Director, Security Engineering & Operations (Ottawa)

Director, Security Engineering & Operations (Ottawa)

17 Aug
|
Payscale
|
Ottawa

17 Aug

Payscale

Ottawa

About PayscalePayscale is the pioneer of compensation intelligence, helping organizations make smarter pay decisions that drive business performance. For more than 20 years, Payscale has combined trusted market data with AI-powered technology to deliver actionable insights that turn pay from a cost into a catalyst for growth. The Payscale Intelligence Cloud portfolio of solutions — Ascent, JobNav, and Paycycle — empower top companies and businesses like Cintas, Leidos, Chipotle, Ohio State University, and TJX Companies.Create confidence in your compensation. Payscale.To learn more, visit www.Payscale.Com.Job SummaryThe Director, Security Engineering & Operations directs, manages, and leads Payscale'sSecurity Engineering and Eecurity Operations functions. This is a hands-on leadership role:the Director sets strategy and manages the team while remaining directly engaged inarchitecture, tooling, automation, and incident command. Responsibilities span the designand hardening of security controls, threat detection and incident response, vulnerabilityand exposure management, endpoint and identity protection, and security automationacross Payscale's corporate, cloud, and hosting environments. The Director ownsPayscale's MDR relationship and is accountable for the maturity, performance, androadmap of both functions.This role reports to the CISO, VP - Cybersecurity & Enterprise Technology.What You'll DoLeadership & People ManagementDirect, manage, and lead the security engineering and security operations teammembers; own hiring, onboarding,performance reviews, and career developmentplans aligned to Payscale's Information Security Career LadderSet strategy and quarterly/annual objectives for both functions and translate theminto a prioritized, measurable roadmap; hold regular 1:1s and team connects tomaintain a high-performance, feedback-rich cultureMentor engineers and analysts at all career levels, providing task-based directives,technical coaching, and growth-oriented feedbackOwn the on-call rotation and after-hours escalation path across both functions,ensuring coverage for time-sensitive detection and responseServe as a working leader — remaining hands-on in engineering, architecture, andincident response rather than leading solely through delegationSecurity EngineeringOwn the design, implementation, and continuous hardening of security controlsacross corporate, cloud, and hosting environmentsBuild and maintain security automation and integrations — SOAR, detection-as-code, and infrastructure-as-code guardrails — to scale coverage without addingheadcountEngineer and operate the security tooling stack (EDR/XDR, SIEM, identityprotection, DLP/CASB, vulnerability scanning), ensuring platforms are well-integrated and meet architectural standardsPartner with Engineering and Infrastructure to embed "secure by design" intoCI/CD, cloud architecture, and product developmentDrive adoption of a zero-trust methodology across identity, endpoint, network, andapplication layersLead security engineering for enterprise AI and agentic tooling adoption, buildingcontrols and guardrails for safe internal useSecurity Operations & Incident ResponseDrive the threat detection and incident response capability: detection engineering,playbook development, tabletop exercises, and continuous improvement ofMTTA/MTTR metricsLead or oversee incident response events as the designated incident manager forsignificant or multi-team incidents, running incident command end-to-endOwn the MDR relationship, holding the provider accountable to SLAs, coverage,and response outcomesExtend detection and response to secure enterprise AI and agentic toolingadoptionVulnerability & Exposure ManagementOwn the vulnerability and exposure management function across all corporate andhosting environments, coordinating cross-functionally on mitigation andremediation with clear SLAsExpand security monitoring, visibility, and coverage using existing platforms andopen-source toolingProgram,



