Principal Information Security Analyst
Meet Benevity
Benevity is the way the world does good, providing companies (and their employees) with technology to take social action on the issues they care about. Through giving, volunteering, grantmaking, employee resource groups and micro-actions, we help most of the Fortune 100 brands build better cultures and use their power for good. We’re also one of the first B Corporations in Canada, meaning we’re as committed to purpose as we are to profits.
We have people working all over the world, including Canada, Spain, Switzerland, the United Kingdom, the United States and more!
High Level Role Overview
Benevity is looking for a Principal Information Security Analyst to join our Security Operations team. In this senior-level role, you will provide technical leadership and operational oversight across a team of analysts responsible for threat detection, alert triage, incident response, and vulnerability management.
This role is ideal for someone with deep hands‑on experience in security operations who is also energized by the opportunity to work alongside AI. We are actively integrating AI tools into our Sec Ops practice to accelerate triage, investigation, detection engineering, and analyst productivity, and this role will play a meaningful part in shaping how we do that. You should be comfortable navigating AI tools, building your own skills with them, identifying practical use cases, and partnering with the team to put them into production.
You will serve as both a senior escalation point and a coach, helping elevate the team’s ability to respond to threats in a cloud-native environment while modernizing how the work gets done.
What you’ll do:
- Lead daily Security Operations workflows, including triage, escalation, and resolution of alerts from core security tooling such as EDR, WAF, CSPM, SIEM, and cloud-native platforms
- Lead and coordinate security incident response across the full lifecycle, from detection and containment through eradication, recovery, and lessons learned, serving as incident commander for significant events
- Drive and oversee the triage, investigation, and resolution of alerts generated across all security tooling, not just those escalated by the MDR provider
- Act as the technical lead and escalation point for Managed Detection and Response (MDR) activities, ensuring timely review and validation of escalated alerts
- Identify, evaluate, and operationalize AI-assisted approaches to Sec Ops work, including AI-augmented triage, investigation, summarization, detection engineering, and reporting
- Build your own fluency with AI tooling and help the broader team develop the same skills, sharing patterns that work and being honest about ones that don’t
- Apply a healthy degree of skepticism to AI outputs, validating findings and helping the team understand where AI assists the work and where human judgment still owns the decision
- Develop and continuously refine incident response processes, detection logic, and triage playbooks to improve clarity and effectiveness
- Oversee the vulnerability management lifecycle, ensuring timely identification, prioritization, remediation tracking, and stakeholder coordination
- Collaborate with GRC, Product Security, Dev Ops, and Infrastructure teams to improve detection coverage, alert fidelity, and log quality
- Partner with our Senior Fraud Analyst on cross-functional investigations where fraud and cyber threats intersect, contributing Sec Ops expertise without owning the fraud function day‑to‑day
- Serve as a subject matter expert in cloud‑native security operations with strong understanding of containerized and API‑driven environments
- Support the development, tracking, and reporting of KPIs and metrics to measure and improve team performance
- Conduct post‑incident reviews and root‑cause analysis, driving preventive control enhancements
- Mentor junior and mid‑level analysts, providing feedback, coaching, and opportunities for growth
What you’ll bring:
- 7+ years of experience in information security or security operations, with at least 2 years in a team lead or senior analyst capacity
- Proven experience triaging and responding to alerts across a broad suite of tools including…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: