Manager, IT Risk & Security Operations

REALTOR.ca

Ottawa

On-site

CAD 120,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health insurance
Employee referral program

Job summary

REALTOR.ca in Ottawa is seeking an experienced Manager, IT Risk & Security Operations to lead enterprise cybersecurity across security operations, cloud and identity security, vulnerability management, and governance.

You will translate strategy into operational practice, manage the security team, and act as the escalation point for incidents and risks, partnering with Infrastructure, Software Engineering, Product, and Service Desk.

Qualifications

  • Degree in Information Technology, Cybersecurity, or related field.
  • At least 8 years in cybersecurity or security operations.
  • Proven experience leading security teams and programs.

Responsibilities

  • Directly lead the security team, set goals, and coach performance.
  • Oversee daily security operations, incident response, and threat triage.
  • Drive vulnerability management, security testing, and risk-based remediations.
  • Collaborate with Infrastructure, Software Engineering, Product, and Service Desk.
  • Develop and maintain incident response playbooks and tabletop exercises.
  • Oversee security tech lifecycle, automation, and vendor relationships.

Skills

Team Leadership
Security Operations
Incident Response
Threat Detection
Vulnerability Management
Cloud & IAM Security

Education

Bachelor's in IT/Cybersecurity

Tools

SIEM/SOAR
EDR/XDR
Microsoft Defender
Azure
AWS

Job description

REALTOR.ca is a cornerstone of Canada’s real estate market, dedicated to helping millions of Canadians find attainable housing across the country. As the leading real estate platform in Canada, we offer the most comprehensive listings and resources to assist consumers in finding their dream homes.

At REALTOR.ca, we are committed to supporting REALTOR® members’ businesses and fostering consumer trust and loyalty. Our dedication to delivering value and continuously adapting to market demands ensures REALTOR.ca is more than just a listing service- it is the heart of the Canadian real estate experience.

Join us and be a part of a team that is at the forefront of the real estate industry, making a significant impact on the lives of Canadians every day.

Position Overview

The Manager, IT Risk & Security Operations leads REALTOR.ca Canada Inc.'s enterprise cybersecurity operations, including security operations, infrastructure and network security, cloud and identity security, application security, vulnerability management, cyber resilience, governance, risk management, third-party risk, and compliance.

The role translates cybersecurity strategy and policy into operational practice, leads the security operations function and incident response, and drives day-to-day risk reduction across the organization's technology environment. The Manager leads and develops the security team and serves as the operational escalation point for cybersecurity incidents and risks.

Core Competencies
  • Team Leadership & Coaching
  • Security Operations Execution
  • Technical Proficiency Across Security Tooling
  • Prioritization & Operational Judgment
  • Communication & Cross-Team Coordination
  • Process Improvement & Documentation
Function

Working closely with Infrastructure, Service Desk, Software Engineering, and Product teams, the Manager, IT Risk & Security Operations ensures security requirements and controls are effectively implemented throughout the technology lifecycle and supports the secure delivery and operation of enterprise platforms, digital services, and applications.

Key Responsibilities
Team Leadership & Operations Management
  • Directly manage, coach, and develop the security team, including goal-setting, performance reviews, skills development, and a culture of accountability, collaboration, and continuous improvement.
  • Own day-to-day scheduling, workload balancing, coverage, and priorities for the security operations function, translating broader security strategy into actionable team objectives.
  • Provide regular reporting on team performance, operational metrics, emerging risks, and areas requiring leadership attention.
  • Partner with Software Engineering, Product, Infrastructure, and Service Desk leadership to embed security requirements, secure design principles, risk-based decision-making, and governance throughout the technology lifecycle.
Security Operations & Incident Response
  • Lead daily security monitoring, alert triage, threat detection, and investigation across SIEM, SOAR, EDR/XDR, email security, and related platforms.
  • Act as the primary operational escalation point for security incidents and coordinate containment, recovery, communications, and post-incident follow-up.
  • Maintain and continuously improve incident response playbooks, runbooks, standard operating procedures, and escalation processes.
  • Coordinate tabletop exercises and support disaster recovery and ransomware-preparedness testing.
  • Drive detection engineering and SOC automation to improve coverage, consistency, and response efficiency.
Security Technology & Automation
  • Lead the evaluation, implementation, lifecycle management, renewals, upgrades, and day-to-day vendor relationships for security operations technologies, including SIEM, SOAR, EDR/XDR, vulnerability management, and email/endpoint security platforms.
  • Drive adoption of security automation to reduce manual effort in monitoring, triage, investigation, and remediation workflows.
  • Support larger strategic security initiatives and technology decisions requiring enterprise budget or executive approval.
Vulnerability Management & Security Testing
  • Run the day-to-day vulnerability management program, including scanning cadence, triage, risk-based prioritization, remediation tracking, dashboards, and reporting across infrastructure, endpoints, cloud, applications, and network devices.
  • Coordinate remediation timelines and priorities with Infrastructure, Software Engineering, Service Desk, and other stakeholders.
  • Coordinate internal and third-party penetration testing and security assessments across applications, infrastructure, networks, and cloud environments, and track findings through remediation and validation.
Infrastructure, Network, Cloud & Identity Security
  • Implement and maintain security standards and configuration baselines across on-premises infrastructure, endpoints, networks, cloud platforms, and Microsoft 365.
  • Oversee the operational security of IAM, PAM, MFA, Microsoft Entra ID, Active Directory, and other identity security controls.
  • Monitor and maintain security controls covering firewalls, network segmentation, secure remote access, endpoint protection, network detection, and cloud security posture.
  • Coordinate vulnerability remediation, security hardening, patching priorities, and control improvements with Infrastructure and Service Desk teams.
  • Partner with Infrastructure and Cloud teams to embed security requirements into technology changes, deployments, and day-to-day operations.
Risk, Governance & Compliance
  • Maintain the operational cyber risk register, support risk assessments, and elevate significant risk to leadership.
  • Support internal and external audits and compliance assessments by coordinating evidence, stakeholders, and remediation actions.
  • Coordinate third-party security assessment intake, tracking, and follow-up.
  • Help maintain adherence to security policies and standards aligned with NIST CSF, ISO 27001, CIS Controls, and OWASP.
Application Security
  • Serve as the operational liaison between IT Security and Software Engineering on application risk, translating material application risks into the enterprise risk process.
  • Coordinate application penetration testing and security audits, including scoping input, scheduling, evidence gathering, and tracking findings and recommendations through closure.
  • Review SAST, DAST, and SCA results from Software Engineering processes, help prioritize remediation from a risk perspective, and elevate material control gaps to IT and Software Engineering leadership.
  • Work with Product and Software Engineering teams to implement security requirements identified through architecture, design, project, and change-management reviews.
Security Awareness
  • Support security awareness, phishing simulation, and employee education initiatives, working with relevant teams to reinforce secure practices and address recurring risk themes.
Skills & Qualifications
  • Degree or diploma in Information Technology, Cybersecurity, Computer Science, or a related discipline, or an equivalent combination of education and experience.
  • Minimum 8 years of progressive experience in cybersecurity, security operations, or a related technical security discipline.
  • Minimum 3 years of experience managing or supervising a cybersecurity or technical team, including coaching, performance management, and employee development.
  • Hands- on experience with security monitoring, incident response, vulnerability management, and security operations technologies such as SIEM, SOAR, EDR/XDR, IAM/PAM, firewalls, and cloud security tools.
  • Experience evaluating, implementing, and managing security technologies throughout their lifecycle and using automation to improve security operations.
  • Experience partnering with security technologies and platforms such as Microsoft Sentinel, Microsoft Defender, Microsoft Entra ID, Azure, and AWS is an asset.
  • Experience partnering with Software Engineering, Infrastructure, Cloud, and Service Desk teams to implement and operationalize security controls.
  • Working knowledge of application security concepts, including SAST, DAST, SCA, and secure software development lifecycle principles, with the ability to assess risk and coordinate effectively with Software Engineering teams.
  • Familiarity with security frameworks and practices, including CIS Controls, NIST CSF, ISO 27001, and OWASP.
  • Strong communication, leadership, and operational judgment, with the ability to coach team members, work across technical and business teams, and elevate material risks appropriately.
  • A relevant security certification, such as Security+, CySA+, GIAC, CISSP, CISM, or CCSP, is a strong asset.
What Success Looks Like
  • A well-coached, high-performing security team with clear priorities, accountability, and growth paths.
  • Fast, effective detection, triage, response, and recovery from security incidents.
  • A vulnerability management and security testing program with clear SLAs, consistent remediation tracking, and reliable reporting.
  • Security controls across infrastructure, networks, cloud, identity, and applications that are consistently maintained and monitored.
  • Risk, audit, third-party assessments, and penetration-testing findings that are clearly tracked and closed in a timely manner.
  • Strong day-to-day partnerships with Infrastructure, Service Desk, Software Engineering, and Product teams.

We thank all applicants for their interest; however, only those under consideration for the role will be contacted.

At REALTOR.ca, we are committed to fostering an inclusive, barrier-free and accessible environment. If you require an accommodation, we will work with you to meet your needs. As an equal opportunity employer, we value the unique perspectives and experiences that each team member brings.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, IT Risk & Security Operations
Manager, IT Risk & Security Operations

Kibbi Technologies Inc. • Ottawa

Hybrid
CAD 110,000 - 170,000
Manager, IT Risk & Security Operations
Manager, IT Risk & Security Operations

Canadian Real Estate Association • Ottawa

Hybrid
CAD 120,000 - 160,000
Head of IT Risk & Security Operations
Head of IT Risk & Security Operations

REALTOR.ca • Ottawa

On-site
CAD 120,000 - 190,000
Health insurance
Employee referral program
Director, IT & Operational Resiliency
Director, IT & Operational Resiliency

MCAN Financial Group • Toronto

Hybrid
CAD 150,000 - 190,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

QuadReal Property Group • Vancouver

On-site
CAD 125,000 - 173,000
Health & dental
Pension plan
Paid time off
+1
Senior Cyber Security Analyst
Senior Cyber Security Analyst

QuadReal Property Group, LP • Vancouver

Hybrid
CAD 90,000 - 125,000
Performance-based incentive plan
Comprehensive health & dental benefits
Pension plan
+1
Senior Specialist Risk Management
Senior Specialist Risk Management

TEEMA • Toronto

On-site
CAD 126,000 - 176,000
Principal Engineer, Cyber Technology Operations SRE (Global Security)
Principal Engineer, Cyber Technology Operations SRE (Global Security)

RBC • Vancouver

On-site
CAD 150,000 - 210,000
Total Rewards Program
Bonuses
Stock options
+1
Principal Engineer, Cyber Technology Operations SRE (Global Security)
Principal Engineer, Cyber Technology Operations SRE (Global Security)

RBC • Toronto

On-site
CAD 140,000 - 210,000
Total rewards program
Bonuses and stock where applicable
Flexible benefits
Internal Cybersecurity Lead Cybera · Calgary, Canada Full-time · Hybrid — 5 hours ago
Internal Cybersecurity Lead Cybera · Calgary, Canada Full-time · Hybrid — 5 hours ago

Emploive • Calgary

Hybrid
CAD 120,000 - 160,000
Hybrid work environment
Health benefits from day 1
Professional development funds
+1