30 Jul
|
Payscale
|
Canada
Who you are
- 10+ years in information security, including 4+ years in a lead or management role
- Across security engineering and/or security operations functions
- Proven people-management track record: direct reports, performance cycles, and
- Team development in a security context
- Expert, hands-on knowledge of both security engineering (controls design,
- Automation, tooling integration) and security operations (detection, incident
- Response) — capable of acting as architect, engineer, incident handler, lead, and
- Manager
- Experience with the CrowdStrike Falcon platform (EDR, Identity Protection, Data
- Protection, AIDR, ZTA, Exposure Management) and SIEM/SOAR orchestration
- Demonstrated experience owning or managing an MDR or MSSP vendor
- Relationship
- Solid foundation in cloud security (AWS preferred), endpoint security, identity and
- Access management, and zero-trust architecture
- Strong experience in vulnerability and exposure management and
- Mitigation/remediation strategies
- Scripting and automation ability in PowerShell, Python, or Bash; comfortable with
- Detection-as-code and infrastructure-as-code approaches
- Experience with the MITRE ATT&CK; framework and the ability to map operational
- Data to TTPs for structured threat analysis
- Experience building operational, engineering, and vulnerability metrics and
- Management reporting, and driving improvement through a regular reporting
- Cadence
- Experience with zero-trust networks and platforms such as Cloudflare, Zscaler, or
- AppGate
- Experience with Data Loss Prevention and CASB architectures and tooling such as
- Forcepoint, Netskope, or Zscaler
- Familiarity with SOAR and automation platforms such as Tines, n8n, or Ansible
- Certifications such as CISSP or CISM
- Experience in a remote-first SaaS and/or PE-backed environment
What the job involves
- The Director, Security Engineering & Operations directs, manages, and leads Payscale’s
- Security Engineering and Eecurity Operations functions. This is a hands-on leadership role:
- The Director sets strategy and manages the team while remaining directly engaged in
- Architecture, tooling, automation, and incident command.
Responsibilities span the design
- And hardening of security controls, threat detection and incident response, vulnerability
- And exposure management, endpoint and identity protection, and security automation
- Across Payscale’s corporate, cloud, and hosting environments. The Director owns
- Payscale’s MDR relationship and is accountable for the maturity, performance, and
- Roadmap of both functions
- This role reports to the CISO, VP - Cybersecurity & Enterprise Technology
- Direct, manage, and lead the security engineering and security operations team
- Members; own hiring, onboarding, performance reviews, and career development
- Plans aligned to Payscale’s Information Security Career Ladder
- Set strategy and quarterly/annual objectives for both functions and translate them
- Into a prioritized, measurable roadmap; hold regular 1:1s and team connects to
- Maintain a high-performance, feedback-rich culture
- Mentor engineers and analysts at all career levels, providing task-based directives,
- Technical coaching, and growth-oriented feedback
- Own the on-call rotation and after-hours escalation path across both functions,
- Ensuring coverage for time-sensitive detection and response
- Serve as a working leader — remaining hands-on in engineering, architecture, and
- Incident response rather than leading solely through delegation
- Security Engineering
- Own the design, implementation, and continuous hardening of security controls
- Across corporate, cloud, and hosting environments
- Build and maintain security automation and integrations — SOAR, detection-as-
- Code, and infrastructure-as-code guardrails — to scale coverage without adding
- Headcount
- Engineer and operate the security tooling stack (EDR/XDR, SIEM, identity
- Protection, DLP/CASB, vulnerability scanning), ensuring platforms are well-
- Integrated and meet architectural standards
- Partner with Engineering and Infrastructure to embed “secure by design” into
- CI/CD, cloud architecture, and product development
- Drive adoption of a zero-trust methodology across identity, endpoint, network, and
- Application layers
- Lead security engineering for enterprise AI and agentic tooling adoption, building
- Controls and guardrails for safe internal use
- Drive the threat detection and incident response capability: detection engineering,
- Playbook development, tabletop exercises, and continuous improvement of
- MTTA/MTTR metrics
- Lead or oversee incident response events as the designated incident manager for
- Significant or multi-team incidents, running incident command end-to-end
- Own the MDR relationship, holding the provider accountable to SLAs, coverage,
- And response outcomes
- Extend detection and response to secure enterprise AI and agentic tooling
- Adoption
- Own the vulnerability and exposure management function across all corporate and
- Hosting environments, coordinating cross-functionally on mitigation and
- Remediation with clear SLAs
- Expand security monitoring, visibility, and coverage using existing platforms and
- Open-source tooling
- Program, Metrics & Stakeholder Engagement
- Own the security engineering and operations portion of the Information Security
- Program roadmap, delivering operational metrics, risk-posture data, and capacity
- Analysis
- Establish and report security KPIs to technology and executive leadership on a
- Regular cadence
- Collaborate with the GRC team on ISO 27001 and SOC 2 evidence, control
- Effectiveness, and audit readiness as it relates to security engineering and
- Operations
- Lead technical evaluations of emerging security vendors and technologies; provide
- Buy/build/partner recommendations to technology management
- Represent security engineering and operations in cross-functional product,
- Engineering, and infrastructure initiatives, ensuring security requirements are
- Incorporated by design
Benefits
- Flexible paid time off (PTO)
- Paid holidays and floating holidays
- 16 weeks paid parental leave
- Company-sponsored volunteer hours
- Complimentary days off based on meeting company goals
- Comprehensive medical, dental, and vision, covered up to 100% by Payscale
- Life and disability insurance, covered up to 100% by Payscale
- Employee assistance program
- Flexible spending account
- Infertility benefits
- Company matched and immediately vested 401k
- Paid development hours
- Learning and development opportunities
- Regular pportunities to meet with executive leadership
- Annual remote work stipend for wellness or home office equipment
📌 Director of Security Engineering & Operations (Canada)
🏢 Payscale
📍 Canada