IFS is a billion-dollar revenue company with 7000+ employees on all continents. Our leading AI technology is the backbone of our award-winning enterprise software solutions, enabling our customers to be their best when it really matters–at the Moment of Service™. Our commitment to internal AI adoption has allowed us to stay at the forefront of technological advancements, ensuring our colleagues can unlock their creativity and productivity, and our solutions are always cutting-edge.
At IFS, we’re flexible, we’re innovative, and we’re focused not only on how we can engage with our customers but on how we can make a real change and have a worldwide impact. We help solve some of society’s greatest challenges, fostering a better future through our agility, collaboration, and trust.
We celebrate diversity and understand our responsibility to reflect the diverse world we work in. We are committed to promoting an inclusive workforce that fully represents the many different cultures, backgrounds, and viewpoints of our customers, our partners, and our communities. As a truly international company serving people from around the globe, we realize that our success is tantamount to the respect we have for those different points of view.
By joining our team, you will have the opportunity to be part of a global, diverse environment; you will be joining a winning team with a commitment to sustainability; and a company where we get things done so that you can make a positive impact on the world.
We’re looking for innovative and original thinkers to work in an environment where you can #MakeYourMoment so that we can help others make theirs. With the power of our AI-driven solutions, we empower our team to change the status quo and make a real difference.
If you want to change the status quo, we’ll help you make your moment. Join Team Purple. Join IFS.
Job DescriptionPosition Summary
The Security Operations Lead (Lead SOC Analyst) at Copperleaf plays a critical role in protecting our global SaaS platform, internal systems, and customer environments. This role combines deep technical expertise in security operations, detection and response, and enterprise vulnerability management.
This individual functions as a technical team lead and senior escalation point, providing direction, mentorship, and operational leadership to a team of SOC analysts while working cross-functionally across Security Architecture, R&D, CloudOps, and IT. While this is not a direct people management role, it requires strong leadership, influence, and accountability for driving operational excellence and team maturity.
The role is responsible for developing, enhancing, and executing security operations and vulnerability management capabilities, including building new processes, implementing tools, and contributing to the broader security roadmap.
Key Responsibilities
Leadership & Team Support
- Act as the technical lead and primary escalation point for Security Operations and Vulnerability Management.
- Provide mentorship and guidance to intermediate analysts, supporting capability development and operational consistency.
- Drive team maturity, process standardization, and operational excellence across detection, response, and remediation functions.
- Lead by influence across teams, ensuring alignment without direct reporting authority.
- Contribute to performance metrics, KPIs, and reporting for leadership visibility.
Security Monitoring & Incident Response
- Lead complex investigations across AWS & Azure environments, identity systems, endpoints, and SaaS infrastructure.
- Oversee incident response activities including containment, remediation, and post-incident analysis.
- Enhance SOC playbooks, SOPs, and detection logic to improve response efficiency and effectiveness.
- Drive ongoing improvements in logging, monitoring coverage, and alert fidelity.
Vulnerability Management
- Lead the end-to-end vulnerability management lifecycle including identification, prioritization, tracking, remediation, and validation across:
- Cloud environments (AWS, Azure)
- Applications and SaaS platforms
- Infrastructure, endpoints, and third-party systems
- Partner with IT, CloudOps, R&D, and Security Architecture to reduce attack surface and ensure timely remediation.
- Prioritize vulnerabilities based on business risk, exploitability, and threat intelligence (e.g., KEV, CVSS, EPSS).
- Establish and maintain repeatable, scalable vulnerability management processes and tooling.
- Develop metrics and reporting on vulnerability posture, remediation SLAs, and risk exposure.
Threat Intelligence, Detection Engineering & Automation
- Develop and tune detection logic mapped to MITRE ATT&CK across cloud and SaaS environments.
- Design and implement automation workflows, playbooks, and operational tooling improvements.
- Evaluate and optimize use of SIEM, EDR/XDR, and cloud-native security tools.
- Drive continuous improvement through tool rationalization, automation, and innovation initiatives.
- Track emerging threats relevant to SaaS providers, cloud platforms, Kubernetes, identity infrastructure, and AI‑driven attack techniques.
- Conduct proactive threat hunting across cloud workloads, identity logs, endpoints, and product telemetry.
