About The RoleConstellation Software’s rapidly expanding Perseus Operating Group (CSI) is seeking an experienced Information Security Lead to drive the design, development, and secure deployment of complex information systems. This role requires translating security frameworks into practical, scalable governance across a diverse portfolio of global businesses, operating environments, and cultures.CIT Information Security LeadAbout The RoleConstellation Software’s rapidly expanding Perseus Operating Group (CSI) is seeking an experienced Information Security Lead to drive the design, development, and secure deployment of complex information systems. This role requires translating security frameworks into practical, scalable governance across a diverse portfolio of global businesses, operating environments, and cultures.The ideal candidate brings a strong foundation in risk management, with the ability to assess and balance threats, vulnerabilities, and information value to enable informed security decisions. This role also demands proven leadership in designing, evaluating, and continuously improving security processes, while guiding cross-functional teams in strengthening organizational security posture and operational maturity.Key ResponsibilitiesSecurity Operations & Incident ResponseMonitor and investigate security alerts across endpoint, identity, email, and data protection platformsRespond to escalations and coordinate incident containment and remediationPerform root cause analysis and document findingsTrack incidents through full lifecycle (detection, response, closure)Coordinate cross-team response efforts during active incidentsProvide mentorship and technical leadership to SOC analysts, driving skill development and process consistency.Security Tooling & Platform OperationsSupport operations of enterprise tools including EDR/XDR, DLP, email security, and identity monitoringLead escalation handling for endpoint protection platforms (e.G., CrowdStrike-like tools)Coordinate sensor/agent deployments, upgrades, and onboarding during acquisitionsMaintain operational dashboards and reporting visibilityEnsure consistent alert handling and response workflows across platformsSupport dashboard displays and reporting visibility (e.G., office display dashboards)Monitoring & InvestigationsInvestigate endpoint detections and behavioral alertsMonitor identity risks including risky users and insider risk signalsPerform DLP monitoring, reporting, and coordination activitiesConduct email investigations including trace analysis and troubleshootingManage and resolve security-related tickets (e.G.,
email protection platforms utilizing Proofpoint-like tools)Security Awareness & PhishingConduct phishing investigations and response coordinationSupport phishing simulation campaigns and reportingManage user synchronization and participation in awareness platformsIdentify trends from phishing results and recommend improvementsGovernance, Risk & ComplianceImplement and maintain security policies aligned with industry frameworks (NIST, ISO, PCI, SOC)Conduct risk assessments and document findingsTrack remediation activities and risk mitigation progressSupport audits and compliance reportingAssist with control validation and evidence collectionCollaboration & SupportWork with IT, Infrastructure, and business teams on security initiativesProvide guidance on security incidents, tools, and processesDocument procedures, runbooks, and operational standardsIdentify and drive process improvements and automation opportunitiesRequired Qualifications3-5 years of experience in information security (operations, governance, or risk)Experience operating in or supporting a Security Operations Center (SOC), including end-to-end incident lifecycle management (detection, investigation, response, and remediation)Strong hands-on experience with endpoint detection, monitoring, and alerting tools, including tuning detections and improving signal qualityProven experience with core Microsoft security technologies, including:Microsoft Defender (Endpoint, M365, Identity) for threat detection and responseData Loss Prevention (DLP) across M365 workloadsWorking knowledge of compliance frameworks (e.G., NIST, ISO 27001, PCI-DSS, GDPR) and their application in enterprise environmentsStrong analytical and communication skills, with the ability to translate technical findings into clear business risk and actionable outcomesAbility to operate effectively in a global, distributed environment, including prioritizing work, adapting to changing business needs, and supporting occasional after-hours operationsAbility to communicate ideas in both technical and user-friendly languageAbility to investigate, troubleshoot and resolve complicated technical issuesAbility to effectively prioritize and execute tasks in a high-pressure environmentHighly self-motivated and directed,
with keen attention to detailProven analytical and creative problem-solving abilitiesAvailable for infrequent business travelAbility to work within a diverse geographically distributed teamWilling to adjust work schedule to accommodate business needsExceptional documentation and customer service skills with written, oral, and interpersonal communication skillsAbility to adapt to different cultures with varying degrees of physical living standards, accommodations, and environmentsAble to sit at a computer workstation for extended time periods and fully utilize the PC monitor, keyboard, mouse, and required programsPreferred QualificationsAdvanced experience across the Microsoft Security ecosystem, including:KQL query development, analytics rule creation, and incident correlationMicrosoft Purview (data governance, Insider Risk Management, eDiscovery, compliance solutions)Microsoft Defender for Cloud Apps and cloud security posture managementExperience designing or integrating Microsoft security tools into an enterprise XDR or centralized security architectureExperience driving SOC maturity, including playbook development, automation, and continuous process improvementExperience operating in hybrid or multi-cloud environments with centralized security toolingDemonstrated experience leading security process improvements or contributing to security program maturity across distributed organizationsRelevant certifications (e.G., CISSP, GIAC, Microsoft Security certifications)CompensationCSI offers a competitive base salary, bonus potential, a full benefits package, and a great environment.Salary Range (Ontario & BC Only):The estimated base salary range for this role is CAD$103,500.00 - CAD$126,500.00 per year. We include salary ranges in job postings only where required by applicable pay transparency laws, based on the jurisdictions in which the role may be performed. The posted range is a positive faith estimate and reflects factors that are subject to change. Final offer amounts may vary based on job-related factors, including work location, candidate experience and expertise, and other relevant considerations.We recognize the value and importance of diversity and inclusion in our communities and in the workplace. We celebrate diversity and one of our goals as an employer is to create an inclusive work environment for all employees. We are an equal opportunity employer and do not discriminate against any employee or applicant because of race, religion, sex, sexual orientation including gender identity or expression, pregnancy, national origin, age, marital status, veteran status, disability status, or any other category or characteristic protected by law.Applicants with disabilities who would like to require a reasonable accommodation related to any part of the application process may contact us at
[email protected].#Perseus HO#J-18808-Ljbffr
📌 Cit Information Security & Grc, Lead - C$103,500 - C$126,500 A Year (Winnipeg)
🏢 Constellation Software
📍 Winnipeg