{bc}
linkedin

Senior Manager, Information Security

Benevity
Vancouver, CAN
Full-time
Mid-Senior
Hybrid
Discovered 2 weeks ago
Information securitySecurity operationsCloud securityAWSIncident responseAI and LLM security
Free

Job Fit Check

Base Career helps you apply smarter for this job.

?%
Ready to Scan

Key skills for this role

Information securitySecurity operationsCloud security
Smart Apply

Full Job Posting

Role overview

Lead Benevity’s security operations, product and application security, and corporate security teams.

Own the security posture of Benevity’s cloud-native platform while managing security leaders and senior individual contributors.

Partner with GRC and fraud operations and define security practices for AI-powered product capabilities and internal AI tooling.

What you’ll do

  • Lead and coach a multidisciplinary security team, including development, hiring, and sustainable operating cadence.
  • Own security KPIs, the information security roadmap, and security vendor performance.
  • Oversee security operations and incident response as senior escalation lead during major events.
  • Establish AI security standards for LLM integrations, RAG pipelines, and agentic workflows.
  • Embed security into the SDLC through CI/CD automation, application security testing, secure API patterns, and threat modeling.
  • Maintain the security risk register and vulnerability management lifecycle, prioritizing remediation by real-world risk.
  • Direct security hygiene, phishing simulations, awareness training, and the Responsible Disclosure Program.
  • Partner with DevOps and GRC on infrastructure-as-code security, audit obligations, and posture metrics.

What you’ll bring

  • 10+ years of progressive information security experience, including 5+ years leading teams.
  • Experience managing managers and individual contributors and developing both groups.
  • Hands-on security operations experience on AWS and other cloud providers.
  • Experience leading major incident response as incident commander.
  • Practical understanding of AI and LLM security risks, including prompt injection and agentic systems.
  • Working knowledge of SAST, SCA, DAST, API and microservices security, and threat modeling.
  • Deep understanding of cloud security, threat detection, and attacker tactics in containerized, API-driven environments.
  • Hands-on WAF experience is required.
  • Experience owning budgets, selecting vendors, and managing managed-service relationships.
  • Bachelor’s degree in Computer Science or Information Security, or equivalent practical experience.

Additional qualifications

  • Familiarity with NIST CSF, ISO 27001, SOC 2 Type II, CIS Controls, and OWASP SAMM or BSIMM.
  • Relevant certifications such as CISSP, CISM, or GCIH are advantageous.
  • IC-level credentials such as OSCP, CSSLP, or GWAPT are advantageous.
  • SaaS product experience, regulated-environment experience, and multi-tenant architecture experience are advantageous.
  • Strong analytical, communication, ownership, and accountability skills are required.

Where we work

  • Benevity uses a flexible hybrid approach for employees located near one of its offices.
  • There is no set in-office requirement, but in-person collaboration is valued for onboarding, project work, and team connection.

Apply for this job in 1 click

Skip the repetitive application forms

Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.

Sarah M.James T.Maya R.

Trusted by over 500,000 job seekers on Base Career

Start Free Today

More from this employer

More jobs at Benevity