Manager, IT Risk
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
By continuing, you agree to our Terms & Privacy Policy.
Reports To: Director, IT
Role Type: Full-time
Workplace Type: Hybrid or Remote
About Us
REALTOR.ca is a cornerstone of Canada’s real estate market, dedicated to helping millions of Canadians find attainable housing across the country. As the leading real estate platform in Canada, we offer the most comprehensive listings and resources to assist consumers in finding their dream homes.
At REALTOR.ca, we are committed to supporting REALTOR® members’ businesses and fostering consumer trust and loyalty. Our dedication to delivering value and continuously adapting to market demands ensures that REALTOR.ca is more than just a listing service- it is the heart of the Canadian real estate experience.
Join us and be a part of a team that is at the forefront of the real estate industry, making a significant impact on the lives of Canadians every day.
Position Overview
The Manager, IT Risk & Security Operations leads REALTOR.ca Canada Inc.'s enterprise cybersecurity operations, including security operations, infrastructure and network security, cloud and identity security, application security, vulnerability management, cyber resilience, governance, risk management, third‑party risk, and compliance.
The role translates cybersecurity strategy and policy into operational practice, leads the security operations function and incident response, and drives day‑to‑day risk reduction across the organization’s technology environment. The Manager leads and develops the security team and serves as the operational escalation point for cybersecurity incidents and risks.
Core Competencies
- Team Leadership & Coaching
- Security Operations Execution
- Incident Response & Triage
- Technical Proficiency Across Security Tooling
- Prioritization & Operational Judgment
- Communication & Cross-Team Coordination
- Process Improvement & Documentation
Function
Working closely with Infrastructure, Service Desk, Software Engineering, and Product teams, the Manager, IT Risk & Security Operations ensures security requirements and controls are effectively implemented throughout the technology lifecycle and supports the secure delivery and operation of enterprise platforms, digital services, and applications.
Key Responsibilities
Team Leadership & Operations Management
- Directly manage, coach, and develop the security team, including goal‑setting, performance reviews, skills development, and a culture of accountability, collaboration, and continuous improvement.
- Own day‑to‑day scheduling, workload balancing, coverage, and priorities for the security operations function, translating broader security strategy into actionable team objectives.
- Provide regular reporting on team performance, operational metrics, emerging risks, and areas requiring leadership attention.
- Partner with Software Engineering, Product, Infrastructure, and Service Desk leadership to embed security requirements, secure design principles, risk‑based decision‑making, and governance throughout the technology lifecycle.
Security Operations & Incident Response
- Lead daily security monitoring, alert triage, threat detection, and investigation across SIEM, SOAR, EDR/XDR, email security, and related platforms.
- Act as the primary operational escalation point for security incidents and coordinate containment, recovery, communications, and post‑incident follow‑up.
- Maintain and continuously improve incident response playbooks, runbooks, standard operating procedures, and escalation processes.
- Coordinate tabletop exercises and support disaster recovery and ransomware‑preparedness testing.
- Drive detection engineering and SOC automation to improve coverage, consistency, and response efficiency.
Security Technology & Automation
- Lead the evaluation, implementation, lifecycle management, renewals, upgrades, and day‑to‑day vendor relationships for security operations technologies, including SIEM, SOAR, EDR/XDR, vulnerability management, and email/endpoint security platforms.
- Drive adoption of security automation to reduce manual effort in monitoring, triage, investigation, and remediation workflows.
- Support larger strategic security initiatives and technology decisions requiring enterprise budget or executive approval.
Vulnerability Management & Security Testing
- Run the day‑to‑day vulnerability management program, including scanning cadence, triage, risk‑based prioritization, remediation tracking, dashboards, and reporting across infrastructure, endpoints, cloud, applications, and network devices.
- Coordinate remediation timelines and priorities with Infrastructure, Software Engineering, Service Desk, and other st