Security Operations Team Lead
RemoteBritish ColumbiaCAD 126k–137kleadFullTime
- Posted
- today
- Source
- safe (ashby)
- Field
- Operations, Security
Skills
CommunicationCybersecurityOnboardingLeadershipSecurityRoadmappingPythonNext.jsAWSAI
Description
Safe Software is looking for a Security Operations Team Lead to build and lead our security operations function. This is a new role, and the person in it will own the programs, processes, and people that make security operations work at Safe. We have an immediate opening and are excited to find the right candidate to join our team.
Reporting to the Director of Information Security, you'll take ownership of the programs on our roadmap — incident response, vulnerability and patch management, system hardening and configuration management, device trust and conditional access, and resiliency planning — and turn them from initiatives into durable, measurable practices. This is also a people-leadership role: you'll manage the Security Operations Engineers who deliver that work, starting with a small team and growing it as the function matures.
It's a leadership role, and a hands-on one. You'll stay close enough to the work to make good technical calls, carry a share of the on-call rotation, and be credible with the engineers you lead. We're looking for someone with a first stretch of leadership behind them who wants substantially more ownership than they've had so far, and the support to grow into it.
You'll also set the tone for how security shows up at Safe. Security only works when it feels like a partnership rather than an obstacle, and the best security operations leaders we've worked with treat other teams as partners with their own pressures and deadlines. That's the disposition we're hiring for.
ABOUT THE TEAM
Information Security at Safe protects the data, systems, and people behind FME and the 25,000+ enterprise customers who rely on it. We're a growing, high-trust team that partners closely with teams across Safe rather than operating as a separate gate.
We're at a genuinely interesting period of growth and opportunity: we're building programs, not just maintaining them. Incident response, resiliency planning, configuration management, and vulnerability management are all being stood up or significantly matured right now, and this role drives much of that work. This means real latitude to decide how security operations should work at Safe.
We also lean on AI and automation to cut toil, sharpen investigations, and move faster. Part of this role is setting both the expectation and the guardrails for how the team experiments with them.
WHAT YOU'LL BE DOING
As the Security Operations Team Lead, you will:
- Build and lead the security operations team, including hiring, onboarding, coaching, performance, and career development. You'll set the bar for how the team works, then grow the team as the function scales.
- Own the incident response program end to end — the process, the runbooks, the on-call rotation, the tabletop exercises, and the post-incident reviews. You'll act as incident commander for significant events, carry a share of the on-call rotation, and make sure every incident makes the next one easier.
- Own the security operations roadmap and its delivery, translating strategy into prioritized, resourced work with clear outcomes, and reporting on progress, risk, and where you need help.
- Drive programs and processes to maturity — automated patch management, CIS benchmark adoption for system hardening and configuration management, device trust and conditional access, vulnerability management with meaningful SLAs, and resiliency planning.
- Set the technical direction for our security tooling, ensuring Rapid7 InsightVM (vulnerability management) and InsightIDR (SIEM), Cisco Secure Endpoint (EDR), Cisco Umbrella, Active Directory, JumpCloud, Google Workspace, and AWS security controls are configured, tuned, and delivering real detection value rather than noise.
- Define and track the metrics that matter — detection and response times, remediation SLAs, hardening and patch coverage, alert quality — and make sure they drive decisions instead of decorating a dashboard.
- Champion AI and automation across the team's workflows, piloting and standardizing tools that reduce toil and sharpen investigations, and establishing sensible guardrails for how AI is used in security work.
- Own Security Operations' contribution to compliance, operating and evidencing controls for ISO 27001, SOC 2, and future frameworks, and building processes where audit evidence falls out of the day-to-day work instead of becoming a fire drill.
- Partner with IT and teams across Safe to embed security into how work already gets done, delivering findings constructively and building the kind of trust that gets people calling you early.
- Represent Security Operations to leadership, communicating risk, incidents, and program status clearly to both technical and non-technical audiences.
QUALIFICATIONS, SKILLS, AND COMPETENCIES
Safers come from a variety of backgrounds with a diversity in skills and knowledge. That said, we find that those who are most successful in this role have experience with the following areas.
REQUIRED SKILLS:
- 5+ years in security operations, incident response, or a closely related security engineering discipline, including 1–2 years leading a team — as a manager, team lead, or technical lead with formal ownership of others' work.
- Meaningful ownership of a security program — incident response, vulnerability management, hardening, or similar — that you helped take from immature to reliably operating.
- Deep hands-on SIEM and EDR experience: building and tuning detections, running investigations, and improving signal-to-noise over time.
