Manager, IT Risk & Security Operations (Ottawa)

Manager, IT Risk & Security Operations (Ottawa)

15 Sep
|
The Canadian Real Estate Association
|
Ottawa

15 Sep

The Canadian Real Estate Association

Ottawa

Reports To: Director, IT

Role Type: Full-time

Location: Ottawa, ON

Workplace Type: Hybrid or Remote

Effective: ASAP

About Us

REALTOR.ca is a cornerstone of Canada’s real estate market, dedicated to helping millions of Canadians find attainable housing across the country. As the leading real estate platform in Canada, we offer the most comprehensive listings and resources to assist consumers in finding their dream homes.

At REALTOR.ca, we are committed to supporting REALTOR® members’ businesses and fostering consumer trust and loyalty. Our dedication to delivering value and continuously adapting to market demands ensures that REALTOR.ca is more than just a listing service- it is the heart of the Canadian real estate experience.

Join us and be a part of a team that is at the forefront of the real estate industry, making a significant impact on the lives of Canadians every day.

Position Overview The Manager, IT Risk & Security Operations leads REALTOR.ca Canada Inc.'s enterprise cybersecurity operations, including security operations, infrastructure and network security, cloud and identity security, application security, vulnerability management, cyber resilience, governance, risk management, third-party risk, and compliance.

The role translates cybersecurity strategy and policy into operational practice, leads the security operations function and incident response, and drives day-to-day risk reduction across the organization's technology environment. The Manager leads and develops the security team and serves as the operational escalation point for cybersecurity incidents and risks.

Core Competencies

- Team Leadership & Coaching

- Security Operations Execution

- Incident Response & Triage

- Technical Proficiency Across Security Tooling

- Prioritization & Operational Judgment

- Communication & Cross-Team Coordination

- Process Improvement & Documentation

Function

Working closely with Infrastructure, Service Desk, Software Engineering, and Product teams, the Manager, IT Risk & Security Operations ensures security requirements and controls are effectively implemented throughout the technology lifecycle and supports the secure delivery and operation of enterprise platforms, digital services, and applications.

Key Responsibilities

Team Leadership & Operations Management

- Directly manage, coach, and develop the security team, including goal-setting, performance reviews, skills development, and a culture of accountability, collaboration, and continuous improvement.

- Own day-to-day scheduling, workload balancing, coverage, and priorities for the security operations function, translating broader security strategy into actionable team objectives.

- Provide regular reporting on team performance, operational metrics, emerging risks, and areas requiring leadership attention.

- Partner with Software Engineering, Product, Infrastructure, and Service Desk leadership to embed security requirements, secure design principles, risk-based decision-making, and governance throughout the technology lifecycle.

Security Operations & Incident Response

- Lead daily security monitoring, alert triage, threat detection, and investigation across SIEM, SOAR, EDR/XDR, email security, and related platforms.

- Act as the primary operational escalation point for security incidents and coordinate containment, recovery, communications, and post-incident follow-up.

- Maintain and continuously improve incident response playbooks, runbooks, standard operating procedures, and escalation processes.

- Coordinate tabletop exercises and support disaster recovery and ransomware-preparedness testing.

- Drive detection engineering and SOC automation to improve coverage, consistency, and response efficiency.

Security Technology & Automation

- Lead the evaluation, implementation, lifecycle management, renewals, upgrades,



and day-to-day vendor relationships for security operations technologies, including SIEM, SOAR, EDR/XDR, vulnerability management, and email/endpoint security platforms.

- Drive adoption of security automation to reduce manual effort in monitoring, triage, investigation, and remediation workflows.

- Support larger strategic security initiatives and technology decisions requiring enterprise budget or executive approval.

Vulnerability Management & Security Testing

- Run the day-to-day vulnerability management program, including scanning cadence, triage, risk-based prioritization, remediation tracking, dashboards, and reporting across infrastructure, endpoints, cloud, applications, and network devices.

- Coordinate remediation timelines and priorities with Infrastructure, Software Engineering, Service Desk, and other stakeholders.

- Coordinate internal and third-party penetration testing and security assessments across applications, infrastructure, networks, and cloud environments, and track findings through remediation and validation.

Infrastructure, Network, Cloud & Identity Security

- Implement and maintain security standards and configuration baselines across on-premises infrastructure, endpoints, networks, cloud platforms, and Microsoft 365.

- Oversee the operational security of IAM, PAM, MFA, Microsoft Entra ID, Active Directory, and other identity security controls.

- Monitor and maintain security controls covering firewalls, network segmentation, secure remote access, endpoint protection, network detection, and cloud security posture.

- Coordinate vulnerability remediation, security hardening, patching priorities, and control improvements with Infrastructure and Service Desk teams.

