06 Sep
|
Socket.dev
|
Montreal
06 Sep
Socket.dev
Montreal
At SITA, we keep airports moving, airlines flying smoothly, and borders open. Our technology and communication innovations power the success of the global air travel industry. You’ll find us in 95% of international airports, working closely with over 2,500 transportation and government clients.
Each partnership brings unique challenges, and we thrive on delivering fresh solutions and cutting‑edge tech to keep operations running like clockwork. Here, we feel empowered, supported, and inspired to grow. The internal title for this role will be Senior Lead Security Architect The Senior Security Incident Response Team Manager (SIRT Manager) is responsible for leading the organization’s 24x7x365 Security Operations Center (SOC), overseeing security monitoring, threat detection, incident response, cyber investigations, and threat hunting activities across a global environment.
Reporting directly to the Chief Information Security Officer (CISO), this role provides strategic and operational leadership for geographically dispersed cybersecurity teams while ensuring the protection of critical enterprise, transportation, aviation, and government‑facing systems. The Senior SIRT Manager serves as the primary escalation point for major cybersecurity incidents, drives continuous improvement of SOC capabilities, and collaborates closely with Security, IT, Legal, Privacy, Risk, Compliance, and business stakeholders to strengthen the organization’s cybersecurity posture. SOC Leadership & Operations - Lead and oversee all Security Operations Center activities, ensuring effective delivery of 24/7/365 monitoring, threat detection, incident response, and security operations services.
Incident
Management & Escalation - Serve as the primary point of contact and escalation authority for critical security incidents, cyber threats, and crisis events.
Global Team
Management - Manage and develop geographically distributed SOC teams across North America and APAC regions, ensuring operational readiness and business continuity.
Threat
Detection & Hunting - Direct threat hunting, threat intelligence, threat analysis, and proactive detection activities to identify and mitigate emerging cyber risks.
Incident Response
Leadership - Coordinate enterprise‑wide incident response efforts, including containment, eradication, recovery, root cause analysis, and post‑incident reviews.
SOC Performance & Metrics - Develop, monitor, and report on SOC KPIs, SLAs, operational metrics, trends, and executive dashboards for cybersecurity leadership and the CISO. Stakeholder & Executive Communication - Provide regular reporting to the CISO and senior leadership regarding threats, risks, incidents, remediation efforts, and security program improvements.
Process
Improvement &
• Automation - Identify opportunities to improve SOC efficiency through enhanced alerting, detection engineering, automation, workflow optimization, and tool integration. Governance &
• Compliance Support - Ensure SOC operations align with applicable regulatory, contractual, and security framework requirements, including audit and compliance obligations. Third‑Party &
• MSSP Management - Manage relationships with managed security service providers (MSSPs), vendors, and external partners, ensuring service quality and contractual performance. Training &
• Capability Development - Mentor, coach, and develop SOC analysts and responders while promoting continuous learning, certification achievement, and operational excellence.
Security
Readiness & Resilience - Lead tabletop exercises, cyber simulations, SOP development, knowledge management, and continuous improvement initiatives to strengthen organizational resilience.
Education - Bachelor's degree in Computer Science, Information Security, Information Systems, Cybersecurity, or a related technical discipline.
Cybersecurity Leadership
Experience - 10+ years of experience in information technology and cybersecurity, including at least 5 years in information security leadership roles. SOC Management Expertise - Minimum 5 years managing a large‑scale 24x7 Security Operations Center with responsibility for multi‑location teams and operational delivery.
Incident
Response & Threat Management - Deep experience leading cyber incident response, threat detection, threat hunting, cyber investigations,
and forensic analysis activities.
Security
Technologies - Solid knowledge of SIEM, SOAR, EDR/XDR, malware analysis platforms, threat intelligence solutions, cloud security technologies, and monitoring tools. Regulatory & Security Framework Knowledge - Working knowledge of NIST, ISO 27001, PCI DSS, HIPAA, SOC 2, and other relevant cybersecurity and compliance frameworks.
Executive
Communication & Stakeholder Management - Exceptional written, verbal, presentation, and executive communication skills with the ability to translate technical risks into business impacts. Operational & Strategic Leadership - Proven ability to manage multiple priorities, balance operational demands, drive process improvements, and lead teams during high‑pressure situations. Analytical & Problem‑Solving Skills - Strong investigative mindset with expertise in risk assessment, root cause analysis, data‑driven decision making, and continuous improvement methodologies.
We’re all about diversity. We operate in 200 countries and speak 60 different languages and cultures.
Flex Week: Work from home up to 2 days/week (depending on your team’s needs) Flex Day: Make your workday suit your life and plans.
Employee Wellbeing: We’ve got you covered with our Employee Assistance Program (EAP), for you and your dependents 24/7, 365 days/year. We also offer Champion Health – a personalized platform that supports a range of wellbeing needs. Our learning ecosystem offers access to world‑class platforms and programs designed to help you thrive.
From LinkedIn Learning, Microsoft’s Enterprise Skills Initiative, and Airport Council International - available to all employees-to specialized solutions like Pluralsight for technology upskilling, Harvard Business Publishing for people leadership, Stanford for strategic development and many others, we align learning opportunities with your Development Plan and our business priorities. Your development journey is supported every step of the way.
Competitive Benefits: Competitive benefits that make sense with both your local market and employment status. In support of our Employment Equity Program, women, aboriginal people, members of visible minorities, and/or persons with disabilities are encouraged to apply and self‑identify in the application process.
📌 Responsable principal de l'équipe d'intervention en cas d'incident de sécurité /Senior Security Incident Response Team Manager (SIRT) (Montreal)
🏢 Socket.dev
📍 Montreal