TTEC Digital is hiring a Security Operations Manager to join our AWS practice. This is a remote opportunity based in Canada.
Reporting to the Executive Director of Information Security the Security Operations Manager is a critical role responsible for overseeing the security posture of technology services delivered to the Canadian government. This includes partnering with internal security and technology teams as well as oversight of a Managed Security Services Provider (MSSP) responsible for 24/7 security monitoring, incident response, and vulnerability detection and reporting. The ideal candidate possesses a strong understanding of Canadian government security regulations, experience managing security operations in complex environments, and a proven ability to collaborate effectively with internal teams as well as Canadian Government Agencies.
What you'll be doing:
MSSP Oversight
Manage the relationship with the MSSP, ensuring service level agreements (SLAs) are met and performance is consistently evaluated.
Review and approve MSSP deliverables, including security assessments, incident reports, and vulnerability scans.
Conduct regular service review meetings with the MSSP to discuss performance, address issues, and identify areas for improvement.
Monitor MSSP performance metrics, including mean time to detect (MTTD), mean time to respond (MTTR), and false positive rates.
Security Operations Management:
Develop and maintain security operations procedures and documentation.
Oversee security incident response activities, ensuring timely and effective containment, eradication, and recovery.
Contribute to the development and implementation of security policies, standards, and guidelines.
Compliance and Reporting:
Ensure compliance with relevant Canadian government security regulations and standards (e.g., Policy on Government Security, Canadian Centre for Cyber Security, CCCS medium, ITSG-33, etc.).
Prepare regular security reports for management, including metrics on security incidents, vulnerabilities, and compliance status.
Support internal and external audits related to security controls.
Collaboration and Communication:
Collaborate effectively with internal IT teams, project managers, business stakeholders and customers.
Communicate security issues and recommendations clearly and concisely to both technical and non-technical audiences.
Maintain strong relationships with government security contacts.
What skills/experience you will bring
Bachelor's degree in Computer Science, Information Security, or a related field.
Minimum of 5 years of experience in security operations, with at least 2 years in a management or supervisory role.
Experience working in a cloud environment (e.g., AWS, Azure, GCP).
Experience working with Canadian government security regulations and standards is required.
Experience managing MSSPs or other third-party security vendors.
Strong understanding of security technologies, including SIEM, intrusion detection/prevention systems (IDS/IPS), firewalls, vulnerability scanners, and endpoint security solutions.
Experience with incident response methodologies and frameworks (e.g., NIST, SANS).
Relevant security certifications such as CISSP, CISM, CompTIA Security+, or equivalent are highly desirable.
Excellent communication, interpersonal, and presentation skills.
Strong analytical and problem-solving skills.
Ability to obtain a Canadian government security clearance (Reliability Status or higher).
Nice to have:
Experience with automation and orchestration tools for security operations.