Manager, Detection & Response
Wealthsimple
In this role, you will have the opportunity to:
- Oversee and guide the strategy to evolve our security incident response (IR) capabilities, guiding the maturation of the IR framework, including playbooks, communication plans, and post-incident reviews, to drive swift, consistent, and scalable responses.
- Lead the planning and facilitation of regular tabletop exercises with key partners in Engineering, Regulatory Operations, and Customer Experience to ensure organizational readiness.
- Serve as the senior leader during major security incidents, providing clear direction, coordinating cross-functional efforts, and ensuring effective resolution.
- Oversee the execution of the security detection strategy, guiding the team to build high-fidelity detections and championing a data-driven approach to identify gaps, measure effectiveness, and inform strategic investments.
- Partner with Engineering and Security Engineering teams to ensure the right visibility is established in critical systems and to continuously refine our SIEM and SOAR platform capabilities.
- Ensure the detection program is tightly integrated with the response function, enabling the team to rapidly investigate and scope potential incidents.
- Lead, mentor, and grow a team of talented developers by managing the hiring plan to attract top talent, and enabling the continuous development of their skills in incident command, investigation, and stakeholder communication.
- Manage the team's on-call rotation, ensuring a sustainable and healthy operational tempo while providing excellent coverage.
- Build and maintain strong, collaborative relationships with key stakeholders across Engineering, Regulatory Operations, Customer Experience, Fraud, and Privacy teams.
- Act as the primary point of contact for the Detection & Response function, providing clear and timely updates to leadership during and after incidents.
- Translate complex technical findings and incident trends into actionable insights and metrics for the business, helping to shape the direction of security investment.
We’re looking for someone who:
- Has 8+ years of experience in the Cybersecurity domain, with a strong emphasis on defensive security operations.
- Has 4+ years of direct experience leading a security function, with a proven track record of building and/or maturing an Incident Response program.
- Has deep, hands-on experience as an Incident Commander or senior incident handler for complex security incidents.
- Has the ability to lead a cross-functional team with confidence and empathy during high-stress situations.
- Has a strong technical foundation in modern cloud infrastructure, security logging, and SIEM platforms.
- Has a strategic mindset, with the ability to develop a long-term vision and roadmap for a critical security function.
- Has excellent judgment under pressure and exceptional communication skills, with the ability to articulate risk and technical concepts to both technical and non-technical stakeholders.
- Has a passion for mentoring others and a belief in making the entire team successful.