical experience with EDR/SIEM platforms and detection-as-code methodologies.
• Experience in incident command encompassing triage, containment, forensics, and communication with stakeholders under pressure.
• Background in securing SaaS environments and endpoint fleets, with a focus on configuration management, access governance, and vulnerability/patch management.
• Strong ability to articulate risk and priorities to both engineers and executives.
• Expertise in cloud control-plane monitoring and identity threat detection using AWS.
• Proficiency in scripting or automation using Python, Ruby, or Go.
• Bachelor’s Degree in Computer Science or a comparable technical field, or equivalent professional experience.
• Familiarity with SSPM or CASB tools.
• Preferred experience in Gen-AI triage or LLM-as-Judge production.
• CISSP and/or CISM certification is preferred.
• Exposure to red-team operations is preferred.
• Must have authorization to work for any employer in the US, as indicated in the application form.
• Annual bonus potential of 12%
• Medical insurance
• Dental insurance
• Vision insurance
• Flexible time-off policy
• Paid parental leave
• RRSP match
• Wellness reimbursement
• Volunteering days
• Annual professional development budget
• Charitable donation match
• Flexible hours
• Remote-first workplace flexibility
• Access to premiere office locations
• Virtual and in-person team events
Zepto
Forward Financing
Included Health
phia, LLC
Get handpicked remote jobs straight to your inbox weekly.