High Level Role OverviewBenevity is looking for a Principal Information Security Analyst to join our Security Operations team. In this senior‑level role, you will provide technical leadership and operational oversight across a team of analysts responsible for threat detection, alert triage, incident response, and vulnerability management.This role is ideal for someone with deep hands‑on experience in security operations who is also energized by the opportunity to work alongside AI. We are actively integrating AI tools into our SecOps practice to accelerate triage, investigation, detection engineering, and analyst productivity, and this role will play a meaningful part in shaping how we do that. You should be comfortable navigating AI tools, building your own skills with them, identifying practical use cases, and partnering with the team to put them into production. You will serve as both a senior escalation point and a coach, helping elevate the team's ability to respond to threats in a cloud‑native environment while modernizing how the work gets done.What You'll DoLead daily Security Operations workflows, including triage, escalation, and resolution of alerts from core security tooling such as EDR, WAF, CSPM, SIEM, and cloud‑native platformsLead and coordinate security incident response across the full lifecycle, from detection and containment through eradication, recovery, and lessons learned, serving as incident commander for significant eventsDrive and oversee the triage, investigation, and resolution of alerts generated across all security tooling, not just those escalated by the MDR providerAct as the technical lead and escalation point for Managed Detection and Response (MDR) activities, ensuring timely review and validation of escalated alertsIdentify, evaluate, and operationalize AI‑assisted approaches to SecOps work, including AI‑augmented triage, investigation, summarization, detection engineering, and reportingBuild your own fluency with AI tooling and help the broader team develop the same skills,
sharing patterns that work and being honest about ones that don’tApply a healthy degree of skepticism to AI outputs, validating findings and helping the team understand where AI assists the work and where human judgment still owns the decisionDevelop and continuously refine incident response processes, detection logic, and triage playbooks to improve clarity and effectivenessOversee the vulnerability management lifecycle, ensuring timely identification, prioritization, remediation tracking, and stakeholder coordinationCollaborate with GRC, Product Security, DevOps, and Infrastructure teams to improve detection coverage, alert fidelity, and log qualityPartner with our Senior Fraud Analyst on cross‑functional investigations where fraud and cyber threats intersect, contributing SecOps expertise without owning the fraud function day‑to‑dayServe as a subject matter expert in cloud‑native security operations with strong understanding of containerized and API‑driven environmentsSupport the development, tracking, and reporting of KPIs and metrics to measure and improve team performanceConduct post‑incident reviews and root‑cause analysis, driving preventive control enhancementsMentor junior and mid‑level analysts, providing feedback, coaching, and opportunities for growthWhat You'll Bring7+ years of experience in information security or security operations, with at least 2 years in a team lead or senior analyst capacityProven experience triaging and responding to alerts across a broad suite of tools including CSPM, WAF, EDR, SIEM,
and cloud‑native logging platformsFamiliarity with MDR service models and hands‑on experience validating escalated alertsHands‑on experience leading security incident response, including acting as incident commander, coordinating cross‑functional responders, managing communications, and producing post‑incident artifactsPractical experience using AI tools in a security or technical context, with a clear point of view on where they add value, where they fall short, and how to get them production‑readyCuriosity and willingness to keep building AI skills as the tooling evolves, and an interest in helping teammates do the sameAwareness of the security considerations that come with using AI tools in a SecOps environment (data handling, prompt hygiene, output validation)Demonstrated ability to work independently, while recognizing when to seek input or elevate appropriatelyStrong critical thinking and communication skills with the ability to analyze complex data, challenge assumptions, and drive resolutionExperience developing or refining operational playbooks, triage guides, and incident workflowsDeep understanding of cloud security best practices, threat detection, and modern attacker tactics, techniques, and proceduresFamiliarity with common security frameworks such as NIST CSF, CIS Controls, and ISO 27001A robust sense of ownership and accountability, with the ability to act as a self‑starter who can lead initiatives from concept to completionDemonstrated ability to collaborate across technical and non‑technical teams to drive effective outcomesExperience fostering a positive and inclusive team environment, with a focus on team building, talent development, and shared successA passion for teaching and mentoring others, helping team members grow their skills and confidencePreferred certifications include GCIH, GCFA, OSCP, or CISSPSalary range - Ontario$125,000—$165,000 CADCandidates with disabilities who may require accommodations throughout the hiring or assessment process are encouraged to reach out to
[email protected].#J-18808-Ljbffr
📌 Principal Information Security Analyst - C$125,000 - C$165,000 A Year (Winnipeg)
🏢 Benevity
📍 Winnipeg