Senior Information Security Officer

SOCAN

Toronto

On-site

CAD 101,360 - 121,360

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

35-hour work week
Twelve paid sick days annually
Access to fitness facility
Annual Performance Incentive bonus
Defined contribution Pension Plan
Comprehensive health and dental benefits

Job summary

A leading Canadian organization is seeking a Senior Information Security Officer to enhance security governance and manage risks. This role includes developing and implementing security policies, conducting risk assessments, and leading incident responses. Candidates should have a Bachelor’s degree in Computer Science or equivalent, along with 5+ years in information security and experience with SIEM platforms. The position offers a salary range of $101,360 – $121,360 and various benefits, including comprehensive health coverage and performance bonuses.

Qualifications

  • 5+ years of experience in information security across various domains.
  • Hands-on experience with vulnerability management and security assessments.
  • Experience in performing threat hunting and incident response.

Responsibilities

  • Develop, maintain, and socialize security policies and procedures.
  • Lead and support security risk assessments and control reviews.
  • Design and improve security monitoring and alerting processes.

Skills

KQL proficiency
Incident response experience
Automation/scripting ability
Experience with SIEM platforms
Strong written and verbal communication skills

Education

Bachelor’s degree in Computer Science or related field
Relevant security certifications (CISSP, CISM, etc.)

Tools

Microsoft Sentinel

Job description

Position Overview

Job Title: Senior Information Security Officer (SISO)

Location: Toronto, ON (Remote)

Employment Type: Permanent Full‑Time

Salary: $101,360 – $121,360

Language: English required; French is an asset

Key Responsibilities
  • Security Governance: develop, maintain, and socialize security policies, standards, procedures, and architecture guardrails aligned to business objectives.
  • Risk Management: lead and/or support security risk assessments, control reviews, threat modeling, risk treatment plans, and executive‑ready reporting.
  • Security Operations: design and continuously improve security monitoring, alerting, and response processes across Microsoft Azure cloud and on‑prem infrastructure (VMware ESX/NSX), as well as endpoint, identity, network, and SaaS environments.
  • Detection Engineering: build and tune SIEM detections and analytics (queries, correlation rules, use cases), reduce false positives, and measure detection coverage (e.g., mapped to MITRE ATT&CK).
  • Threat Hunting: conduct proactive hunts using logs/telemetry, develop hypotheses, document findings, and translate learnings into new detections and control improvements.
  • Incident Handling: triage and investigate security alerts; lead incident response from containment through eradication and recovery; run post‑incident reviews and drive corrective actions.
  • SIEM & Automation: operate and optimize SIEM/SOAR integrations, log onboarding, parsing/normalization, playbooks, and automations to improve MTTR and analyst efficiency.
  • Vulnerability Management: manage scanning and remediation workflows, prioritize findings based on risk, track SLAs, and validate fixes.
  • Security Assessments & Testing: perform technical security assessments, configuration reviews, and support or execute penetration testing; coordinate remediation with owners.
  • Application Security: partner with developers or vendors on secure SDLC practices and standards (OWASP ASVS and OWASP Top 10), including code review support, dependency scanning, secrets management, CI/CD security, and developer enablement.
  • Third‑Party & SaaS Security: assess vendors and integrations, review security controls, and monitor ongoing risk.
  • Security Awareness: contribute to security training, guidance, and internal communications to strengthen the security culture.
  • Documentation & Metrics: maintain runbooks and playbooks; define KPIs/KRIs (e.g., coverage, response times, patch SLAs) and report progress.
Qualifications & Experience
  • Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent practical experience).
  • 5+ years of progressive experience across multiple information security domains (governance/risk and hands‑on security operations).
  • Hands‑on experience with SIEM platforms (Microsoft Sentinel) including log onboarding, detection development, tuning, and dashboarding.
  • Demonstrated detection engineering and investigation skills: KQL proficiency, alert triage, and evidence‑based incident response.
  • Experience performing threat hunting and translating hunts into detection use cases and playbooks.
  • Incident response experience including scoping, containment, eradication, recovery, and post‑incident retrospectives.
  • Strong understanding of core security controls across identity (SSO/MFA), endpoint security, networking, logging/telemetry, and hybrid security concepts spanning Microsoft Azure and on‑prem infrastructure (VMware ESX/NSX), including Entra ID/Azure AD, Azure networking, key management, cloud posture management, and segmentation/micro‑segmentation.
  • Vulnerability management experience: scanning (infrastructure and apps), prioritization, remediation tracking, and verification.
  • Experience with security assessments and/or penetration testing methodologies and reporting.
  • Application security experience: secure SDLC, OWASP Top 10, API security, dependency and secrets scanning, and partnering with developers.
  • Automation/scripting ability (e.g., Python, PowerShell, Bash) and experience integrating security tools via APIs/webhooks; SOAR/playbook experience preferred.
  • Knowledge of security frameworks and standards (e.g., NIST CSF / 800‑53, ISO 27001, CIS Controls) and practical risk management.
  • Relevant certifications are an asset (e.g., CISSP, CISM, GIAC, GCIH, GCIA, GCED, OSCP, AZ‑500, SC‑200/SC‑100).
  • Excellent written and verbal communication skills; able to explain risk and technical findings to both technical and non‑technical audiences.
Benefits
  • 35‑hour work week schedule (possible flexible work options, e.g., 4‑day work week).
  • Twelve paid sick days annually (including five personal days).
  • Access to SOCAN fitness facility.
  • Annual Performance Incentive bonus (dependent on personal and company performance).
  • Defined contribution Pension Plan.
  • Comprehensive health and dental benefits program.
  • Inclusive and collaborative working environment.
Commitment to Diversity, Equity, Inclusion, and Anti‑Racism

SOCAN thrives with a variety of viewpoints, identities, and backgrounds, and we are committed to anti‑racism. Everyone is welcome to apply for our wide range of roles, regardless of gender identity, gender expression, ethnicity, race, age, culture, sexual orientation, religious belief, or physical ability. SOCAN remains dedicated to creating a more equitable, inclusive, and diverse workplace.

Accessibility & Accommodation

SOCAN is committed to providing an inclusive workplace environment that meets the accessibility needs of employees with disabilities.

Equal Employment Opportunity

Socan is an Equal Opportunity Employer. Hiring and other employment decisions at Socan are made without regard to race, colour, religion, sex, ancestry, national origin, ethnic origin, age, disability, citizenship, veteran status, sexual orientation, record of offences, marital status, family status, or any other characteristic protected by federal, provincial, or local law, regulation, or ordinance. We encourage applicants of all backgrounds to apply.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Operations & Strategic Initiatives Lead
Operations & Strategic Initiatives Lead

SOCAN • Toronto

Hybrid
CAD 84,000 - 106,000
35-hour workweek
Hybrid work model
Inclusive and collaborative working环境
Temp. AV Identification Administrator
Temp. AV Identification Administrator

SOCAN • Toronto

Hybrid
CAD 44,000 - 56,000
Flexible work options
Access to fitness facility
Inclusive working environment
Data Analyst
Data Analyst

SOCAN • Toronto

Hybrid
CAD 71,000 - 90,000
35-hour workweek
Sick days
Fitness facility
+3
Distribution Royalty Allocation Administrator (Royalty Operations)
Distribution Royalty Allocation Administrator (Royalty Operations)

SOCAN • Toronto

Hybrid
CAD 52,000 - 66,000
Flexible workweek options
Twelve paid sick days annually
Access to a fitness facility
+4
Administrateur·trice à l’identification et à la répartition (revenus étrangers)
Administrateur·trice à l’identification et à la répartition (revenus étrangers)

SOCAN • Montreal (administrative region)

Hybrid
CAD 52,000 - 66,000
Flexibilité du lieu de travail
Douze jours de congé de maladie
Prime annuelle de rendement
+2
Temp Distribution Administrator (Agreements)
Temp Distribution Administrator (Agreements)

SOCAN • Toronto

Hybrid
CAD 45,000 - 50,000
Access to SOCAN fitness facility
Flexible work options including a 4-day work week
Inclusive working environment
+1
Enterprise Security Specialist
Enterprise Security Specialist

Cprvision • Whitchurch-Stouffville

Hybrid
CAD 120,000 - 135,000
Flexible working arrangements
Comprehensive benefits package
Annual bonus program
+1
Senior Cyber Security Specialist
Senior Cyber Security Specialist

Socket.dev • Burnaby

Hybrid
CAD 120,000 - 160,000
Health benefits
Retirement plan
Employee discount
Cybersecurity Consulting Associate
Cybersecurity Consulting Associate

Sopra Steria • Toronto

Hybrid
CAD 60,000 - 80,000
Competitive compensation
Comprehensive benefits package
Paid time off
+3
Senior Cyber Security Specialist
Senior Cyber Security Specialist

Sobeys • Mississauga

On-site
CAD 120,000 - 160,000
Health & dental
ESOP (Employee Stock Ownership Plan)
Discount at banners
+5