Retour à la recherche
II
Intouch InsightSource d’offres vérifiée

Lead, IT, DevOps & Security

Offre en anglais

Lead the execution and expansion of the SOC 2 program while owning all IT infrastructure, DevOps, and security across the company. Act as a player-coach by personally implementing automated controls and infrastructure while managing a small IT and DevOps team.

  • Hybride
  • Ottawa, ON
  • Publié 23 juill. 2026
  • 1 poste

Résumé du poste

The Mission Intouch Insight is scaling its security and compliance program, and we are hiring a technical leader to own it. As Lead, IT, DevOps & Security, you will lead the execution and expansion of our SOC 2 program — extending it beyond Security to add the Confidentiality and Availability Trust Services Criteria — while owning all of IT infrastructure, DevOps, and security across the company. You treat IT and compliance as engineering problems — "compliance as code," "IT stack as code" — building automated, auditable systems rather than managing from a distance. This is a hands-on, player-coach role. You will personally do much of the implementation — building the automated controls, infrastructure, and security tooling yourself — while also leading a small team (IT and DevOps), setting the roadmap, and acting as the company's owner of security and compliance as we grow toward our next revenue milestone and serve a larger enterprise customer base. Roughly the majority of your time is spent building; the rest is leading, planning, and owning outcomes. What You'll Do Own and expand the SOC 2 program (primary focus). Own our SOC 2 Type 2 program — already running in Vanta — and lead its expansion beyond the Security baseline to add the Confidentiality and Availability Trust Services Criteria. Design and operationalize the new controls (e.g. data classification and handling, encryption and access controls for confidential data; capacity, backup, disaster-recovery, and uptime monitoring for availability), map them into Vanta, and keep evidence collection continuous and audit-ready. Own the auditor relationship and drive toward zero critical findings. Lead security engineering. Set IT and information-security policy, run vulnerability management and remediation, and lead incident detection, alerting, and response — all through an automation-first lens. Champion security best practices across the organization. Lead the team (as a player-coach). Manage and develop the IT and DevOps staff, set expectations and growth paths, and be the decision-maker and escalation point the team relies on — while staying deep in the work yourself rather than managing from a distance. Own DevOps across product and corporate. Oversee product/platform DevOps (CI/CD, application infrastructure, deployment pipelines supporting the engineering team) as well as corporate infrastructure and identity. Run IT as code. Use Terraform to manage and provision cloud identity and security infrastructure for a reproducible, scalable environment. Administer and secure a mixed Windows/macOS fleet with Microsoft Intune and Jamf; automate device enrollment, patching, and configuration. Own identity & access. Secure and automate the user lifecycle across Microsoft Entra ID and Google Workspace. Set strategy. Develop and own the IT, DevOps, and security roadmap aligned to business goals; manage the operational budget and vendor relationships. What You'll Need SOC 2 leadership. Demonstrable experience leading or substantially driving SOC 2 Type 2 programs — ideally including adding Trust Services Criteria (Confidentiality, Availability) to an existing scope. Hands-on experience with a compliance automation platform (Vanta or similar) is a strong asset. People leadership. Experience managing a team (IT, DevOps, and/or security), setting direction, and developing people — or a strong senior/lead ready to step up, with the judgment to be an accountable decision-maker. Security depth. Hands-on background in IT/security engineering: policy, vulnerability management, incident response, and modern detection/alerting. The DevOps mindset. Proven use of Terraform (or equivalent IaC) to manage cloud IAM, especially Microsoft Entra ID; comfort across product and corporate DevOps. Communication. Able to articulate security and technology strategy to both technical teams and executive leadership. Nice to Have Modern endpoint expertise. Securing Windows (Intune) and macOS (Jamf) fleets. Platform breadth. Hands-on administration of Microsoft Entra ID and Google Workspace in a corporate setting. Success Measures A successfully expanded SOC 2 program: Confidentiality and Availability criteria added to the audit scope and brought under continuous, automated compliance with zero critical findings. Security posture: reduced risk through automated detection, timely remediation, and enforced policy. Team capability: a well-run, growing IT/DevOps function with clear ownership and development. Reliability & efficiency: high uptime of critical infrastructure and reduced manual overhead through automation Compensation: $110,000 - $140,000 Hybrid to us means that you primarily work from home, with no more than 1 day per week in the Kanata office, if you live within range. About Intouch Intouch Insight is a growing technology and managed services company with headquarters in Ottawa, Canada. We take great pride in the Customer Experience ecosystem we’ve created, allowing us to be at the forefront of innovation and driving growth for our clients. We have a 25+ year history and a Fortune 1000 customer-base. Our single platform approach allows multiple data sources such as Survey, Checklists, Mystery Shop and Audit data to use our common reporting platform. At our core, we’re passionate about helping businesses create experiences to win customers for life. Intouch Insight provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training. Intouch welcomes and encourages applications from people with disabilities. Accommodations are available on request for candidates taking part in all aspects of the selection process. If you require accommodation, please contact hr@intouchinsight.com

Ce que vous ferez

Lead the execution and expansion of the SOC 2 program while owning all IT infrastructure, DevOps, and security across the company. Act as a player-coach by personally implementing automated controls and infrastructure while managing a small IT and DevOps team.

Exigences

Requires demonstrable experience leading SOC 2 Type 2 programs and a strong background in IT/security engineering. Must be proficient with Terraform for Infrastructure as Code and have experience managing teams and cloud identity platforms.

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • SOC 2 Compliance
  • DevOps
  • IT Security Engineering
  • Terraform
  • Infrastructure as Code
  • Vanta
  • Microsoft Entra ID
  • Microsoft Intune
  • Jamf
  • Google Workspace
  • Vulnerability Management
  • Incident Response
  • People Management
  • CI/CD
  • Cloud IAM
  • Network Security
  • Player Coach
  • Pipelines
  • Cloud Identity and Access Management (IAM)
  • IT Security
  • Evidence Collection
  • IT Infrastructure
  • Planning
  • Infrastructure Security
  • Access Controls
  • Mac OS
  • Auditing
  • Automation
  • Decision Making
  • Customer Service
  • Communication
  • Confidentiality
  • Training And Development
  • Encryption
  • Disaster Recovery
  • Leadership
  • Scalability
  • Innovation
  • Security Engineering
  • Technology Strategies
  • Managed Services
  • Mystery Shopping
  • Security Policies
  • Tooling
  • Vendor Relationship Management
  • Microsoft Intune (Mobile Device Management Software)
  • Reliability
  • Data Classification

Domaines d’emploi

  • Security & Safety
  • Technology
  • Engineering
  • Management & Leadership
  • Software
  • DevOps Security Engineer
  • Cyber Security Manager / Administrator
  • Database and Network Professionals Not Elsewhere Classified
  • Information Security Engineers
  • Computer Occupations, All Other

Renseignements supplémentaires

Expérience minimale
5+ ans
Langue de l’offre
anglais
Heures de travail
40 heures par semaine