More jobs:
Principal Information Security Analyst
Job Description & How to Apply Below
Overview
Meet Benevity
Benevity is the way the world does good, providing companies (and their employees) with technology to take social action on the issues they care about. Through giving, volunteering, grantmaking, employee resource groups and micro-actions, we help most of the Fortune 100 brands build better cultures and use their power for good. We’re also one of the first B Corporations in Canada, meaning we’re as committed to purpose as we are to profits.
We have people working all over the world, including Canada, Spain, Switzerland, the United Kingdom, the United States and more.
Note: This section preserves the original language where possible while organizing content into clearly defined sections.
What You'll Do- Lead daily Security Operations workflows, including triage, escalation, and resolution of alerts from core security tooling such as EDR, WAF, CSPM, SIEM, and cloud-native platforms
- Lead and coordinate security incident response across the full lifecycle, from detection and containment through eradication, recovery, and lessons learned, serving as incident commander for significant events
- Drive and oversee the triage, investigation, and resolution of alerts generated across all security tooling, not just those escalated by the MDR provider
- Act as the technical lead and escalation point for Managed Detection and Response (MDR) activities, ensuring timely review and validation of escalated alerts
- Identify, evaluate, and operationalize AI-assisted approaches to Sec Ops work, including AI-augmented triage, investigation, summarization, detection engineering, and reporting
- Build your own fluency with AI tooling and help the broader team develop the same skills, sharing patterns that work and being honest about ones that don't
- Apply a healthy degree of skepticism to AI outputs, validating findings and helping the team understand where AI assists the work and where human judgment still owns the decision
- Develop and continuously refine incident response processes, detection logic, and triage playbooks to improve clarity and effectiveness
- Oversee the vulnerability management lifecycle, ensuring timely identification, prioritization, remediation tracking, and stakeholder coordination
- Collaborate with GRC, Product Security, Dev Ops, and Infrastructure teams to improve detection coverage, alert fidelity, and log quality
- Partner with our Senior Fraud Analyst on cross-functional investigations where fraud and cyber threats intersect, contributing Sec Ops expertise without owning the fraud function day-to-day
- Serve as a subject matter expert in cloud-native security operations with strong understanding of containerized and API-driven environments
- Support the development, tracking, and reporting of KPIs and metrics to measure and improve team performance
- Conduct post-incident reviews and root-cause analysis, driving preventive control enhancements
- Mentor junior and mid-level analysts, providing feedback, coaching, and opportunities for growth
- 7+ years of experience in information security or security operations, with at least 2 years in a team lead or senior analyst capacity
- Proven experience triaging and responding to alerts across a broad suite of tools including CSPM, WAF, EDR, SIEM, and cloud-native logging platforms
- Familiarity with MDR service models and hands-on experience validating escalated alerts
- Hands-on experience leading security incident response, including acting as incident commander, coordinating cross-functional responders, managing communications, and producing post-incident artifacts
- Practical experience using AI tools in a security or technical context, with a clear point of view on where they add value, where they fall short, and how to get them production-ready
- Curiosity and willingness to keep building AI skills as the tooling evolves, and an interest in helping teammates do the same
- Awareness of the security considerations that come with using AI tools in a Sec Ops environment (data handling, prompt hygiene, output validation)
- Demonstrated ability to work independently, while recognizing when to seek input or escalate appropriately
- Strong critical thinking and…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×