- Partner with Infrastructure and Cloud teams to embed security requirements into technology changes, deployments, and day-to-day operations.

Risk, Governance & Compliance

- Maintain the operational cyber risk register, support risk assessments, and escalate significant risk to leadership.

- Support internal and external audits and compliance assessments by coordinating evidence, stakeholders, and remediation actions.

- Coordinate third-party security assessment intake, tracking, and follow-up.

- Help maintain adherence to security policies and standards aligned with NIST CSF, ISO 27001, CIS Controls, and OWASP.

Application Security

- Serve as the operational liaison between IT Security and Software Engineering on application risk, translating material application risks into the enterprise risk process.

- Coordinate application penetration testing and security audits, including scoping input, scheduling, evidence gathering, and tracking findings and recommendations through closure.

- Review SAST, DAST, and SCA results from Software Engineering processes, help prioritize remediation from a risk perspective, and escalate material control gaps to IT and Software Engineering leadership.

- Work with Product and Software Engineering teams to implement security requirements identified through architecture, design, project, and change-management reviews.

Security Awareness

- Support security awareness, phishing simulation, and employee education initiatives, working with relevant teams to reinforce secure practices and address recurring risk themes.

Skills & Qualifications

- Degree or diploma in Information Technology, Cybersecurity, Computer Science, or a related discipline, or an equivalent combination of education and experience.





- Minimum 8 years of progressive experience in cybersecurity, security operations, or a related technical security discipline.

- Minimum 3 years of experience managing or supervising a cybersecurity or technical team, including coaching, performance management, and employee development.

- Hands-on experience with security monitoring, incident response, vulnerability management, and security operations technologies such as SIEM, SOAR, EDR/XDR, IAM/PAM, firewalls, and cloud security tools.

- Experience evaluating, implementing, and managing security technologies throughout their lifecycle and using automation to improve security operations.

- Experience partnering with security technologies and platforms such as Microsoft Sentinel, Microsoft Defender, Microsoft Entra ID, Azure, and AWS is an asset.

- Experience partnering with Software Engineering, Infrastructure, Cloud, and Service Desk teams to implement and operationalize security controls.

- Working knowledge of application security concepts, including SAST, DAST, SCA, and secure software development lifecycle principles, with the ability to assess risk and coordinate effectively with Software Engineering teams.

- Familiarity with security frameworks and practices, including CIS Controls, NIST CSF, ISO 27001, and OWASP.

- Strong communication, leadership, and operational judgment, with the ability to coach team members, work across technical and business teams, and escalate material risks appropriately.

- A relevant security certification, such as Security , CySA , GIAC, CISSP, CISM, or CCSP, is a strong asset.

What Success Looks Like

- A well-coached, high-performing security team with clear priorities, accountability, and growth paths.

- Fast, effective detection, triage, response, and recovery from security incidents.

- A vulnerability management and security testing program with clear SLAs, consistent remediation tracking, and reliable reporting.

- Security controls across infrastructure, networks, cloud, identity, and applications that are consistently maintained and monitored.

- Risk, audit, third-party assessments, and penetration-testing findings that are clearly tracked and closed in a timely manner.

- Strong day-to-day partnerships with Infrastructure, Service Desk, Software Engineering, and Product teams.

- Continuous improvement of security processes, documentation, tooling, and automation, supported by reliable operational reporting.

About the Team

We are a diverse and talented group of professionals passionate about technology and innovation. We value collaboration, creativity, and continuous learning. As a part of the development team, you will join a supportive team that encourages knowledge sharing and professional growth. We foster a positive and inclusive work environment where all team member’s contributions are valued.

Company Culture

At REALTOR.ca, we pride ourselves on our dynamic and inclusive company culture. We believe that a great workplace is built on mutual respect, open communication, and a shared commitment to excellence. Our team enjoys a flexible work environment that promotes work-life balance, with options for remote work and flexible hours. We also offer opportunities for professional development and career advancement, ensuring that our employees can grow alongside the company.

We thank all applicants for their interest; however, only those under consideration for the role will be contacted.

At REALTOR.ca, we are committed to fostering an inclusive, barrier-free and accessible setting. Part of this commitment includes arranging accommodations to ensure an equitable opportunity to participate in the recruitment and selection process. If you require an accommodation, we will work with you to meet your needs. As an equal opportunity employer, we value the unique perspectives and experiences that each team member brings.

📌 Manager, IT Risk & Security Operations (Ottawa)
🏢 The Canadian Real Estate Association
📍 Ottawa

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: manager, it risk & security operations (ottawa) / ottawa

Subscribe to this job alert:

Get the latest job offers by email for: manager, it risk & security operations (ottawa) / ottawa