Metrics & Stakeholder EngagementOwn the security engineering and operations portion of the Information Securityprogram roadmap, delivering operational metrics, risk-posture data, and capacityanalysisEstablish and report security KPIs to technology and executive leadership on aregular cadenceCollaborate with the GRC team on ISO 27001 and SOC 2 evidence, controleffectiveness, and audit readiness as it relates to security engineering andoperationsLead technical evaluations of emerging security vendors and technologies; providebuy/build/partner recommendations to technology managementRepresent security engineering and operations in cross-functional product,engineering, and infrastructure initiatives, ensuring security requirements areincorporated by designWhat We're Looking For10+ years in information security, including 4+ years in a lead or management roleacross security engineering and/or security operations functionsProven people-management track record: direct reports, performance cycles, andteam development in a security contextExpert, hands-on knowledge of both security engineering (controls design,automation, tooling integration) and security operations (detection, incidentresponse) — capable of acting as architect, engineer, incident handler, lead, andmanagerExperience with the CrowdStrike Falcon platform (EDR, Identity Protection, DataProtection, AIDR, ZTA, Exposure Management) and SIEM/SOAR orchestrationDemonstrated experience owning or managing an MDR or MSSP vendorrelationshipStrong foundation in cloud security (AWS preferred), endpoint security, identity andaccess management, and zero-trust architectureStrong experience in vulnerability and exposure management andmitigation/remediation strategiesScripting and automation ability in PowerShell, Python, or Bash; comfortable withdetection-as-code and infrastructure-as-code approachesExperience with the MITRE ATT&CK framework and the ability to map operationaldata to TTPs for structured threat analysisExperience building operational, engineering, and vulnerability metrics andmanagement reporting, and driving improvement through a regular reportingcadenceExperience with zero-trust networks and platforms such as Cloudflare, Zscaler, orAppGateExperience with Data Loss Prevention and CASB architectures and tooling such asForcepoint, Netskope, or ZscalerFamiliarity with SOAR and automation platforms such as Tines, n8n, or AnsibleNice to HaveCertifications such as CISSP or CISMExperience in a remote-first SaaS and/or PE-backed environmentLocationPayscale has an employee centric remote-first model that provides you the flexibility to do your best work in a space that supports you, while also finding time to collaborate in person for the moments that matter. In our remote-first model, employees can work from the location that works best for them. We do not have centralized corporate offices. Employees can choose to work from home, in company-paid co-working spaces, or any combination of the two that best suits their unique needs.If you work from home, we recommend ensuring that you can meet the following technology, equipment and workspace requirements:High-Speed Internet - A stable broadband or fiber connection (satellite is highly discouraged) with a minimum speed of 100 Mbps in a dedicated workspace that has a reliable Wi-Fi signal.Device for Multifactor Authentication (MFA/2FA) - smartphone, tablet, etc.When it matters (usually no more than a few times a year) we take the time to gather for in-person events.Payscale has employees across the US, Canada, UK,



The Philippines and Romania however we are currently unable to hire in the Quebec Province, Northern Ireland, and Hawaii.Benefits and PerksAll around awesome culture where together we strive to live our 5 values:Data informed decision making.Customer first. Always.Succeed together.Relentless about results. Obsessed with excellence.Lead the change. Shape the standard.An open and inclusive environment where you'll learn and grow through programs and resources like:Monthly company All Hands meetingsRegular opportunities for executive leadership exposure through things like AMAsAccess to continued learning & development opportunitiesOur commitment to a continuous feedback culture which allows us to drive performance and career growthA growing network of Employee Resource GroupsCompany sponsored volunteer hoursAnd more!Our more standard benefits(US)Flexible paid time off, giving you the opportunity to rest, relax and recharge away from work14 Paid Company Holidays, includes 2 floating holidays (you choose!)A comprehensive benefits plan including medical, dental, life, vision, disability, and life insurance covered up to 100% by PayscaleUnlimited infertility coverage benefits through our medical plansAdditional supplemental health benefits offered to you and your family401(k) retirement program with a fully vested immediate company match16 weeks of paid parental leave for birthing and non-birthing parentsHealth Savings Account (HSA) options and company contributions each pay periodFlexible Spending Account (FSA) options for pre-tax employee allocationsAnnual remote work stipend to be used on wellness or home office equipmentOur more standard advantages (Canada)Holiday – Annual accrual for full time and part time employeesSick Pay – Annual paid time off availableCompany Paid and Statutory Holidays – Generous time off provided16 weeks of paid parental leave (top off) for birthing and non-birthing parentsLife Insurance - Basic life and AD&D benefitLong term disability & Critical Illness – Coverage for certain types of illnesses and surgeriesMedical/Rx, Dental, Telehealth – Coverage for prescription, paramedical, medical supplies, emergency, basic and accidental dental, and virtual health care servicesHealth/Wellness Spending Account – Annual amount provided to you and your family for approved expensesRRSP offered to employees with a 1:1 match up to 4%BenefitHub – Discount marketplace, full access to all your benefits and provider portalsAnnual remote work stipend to be used on wellness or home office equipmentEqual Opportunity Employer:We embrace equal employment opportunity. Payscale is committed to a policy of equal employment opportunity for all applicants and employees. It is our policy that employees will not be subjected to unlawful discrimination on the basis of race, color, religion, sex, age, national origin, or ancestry, physical or mental disability, veteran or military status, marital status, sexual orientation, political ideology, and any other basis protected by federal, state, or local laws. This policy applies to all terms and conditions of employment, including but not limited to: recruitment, hiring, transfers, promotions, training, discipline, termination, compensation and benefits, performance appraisals, education, and social and recreational programs.We know the confidence gap and imposter syndrome can get in the way of meeting spectacular candidates, so please don't hesitate to apply — we'd love to hear from you.If you have a disability or impairment and need assistance with the application process, please email [email protected] for support.Fraud Alert:Payscale values security and privacy. During your job application and interview process, we will never ask for your personal banking or financial information, social security number, or other sensitive information, if you are unsure if a message is from Payscale, please email [email protected] #J-18808-Ljbffr

📌 Director, Security Engineering & Operations (Ottawa)
🏢 Payscale
📍 Ottawa

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: director, security engineering & operations (ottawa) / ottawa

Subscribe to this job alert:

Get the latest job offers by email for: director, security engineering & operations (ottawa) / ottawa