- Strong incident response background, including leading or coordinating response for significant incidents, running post-incident reviews, and maintaining runbooks that reflect reality. Familiarity with MITRE ATT&CK.
- Practical experience with vulnerability and patch management at scale, and with hardening and configuration management against a recognized standard such as the CIS Benchmarks.
- Solid network security knowledge, including protocols and architecture, and how to secure both on-premises and cloud environments.
- Solid cloud security knowledge, ideally AWS: IAM, logging, network controls, and posture management, plus experience securing and administering a cloud productivity suite such as Google Workspace.
- Working knowledge of identity and access: SSO, MFA, conditional access, device trust, and least-privilege design.
- Experience supporting or operating controls for ISO 27001, SOC 2, or comparable frameworks, and comfort with the evidence and audit side of the work.
- Excellent written and verbal communication, including the ability to explain risk and incidents clearly to leadership and to deliver difficult findings constructively.
DESIRED SKILLS / BONUS POINTS:
- Direct experience with our stack: Rapid7 InsightVM and InsightIDR, Google Workspace security and admin, Active Directory, AWS, Cisco Umbrella, and Cisco Secure Endpoint.
- Experience standing up or significantly maturing an incident response program, including on-call design and tabletop exercises.
- Demonstrated experience building AI or automation into security operations, and a point of view on how to do it safely.
- Experience with business continuity, disaster recovery, or resiliency planning.
- Experience hiring, growing, and developing a technical team from a small base.
- Scripting or development skills (Python, PowerShell, or similar) sufficient to build and review automation.
- Relevant certifications or a plan to complete certifications such as CISSP, CISM, GIAC, or equivalent.
- A Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field.
If you don't meet every single qualification but are excited about this role, we'd still love to hear from you.
WHAT YOU CAN EXPECT
When you choose a career with Safe Software, you're also choosing…
- Meaningful Work: Make a profound impact across our business, workplace and data integration product.
- A Supportive Environment: Feel empowered to share your ideas and implement them with high autonomy and team support.
- Social Responsibility: Become part of a team that finds meaningful ways to give back. Take paid time off to volunteer for one of our Safe-organized opportunities that align with our core community initiatives.
- Learning & Career Development: We believe in your continuous learning and growth. Take advantage of an annual learning budget and training programs paid for by Safe.
- Flexible Working Hours: Flexible and remote-friendly work arrangements to fit your lifestyle. Work when you want, and how you want to.
- Work-Life Balance: There's no place for burnout at Safe. Maintain a healthy balance of your personal and work life without splitting yourself in two. Enjoy 3 weeks of vacation to recharge, plus an additional paid 6 seasonal days off per year.
- Health & Wellness: Extended health, dental, health or lifestyle spending, and counseling benefits from day 1. That's right, no waiting period.
- Family is important: We are dedicated to supporting our employees through parenthood and offer a Parental Leave Top-Up Program for new parents through childbirth or adoption.
- Shared Success: Share in Safe's success with our bi-annual profit sharing and RRSP/TFSA matching program.
- An Accessible Commute: Regardless of your commute method, we're located close to public transit, and provide complimentary parking and bike storage for our team!
ABOUT SAFE SOFTWARE
Safe Software transforms organizations with FME, the only All-Data Any-AI Enterprise Integration Platform connecting all your data, anywhere, at any velocity.
With over 30 years of expertise and 25,000+ enterprise customers across 125+ countries, we simplify your data journey, wherever it leads.
Founded in 1993, Safe is headquartered in Surrey, BC with over 300 team members and counting. We’re always looking for talented individuals with diverse backgrounds who are determined to learn and grow. Are you ready to join the team?
OUR COMMITMENT TO DIVERSITY AND INCLUSION
Safe Software is an equal opportunity employer and we truly believe that innovation and strength begin with diversity and inclusion.
We welcome all candidates regardless of race, gender identity or expression, sexual orientation, age, ability, disability, national or ethnic origin, political belief, religion, or family status.
Should you require accommodations during the recruitment process, please contact hr_dept@safe.com.
NOTICE REGARDING USE OF AUTOMATED TOOLS IN HIRING
At Safe Software, we use automated tools to help us process applications and identify qualified candidates. These tools may assist in screening resumes and summarizing interview content based on the information you provide. This helps our team review applications efficiently while ensuring every candidate is considered based on the requirements of the role.
Please be assured that the final hiring decision is always made by a member of our team. For more information on how we protect your privacy, please see our policy https://www.safe.com/legal/#applicant-privacy-policy. If you have questions about this process, please contact us at hr_dept@safe.com.
JobMatch aggregates public listings. Always apply through the original posting.