Lead, IT, DevOps & Security

Intouch Insight, Inc.

$110K — $140K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience managing SOC 2 Type 2 programs, emphasizing addition of Confidentiality and Availability criteria.
  • Proven leadership capabilities in managing IT, DevOps, or security teams with a focus on development and direction.
  • Strong background in IT/security engineering, with expertise in policy, vulnerability management, and incident response.
  • Proficiency in Terraform or similar Infrastructure as Code (IaC) tools for cloud identity and security management.
  • Excellent communication skills for articulating technical and security strategies to both technical teams and executive leadership.

Responsibilities

  • Own and expand the SOC 2 Type 2 program, integrating additional Trust Services Criteria.
  • Design and implement new security controls and ensure audit readiness with continuous evidence collection.
  • Lead security engineering initiatives, embedding automation in incident detection and vulnerability management.
  • Manage and develop the IT and DevOps teams while engaging directly in technical work.
  • Oversee both product-level and corporate DevOps functions, including CI/CD and infrastructure management.
  • Implement Terraform for managing cloud identity and security infrastructure in a scalable manner.
  • Automate user lifecycle management across Microsoft Entra ID and Google Workspace.

Benefits

  • Hybrid work environment, primarily remote with occasional office days in Kanata for local employees.
  • Opportunities for professional development and career progression within a growing team.
  • Hands-on involvement in shaping the company’s security and compliance framework.
Full Job Description
Intouch Insight is scaling its security and compliance program, and we are hiring a technical leader to own it. As Lead, IT, DevOps & Security, you will lead the execution and expansion of our SOC 2 program - extending it beyond Security to add the Confidentiality and Availability Trust Services Criteria - while owning all of IT infrastructure, DevOps, and security across the company. You treat IT and compliance as engineering problems - "compliance as code," "IT stack as code" - building automated, auditable systems rather than managing from a distance.

This is a hands-on, player-coach role. You will personally do much of the implementation - building the automated controls, infrastructure, and security tooling yourself - while also leading a small team (IT and DevOps), setting the roadmap, and acting as the company's owner of security and compliance as we grow toward our next revenue milestone and serve a larger enterprise customer base. Roughly the majority of your time is spent building; the rest is leading, planning, and owning outcomes.

What You'll Do

Own and expand the SOC 2 program (primary focus). Own our SOC 2 Type 2 program - already running in Vanta - and lead its expansion beyond the Security baseline to add the Confidentiality and Availability Trust Services Criteria. Design and operationalize the new controls (e.g. data classification and handling, encryption and access controls for confidential data; capacity, backup, disaster-recovery, and uptime monitoring for availability), map them into Vanta, and keep evidence collection continuous and audit-ready. Own the auditor relationship and drive toward zero critical findings.

Lead security engineering. Set IT and information-security policy, run vulnerability management and remediation, and lead incident detection, alerting, and response - all through an automation-first lens. Champion security best practices across the organization.

Lead the team (as a player-coach). Manage and develop the IT and DevOps staff, set expectations and growth paths, and be the decision-maker and escalation point the team relies on - while staying deep in the work yourself rather than managing from a distance.

Own DevOps across product and corporate. Oversee product/platform DevOps (CI/CD, application infrastructure, deployment pipelines supporting the engineering team) as well as corporate infrastructure and identity.

Run IT as code. Use Terraform to manage and provision cloud identity and security infrastructure for a reproducible, scalable environment. Administer and secure a mixed Windows/macOS fleet with Microsoft Intune and Jamf; automate device enrollment, patching, and configuration.

Own identity & access. Secure and automate the user lifecycle across Microsoft Entra ID and Google Workspace.

Set strategy. Develop and own the IT, DevOps, and security roadmap aligned to business goals; manage the operational budget and vendor relationships.

What You'll Need

  • SOC 2 leadership. Demonstrable experience leading or substantially driving SOC 2 Type 2 programs - ideally including adding Trust Services Criteria (Confidentiality, Availability) to an existing scope. Hands-on experience with a compliance automation platform (Vanta or similar) is a strong asset.
  • People leadership. Experience managing a team (IT, DevOps, and/or security), setting direction, and developing people - or a strong senior/lead ready to step up, with the judgment to be an accountable decision-maker.
  • Security depth. Hands-on background in IT/security engineering: policy, vulnerability management, incident response, and modern detection/alerting.
  • The DevOps mindset. Proven use of Terraform (or equivalent IaC) to manage cloud IAM, especially Microsoft Entra ID; comfort across product and corporate DevOps.
  • Communication. Able to articulate security and technology strategy to both technical teams and executive leadership.


Nice to Have
  • Modern endpoint expertise. Securing Windows (Intune) and macOS (Jamf) fleets.
  • Platform breadth. Hands-on administration of Microsoft Entra ID and Google Workspace in a corporate setting.


Success Measures
  • A successfully expanded SOC 2 program: Confidentiality and Availability criteria added to the audit scope and brought under continuous, automated compliance with zero critical findings.
  • Security posture: reduced risk through automated detection, timely remediation, and enforced policy.
  • Team capability: a well-run, growing IT/DevOps function with clear ownership and development.
  • Reliability & efficiency: high uptime of critical infrastructure and reduced manual overhead through automation


Compensation: $110,000 - $140,000

Hybrid to us means that you primarily work from home, with no more than 1 day per week in the Kanata office, if you live within range.

Similar Jobs

More Information Technology Jobs

Find similar Lead, IT, DevOps & Security jobs: