IT & Security Operations Lead

IT & Security Operations Lead

Software Secured is a leading Penetration Testing as a Service company, with a head office in beautiful Ottawa, Canada. We help software development teams get ahead of hackers using a suite of services and products.

This role sits at the intersection of hands-on IT operations, internal security ownership, and compliance stewardship. You will be the first dedicated owner of this function at Software Secured, the person who makes sure our own house is in order while the rest of the team focuses on securing our clients.

You will work alongside engineers who test production systems for a living. That means you will be respected for competence, not title. If you thrive with full ownership, no committee approval, and a team that will challenge you to be sharp, this is your role.

What you get:

  • You will receive a competitive salary.
  • You will receive a yearly profit-sharing between 8 - 15% of your salary based on your performance.
  • You will be provided with perks such as a monthly refreshed Ubereats budget, work from home stipend.
  • You will receive a great health benefits package.
  • You will receive a free Audible account.
  • You will receive a minimum of 3 weeks' vacation.
  • You will receive time and a budget for training and self-development.
  • 10% of your time goes to building and improving the function — not just maintaining it.


What you will own:

Internal Security

  • Own our internal security posture end-to-end, network architecture, firewall configuration, WiFi segmentation, and endpoint protection.
  • Proactively identify threats relevant to a penetration testing firm and take action before they become incidents.
  • Implement and maintain detection capabilities so we know when something is wrong.
  • Think like an attacker, we are a high-value target and you should treat us like one.


IT Operations

  • Own the full device lifecycle, procurement, configuration, hardening, and decommissioning.
  • Manage MDM, SaaS licenses, access controls, and identity management.
  • Ensure onboarding and offboarding are airtight from an IT and access perspective.
  • Maintain asset inventory and documentation that is actually up to date.


Compliance

  • Maintain our SOC 2 Type II compliance program, evidence collection, control monitoring, audit readiness.
  • Support future certification efforts including CREST as we pursue enterprise and international contracts.
  • Own vendor security reviews and onboarding assessments.
  • Keep policies current and relevant, not just for auditors but because they reflect how we actually operate.


Onboarding Coordination

  • Partner with HR to ensure new hires are fully set up and supported from offer acceptance through their first 90 days.
  • Own the internal side of onboarding, equipment, access, tools, and a smooth landing.

What we are looking for:

  • You must be living in Ottawa, Canada
  • Share our core values (please see below).
  • 5–7 years of experience in IT operations, security operations, or a hybrid of both.
  • Hands-on experience with network security, firewall management, network segmentation, and traffic monitoring.
  • Solid MDM and endpoint management experience across macOS and Windows environments.
  • Familiarity with SOC 2 compliance requirements and evidence management.
  • Experience owning a function solo, you set the direction, you drive it, you deliver it.
  • Clear, direct communicator with highly technical teams and non-technical stakeholders alike.
  • This job is available to Canadian citizens, permanent residents, or work visa holders.

Nice to have:

  • CompTIA Security+, CySA+, CISSP, or equivalent certification.
  • Exposure to penetration testing concepts or a security consulting environment.
  • Experience with Vanta, Drata, or similar compliance automation platforms.
  • Security clearance eligibility.
  • Experience building a compliance or IT program from scratch.

What we care about

Passion for security: Security and privacy matters more than anything else. We prioritize it within all of our business decisions as a part of our goal to make the digital world a little safer.

Growth mindset: Security is an ever-changing field. Through curiosity, constant learning (and un-learning), and humility, we are able to stay ahead of the curve.

Determination: Tough problems are something we'll never shy away from. Instead, problems are seen as an opportunity to do better, create new solutions, and innovate.

Empathy: We help our customers go through their customer journey with no judgment - all the way from sales to post-test support.

Integrity: Integrity drives everything we do. We are honest, straightforward, and commit to doing the right thing, even when no one is watching.


See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available