Skip to content

Open nowPosted 37 days ago

IT & Security Operations Lead

Software Secured3 open roles

Where
Ottawa, Ontario, Canada
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowIT & Security Operations LeadSoftware Secured · Ottawa, Ontario, Canada
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Software Secured's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.8%1 day
  2. 3.8%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.2%30 days
This job: posted 37 days ago

The posting

IT & Security Operations Lead

Software Secured is a leading Penetration Testing as a Service company, with a head office in beautiful Ottawa, Canada. We help software development teams get ahead of hackers using a suite of services and products.

This role sits at the intersection of hands-on IT operations, internal security ownership, and compliance stewardship. You will be the first dedicated owner of this function at Software Secured, the person who makes sure our own house is in order while the rest of the team focuses on securing our clients.

You will work alongside engineers who test production systems for a living. That means you will be respected for competence, not title. If you thrive with full ownership, no committee approval, and a team that will challenge you to be sharp, this is your role.

What you get:

  • You will receive a competitive salary.
  • You will receive a yearly profit-sharing between 8 - 15% of your salary based on your performance.
  • You will be provided with perks such as a monthly refreshed Ubereats budget, work from home stipend.
  • You will receive a great health benefits package.
  • You will receive a free Audible account.
  • You will receive a minimum of 3 weeks' vacation.
  • You will receive time and a budget for training and self-development.
  • 10% of your time goes to building and improving the function — not just maintaining it.

What you will own:

Internal Security

  • Own our internal security posture end-to-end, network architecture, firewall configuration, WiFi segmentation, and endpoint protection.
  • Proactively identify threats relevant to a penetration testing firm and take action before they become incidents.
  • Implement and maintain detection capabilities so we know when something is wrong.
  • Think like an attacker, we are a high-value target and you should treat us like one.

IT Operations

  • Own the full device lifecycle, procurement, configuration, hardening, and decommissioning.
  • Manage MDM, SaaS licenses, access controls, and identity management.
  • Ensure onboarding and offboarding are airtight from an IT and access perspective.
  • Maintain asset inventory and documentation that is actually up to date.

Compliance

  • Maintain our SOC 2 Type II compliance program, evidence collection, control monitoring, audit readiness.
  • Support future certification efforts including CREST as we pursue enterprise and international contracts.
  • Own vendor security reviews and onboarding assessments.
  • Keep policies current and relevant, not just for auditors but because they reflect how we actually operate.

Onboarding Coordination

  • Partner with HR to ensure new hires are fully set up and supported from offer acceptance through their first 90 days.
  • Own the internal side of onboarding, equipment, access, tools, and a smooth landing.

What we are looking for:

  • You must be living in Ottawa, Canada
  • Share our core values (please see below).
  • 5–7 years of experience in IT operations, security operations, or a hybrid of both.
  • Hands-on experience with network security, firewall management, network segmentation, and traffic monitoring.
  • Solid MDM and endpoint management experience across macOS and Windows environments.
  • Familiarity with SOC 2 compliance requirements and evidence management.
  • Experience owning a function solo, you set the direction, you drive it, you deliver it.
  • Clear, direct communicator with highly technical teams and non-technical stakeholders alike.
  • This job is available to Canadian citizens, permanent residents, or work visa holders.

Nice to have:

  • CompTIA Security+, CySA+, CISSP, or equivalent certification.
  • Exposure to penetration testing concepts or a security consulting environment.
  • Experience with Vanta, Drata, or similar compliance automation platforms.
  • Security clearance eligibility.
  • Experience building a compliance or IT program from scratch.

What we care about

Passion for security: Security and privacy matters more than anything else. We prioritize it within all of our business decisions as a part of our goal to make the digital world a little safer.

Growth mindset: Security is an ever-changing field. Through curiosity, constant learning (and un-learning), and humility, we are able to stay ahead of the curve.

Determination: Tough problems are something we'll never shy away from. Instead, problems are seen as an opportunity to do better, create new solutions, and innovate.

Empathy: We help our customers go through their customer journey with no judgment - all the way from sales to post-test support.

Integrity: Integrity drives everything we do. We are honest, straightforward, and commit to doing the right thing, even when no one is watching.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Software Secured's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Software Secured's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Software Secured's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.