13 Aug
|
Equinix
|
Toronto
We are looking for a Product Manager, SecOps to lead the strategy, roadmap, and adoption of security capabilities embedded directly into our engineering ecosystem This is not a policy-writing or governance role. It is a product role focused on making security scalable, automated, developer-friendly, and measurable Security Operations depends on tight coordination between the teams that build and manage security capabilities and the teams that use those capabilities to detect and respond to threats This Product Manager role creates a single product owner for that boundary, ensuring detections, automation, telemetry onboarding, and platform changes are production-ready, governed, measurable, and adopted by analysts and responders End-to-end detection lifecycle: Drive the process from threat-informed idea generation through rule development, testing, deployment, tuning, analyst adoption, and retirement SecOps backlog prioritization: Maintain and prioritize a shared roadmap across telemetry onboarding, detection content, SOAR playbooks, analyst workflows, and platform enhancements Operational readiness: Ensure new capabilities launch with runbooks, ownership, success criteria, training, support processes, documentation, and release criteria Cross-team process improvement: Identify and reduce friction in handoffs between engineering and operations, resolving delivery blockers and unclear ownership Platform value realization: Translate security platform capabilities into measurable outcomes, including improved alert quality, faster response, broader telemetry coverage, and higher automation effectiveness Stakeholder alignment: Create clear decision-making forums and communication rhythms across security engineering, monitoring and response, incident management, and threat intelligence Key areas of focus: Detection and rule lifecycle: Own the product process for how detections move from concept to value, including intake, prioritization, test standards, analyst validation, tuning, coverage review, readiness criteria, handoff quality, false-positive trends, alert fidelity, and lifecycle decisions Telemetry and log onboarding strategy:
Prioritize log sources, parser improvements, and schema normalization based on risk, coverage gaps, investigative value, analyst needs, concrete use cases, dependencies, sequencing, and effort tradeoffs SOAR and automation governance: Scale automation safely by improving how ideas are submitted, reviewed, built, tested, approved, and adopted; clarify ownership, controls, approvals, adoption measures, success rates, analyst time savings, and failure patterns Platform roadmap and feature adoption: Partner with technical leaders to shape adoption of SIEM, SOAR, and AI-assisted operational capabilities, including rollout plans, operational testing, enablement, success metrics, detection-as-code, composite detections, and standardized content management Metrics, reporting, and operating cadence: Define KPIs, health dashboards, and recurring reviews for detection quality, onboarding throughput, automation effectiveness, operational readiness, roadmap priorities, launch readiness, and post-launch performance What you’ll do: Own and maintain the SecOps product roadmap across shared engineering and operations priorities Partner with leaders in detection engineering, monitoring and response, incident management, and threat intelligence to define quarterly objectives Facilitate prioritization decisions for detections, log sources, automations, integrations, and workflow improvements Define launch criteria for new security content and capabilities, including documentation, training, support model, and success measures Run structured intake and triage for stakeholder requests and convert them into a clear, ranked backlog Lead cross-functional reviews to resolve delivery blockers, unclear ownership,
and handoff gaps Develop metrics that show whether new capabilities are improving response speed, alert quality, coverage, and analyst efficiency Document requirements, business value, user workflows, acceptance criteria, and rollout plans Represent operational needs in platform discussions and represent engineering realities in operational planning Drive continuous improvement based on analyst feedback, incident learnings, and evolving threat priorities Experience prioritizing roadmaps and backlogs across multiple stakeholder groups with competing demands Strong written and verbal communication skills, including the ability to work effectively with engineers, analysts, managers, and executives Ability to translate technical platform work into clear user value, measurable outcomes, and release criteria Strong understanding of Security Operations concepts, including SIEM, detection engineering, incident response, case management, and security automation Experience as a Product Manager owning cross-functional delivery in a complex technical setting Comfort working with ambiguity and turning loosely defined needs into clear plans and decisions Experience building processes, KPIs, and operating cadences in environments where teams depend on one another for outcomes Experience supporting or partnering closely with Security Operations Center, incident response, or threat detection teams Familiarity with security telemetry pipelines, data normalization, and log onboarding workflows Experience with SIEM and SOAR platforms such as Google SecOps, Chronicle, Splunk, Microsoft Sentinel, Palo Alto XSIAM, or similar technologies Exposure to detection engineering practices such as rule testing, content lifecycle management, and detection-as-code Understanding of response automation design, control frameworks, and approval models for high-impact actions Experience using data to evaluate false positives, alert quality, operational throughput, and workflow adoption Knowledge of common security frameworks and operating models such as NIST incident response guidance #J-18808-Ljbffr
📌 Senior Product Manager (Security Operations, Secops) (Toronto)
🏢 Equinix
📍 Toronto