- Location
- Markham, Ontario - CAN, Canada
- Type
- Full-time
- Department
- Security
- Seniority
- Lead
- Experience
- 3+ years
- Source
- Workday
Description
CIT Information Security Lead
About the Role
Constellation Software’s rapidly expanding Perseus Operating Group (CSI) is seeking an experienced Information Security Lead to drive the design, development, and secure deployment of complex information systems. This role requires translating security frameworks into practical, scalable governance across a diverse portfolio of global businesses, operating environments, and cultures.
The ideal candidate brings a strong foundation in risk management, with the ability to assess and balance threats, vulnerabilities, and information value to enable informed security decisions. This role also demands proven leadership in designing, evaluating, and continuously improving security processes, while guiding cross-functional teams in strengthening organizational security posture and operational maturity.
Key Responsibilities
Security Operations & Incident Response
Monitor and investigate security alerts across endpoint, identity, email, and data protection platforms
Respond to escalations and coordinate incident containment and remediation
Perform root cause analysis and document findings
Track incidents through full lifecycle (detection, response, closure)
Coordinate cross-team response efforts during active incidents
Provide mentorship and technical leadership to SOC analysts, driving skill development and process consistency.
Security Tooling & Platform Operations
Support operations of enterprise tools including EDR/XDR, DLP, email security, and identity monitoring
Lead escalation handling for endpoint protection platforms (e.g., CrowdStrike-like tools)
Coordinate sensor/agent deployments, upgrades, and onboarding during acquisitions
Maintain operational dashboards and reporting visibility
Ensure consistent alert handling and response workflows across platforms
Support dashboard displays and reporting visibility (e.g., office display dashboards)
Monitoring & Investigations
Investigate endpoint detections and behavioral alerts
Monitor identity risks including risky users and insider risk signals
Perform DLP monitoring, reporting, and coordination activities
Conduct email investigations including trace analysis and troubleshooting
Manage and resolve security-related tickets (e.g., email protection platforms utilizing Proofpoint-like tools)
Security Awareness & Phishing
Conduct phishing investigations and response coordination
Support phishing simulation campaigns and reporting
Manage user synchronization and participation in awareness platforms
Identify trends from phishing results and recommend improvements
Governance, Risk & Compliance
Implement and maintain security policies aligned with industry frameworks (NIST, ISO, PCI, SOC)
Conduct risk assessments and document findings
Track remediation activities and risk mitigation progress
Support audits and compliance reporting
Assist with control validation and evidence collection
Collaboration & Support
Work with IT, Infrastructure, and business teams on security initiatives
Provide guidance on security incidents, tools, and processes
Document procedures, runbooks, and operational standards
Identify and drive process improvements and automation opportunities
Required Qualifications
3-5 years of experience in information security (operations, governance, or risk)
Experience operating in or supporting a Security Operations Center (SOC), including end-to-end incident lifecycle management (detection, investigation, response, and remediation)
Strong hands-on experience with endpoint detection, monitoring, and alerting tools, including tuning detections and improving signal quality
Proven experience with core Microsoft security technologies, including:
Microsoft Defender (Endpoint, M365, Identity) for threat detection and response
Data Loss Prevention (DLP) across M365 workloads
Working knowledge of compliance frameworks (e.g., NIST, ISO 27001, PCI-DSS, GDPR) and their application in enterprise environments
Strong analytical and communication skills, with the ability to translate technical findings into clear business risk and actionable outcomes
Ability to operate effectively in a global, distributed environment, including prioritizing work, adapting to changing business needs, and supporting occasional after-hours operations
Ability to communicate ideas in both technical and user-friendly language
Ability to investigate, troubleshoot and resolve complicated technical issues
Ability to effectively prioritize and execute tasks in a high-pressure environment
Highly self-motivated and directed, with keen attention to detail
Proven analytical and creative problem-solving abilities
Available for infrequent business travel
Ability to work within a diverse geographically distributed team
Willing to adjust work schedule to accommodate business needs
Exceptional documentation and customer service skills with written, oral, and interpersonal communication skills
Ability to adapt to different cultures with varying degrees of physical living standards, accommodations, and environments
Able to sit at a computer workstation for extended time periods and fully utilize the PC monitor, keyboard, mouse, and required programs
Preferred Qualifications
Advanced experience across the Microsoft Security ecosystem, including:
KQL query development, analytics rule creation, and incident correlation
Microsoft Purview (data governance, Insider Risk Management, eDiscovery, compliance solutions)
Microsoft Defender for Cloud Apps and cloud security posture management
Experience designing or integrating Microsoft security tools into an enterprise XDR or centralized security architecture
Experience driving SOC maturity, including playbook development, automation, and continuous process improvement
Experience operating in hybrid or multi-cloud environments with centralized security tooling
Demonstrated experience leading security process improvements or contributing to security program maturity across distributed organizations
Relevant certifications (e.g., CISSP, GIAC, Microsoft Security certifications)
Compensation
CSI offers a competitive base salary, bonus potential, a full benefits package, and a great environment.
Salary Range (Ontario & BC Only):
The estimated base salary range for this role is CAD$103,500.00 - CAD$126,500.00 per year. We include salary ranges in job postings only where required by applicable pay transparency laws, based on the jurisdictions in which the role may be performed. The posted range is a good faith estimate and reflects factors that are subject to change. Final offer amounts may vary based on job-related factors, including work location, candidate experience and expertise, and other relevant considerations.We recognize the value and importance of diversity and inclusion in our communities and in the workplace. We celebrate diversity and one of our goals as an employer is to create an inclusive work environment for all employees. We are an equal opportunity employer and do not discriminate against any employee or applicant because of race, religion, sex, sexual orientation including gender identity or expression, pregnancy, national origin, age, marital status, veteran status, disability status, or any other category or characteristic protected by law.Applicants with disabilities who would like to require a reasonable accommodation related to any part of the application process may contact us at [email protected].#Perseus HO