Manager, Enterprise Security
Wealthsimple
Responsibilities:
- Develop and communicate a scalable enterprise security strategy for corporate infrastructure and SaaS applications in partnership with security and engineering leadership, ensuring alignment with business objectives.
- Lead security development initiatives across Zero Trust, identity management, brand protection, and emerging technology security domains.
- Build and maintain a 'people first' team culture with clear expectations, regular feedback, and comprehensive support for professional growth.
- Drive cross-domain initiatives for AI adoption, data protection, and device management programs while ensuring risks and priorities are proactively communicated with stakeholders.
- Establish and maintain security governance frameworks for critical business applications (Google Workspace, Slack, etc.), including defined SLAs and agreed-upon project delivery timelines.
- Oversee implementation of security automation and infrastructure using modern development practices (Ruby, Python, TypeScript, GraphQL, IaC) across AWS and GCP environments.
- Manage budget planning, resource allocation, and strategic roadmap development for security teams, establishing KPIs and metrics to measure program effectiveness.
- Build, scale, and retain high-performing security development teams through strategic hiring, mentorship, and career development programs.
- Advance security program maturity through metrics-driven process improvement and strategic technology adoption while maintaining team velocity and fostering innovation.
Skills and Experience:
- 8+ years of enterprise security development experience, including 2+ years managing security teams and programs. Equivalent experience through non-traditional paths (career changes, diverse industry backgrounds) will be considered.
- Strong technical background in software development using GraphQL, Ruby, Python, or TypeScript with hands-on experience building security automation and tooling.
- Experience with OAuth, SAML, and modern identity protocols, including implementation in enterprise environments supporting large user bases.
- Extensive experience making complex security decisions and assessing their impact on business operations, growth, and user experience.
- Track record of building security programs that scale with organizational growth and technology adoption while maintaining agility.
- Experience with budget planning, resource allocation, and strategic roadmap development. We value both direct budget ownership and collaborative financial planning experience.
- Demonstrated ability to build relationships with stakeholders at all levels and collaborate effectively across functions to achieve shared security goals.
- Experience with Infrastructure as Code tools (such as Terraform) for automation in cloud environments (AWS, GCP, or similar platforms).
- Technical understanding of Zero Trust architectures, device management, data protection, and emerging technology security considerations.
- Experience working with security and compliance frameworks and regulatory requirements (examples: SOC1, SOX, PCI DSS, GDPR, NIST CSF).
Nice to Have:
- Experience managing security teams in high-growth technology environments or fintech/regulated industries.
- Knowledge of AI security frameworks, governance, and emerging technology risk management practices.
- Track record of successful brand protection and anti-phishing technology implementations.
- Previous experience scaling security engineering organizations and establishing cross-domain security programs from the ground up.
Relevant Education and Certifications (preferred, or equivalent experience)
- Preferably one or more: CISSP, CISM, CISA, GSLC
- Preferably cloud certifications from AWS or GCP, or relevant security certifications like CCSP
- Preferably a bachelor's or higher degree in computer science, cybersecurity, software engineering, or a related field