Cross‑Functional Collaboration
- Collaborate closely with Security Architecture, R&D, CloudOps, IT, and Platform teams.
- Support secure design, operational visibility, incident readiness, and remediation coordination.
- Communicate risks, trends, and recommendations to both technical and business stakeholders.
Qualifications
Skills & Experience Requirements
- 8+ years of experience in security operations, incident response, vulnerability management, or related cybersecurity roles.
- Demonstrated experience functioning as a technical lead or team lead within a SOC or security operations environment.
- Strong experience with:
- Cloud platforms (AWS and Azure)
- Vulnerability management tools and methodologies
- SIEM (Rapid7 preferred), SOAR, EDR/XDR
- Deep understanding of:
- Threat landscape (cloud, SaaS, identity)
- Vulnerability frameworks (CVSS, MITRE ATT&CK, KEV, OWASP)
- Experience building or improving security processes, tooling, and operational capabilities.
- Strong cross-functional collaboration and stakeholder management skills.
- Proficiency in scripting languages (Python, Bash, PowerShell, JavaScript) and KQL for advanced log analysis.
- Familiarity with frameworks and regulations relevant to Copperleaf (ISO 27001, SOC 2, NIST CSF, CIS Controls, GDPR).
- Expertise with Windows, macOS, and Linux systems.
Education Requirements
Bachelor's degree preferred in cybersecurity, computer science, engineering, or related fields.
Certification Requirements
Preferred certifications include:
- GIAC Certified Incident Handler (GCIH)
- GIAC Defending Advanced Threats (GDAT)
- GIAC Certified Enterprise Defender (GCED)
- Microsoft Certified SOC Analyst
- CISSP
- Azure Security Engineer (AZ‑500) — strongly preferred for cloud‑focused operations
What We’re Offering
- Salary Range: $95,000 CAD -$125,000 CAD+ Bonus
- Permanent, Full-time
- Flexible paid time off, including sick and holiday
- Medical, dental, & vision insurance
- RRSP Company contribution
- Life insurance and disability benefits
- Tuition assistance
- Community involvement and volunteering events
We embrace flexibility and hybrid work opportunities to support diverse needs and lifestyles, while also valuing inclusive workplace experiences. By fostering a sense of community, we drive innovation, strengthen connections, and nurture belonging. Our commitment ensures you can work in a way that suits you best, while also engaging with colleagues to share ideas and build meaningful relationships.
Skills Required
- 8+ years of experience in security operations, incident response, vulnerability management, or related cybersecurity roles
- Technical lead experience in a SOC or security operations environment
- Strong experience with cloud platforms (AWS and Azure)
- Experience with vulnerability management tools and methodologies
- Experience with SIEM tools, preferably Rapid7
- Experience with scripting languages (Python, Bash, PowerShell, JavaScript)
- Familiarity with cybersecurity frameworks (ISO 27001, SOC 2, etc.)
IFS Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about IFS and has not been reviewed or approved by IFS.
-
Retirement Support — Retirement support is presented as part of the package in North America through a 401(k) plan and references to pension/defined contribution arrangements in some contexts.
-
Healthcare Strength — Healthcare coverage is described as available in some regions, including health, dental, life, and disability insurance offerings.
-
Strong & Reliable Incentives — Variable pay elements such as monthly bonuses and profit sharing are described as meaningful in certain roles, with bonuses tied to performance outcomes like reduced downtime.
IFS Insights
What We Do
IFS develops and delivers enterprise software for companies around the world who manufacture and distribute goods, build and maintain assets, and manage service-focused operations. Within our single platform, our industry specific products are innately connected to a single data model and use embedded digital innovation so that our customers can be their best when it really matters to their customers – at the Moment of Service. The industry expertise of our people and of our growing ecosystem, together with a commitment to deliver value at every single step, has made IFS a recognized leader and the most recommended supplier in our sector. Our team of 5,000 employees every day live our values of agility, trustworthiness and collaboration in how we support our 10,000+ customers. Learn more about how our enterprise software solutions can help your business today at ifs.com. Follow us on Twitter: @ifs Facebook: www.facebook.com/ifsdotcom Instagram: www.instagram.com/ifsdotcom Visit the IFS Blog on technology, innovation and creativity: https://blog.ifs.com/







.png)

