Head of Cyber Defence & Incident Response
Quadient
At Quadient , we support businesses of all sizes in their digital transformation and growth journey, unlocking operational efficiency with reliable, secure, and sustainable automation processes.
Our success in delivering innovation and business growth is inspired by the connections our diverse teams create every day, with our clients and each other.
It’s these connections that make Quadient such an exceptional place to grow your career, develop your skills and make a real impact – help our future-focused business lead the way in powering secure and sustainable business connections through digital and physical channels.
Job Description
- Location: Qaudient offices, Markham Ontario, Canada or Eastern USA (EST Time zone)
- The Head of Cyber Defence and Incident Response owns the organisation’s cyber defence capability across a hybrid environment (mix of on‑prem and cloud platforms), ensuring effective monitoring, detection, response and recovery.
- Reports directly to the CISO and leads cyber defence operations (including the MSSP) and cybersecurity incident response across the organisation. This fits within the context of the broader organizational Crisis Management plan owned outside Technology.
- A key focus is optimising security tooling (e.g., SIEM, SOAR, EDR/XDR, NDR, email security, vulnerability scanning) and driving strong vulnerability and threat management, using threat intelligence to prioritise defensive improvements.
Key Responsibilities
- Own the incident response lifecycle (prepare, detect, analyse, contain, eradicate, recover), ensuring playbooks, tooling, and decision-making processes are in place and exercised.
- Lead and coordinate response to security incidents, acting as incident commander where required, including stakeholder communications, forensic triage, and recovery coordination.
- Manage the MSSP relationship end‑to‑end: service definition, SLAs/KPIs, escalation paths, continuous improvement plans, quality assurance, and commercial governance.
- Optimise security monitoring and response tooling working across technology teams (e.g., SIEM, SOAR, EDR/XDR, NDR, email security) including use‑case coverage, alert quality, automation, logging strategy, and operational runbooks.
- Own the vulnerability management programme (on‑prem and cloud), including scanning coverage, prioritisation, remediation SLAs, exception handling, verification, and executive reporting.
- Drive threat management by operationalising threat intelligence (internal and external) into defensive priorities: detection use cases, hardening actions, control uplift and proactive hunting themes.
- Lead continuous improvement of the defence stack: rationalise tools, tune detections, improve signal quality, reduce noise, and expand automation to accelerate triage and response.
- Establish and run a threat hunting programme using hypothesis‑driven approaches, telemetry coverage mapping, and lessons learned from incidents and red-team activity.
- Run regular tabletop exercises and simulations (including ransomware and cloud compromise scenarios), ensuring roles, escalation paths, and technical procedures are validated and improved.Own incident response governance: severity model, on‑call and escalation processes, evidence handling, case management, and alignment to legal/regulatory obligations.
- Define and report cyber defence metrics (e.g., MTTD/MTTR, alert volumes and precision, incident trends, vuln remediation performance, control coverage), presenting insights and recommendations to senior leadership.
- Lead post-incident reviews and root cause analysis, ensuring lessons learned translate into measurable improvements (detections, hardening, identity controls, backups, segmentation, and training).
- Support business continuity and crisis management processes during cyber events, contributing to executive updates and coordinated communications with Legal/Privacy and other stakeholders.
- Maintain and improve incident response documentation and readiness (playbooks, runbooks, contact trees), and ensure training is delivered for technical responders and business stakehol
- Communicate cyber risk and active incidents clearly to technical and non‑technical audiences, including concise executive briefings and after‑action summaries.
Qualifications
- Strong experience leading cyber defence/SOC and incident response, including major incident coordination, investigation, containment and recovery.
- Hands-on understanding of detection and response tooling and concepts (SIEM, SOAR, EDR/XDR, NDR, email security, log pipelines), including tuning, use-case engineering and operational workflows.
- Proven experience managing an MSSP or outsourced SOC capability, including SLAs/KPIs, service governance, escalations, and continuous improvement.
- Strong experience running vulnerability management and threat management programmes, including prioritisation based on exploitability, exposure, and business impact.
- Knowledge of incident response processes, digital forensics fundamentals, evidence handling, and working with legal/privacy and external forensic partners.
- Experience defending hybrid environments (on‑prem and cloud), including identity signals, network telemetry, endpoint visibility, and cloud-native security monitoring.
- Ability to operate under pressure and lead cross-functional teams through high-severity incidents, communicating clearly and making timely risk-based decisions.
- Fluent in English – excellent written and verbal communication skills, including producing clear architecture guidance, standards, and security design documentation.
Desirable
- Certifications such as GCIH, GCIA, GNFA, CISSP, CISM, or equivalent experience in incident response and security operations.
- Experience with threat hunting, purple teaming, and using MITRE ATT&CK to structure detections, gaps analysis, and defensive improvements.
- Experience with security operations in cloud platforms and common tools (e.g., Microsoft Defender, Sentinel, Splunk, CrowdStrike, Palo Alto, AWS/Azure security services) and integrating telemetry across environments.
- Calm under pressure , able to lead effectively during incidents and make timely decisions with incomplete information.
- Highly collaborative, able to coordinate across IT, engineering, legal/privacy, and business leaders during investigations and recovery.
- Operationally rigorous with strong attention to detail, documentation and evidence quality (case notes, timelines, lessons learned).
- Continuous improvement mindset—drives measurable outcomes through tooling optimisation, process refinement, and coaching teams to improve security hygiene.
Additional Information
See Full
Job description
Rewards & Benefits
- Flexible Work: Embrace a hybrid work model blending office and remote setup for a balanced lifestyle.
- Endless Learning: Access global opportunities for growth through our 24/7 online learning platform.
- Inclusive Community: Join our Empowered Communities and engage in our Philanthropy program.
- Comprehensive Rewards: Enjoy competitive Total Rewards covering wellness, work/life balance, and more, including a generous referral scheme.
- Caring for Wellbeing: Access our complimentary employee assistance program for mental health support.
Smart Work at Quadient
At Quadient, our Smart Work approach fosters connection, collaboration, and innovation while offering flexibility based on role requirements. Whether on-site, hybrid, or remote, our work environments are designed to support productivity and engagement. Hybrid employees balance remote and in-office work, on-site roles contribute daily to our vibrant workplace culture, and remote employees stay connected through virtual collaboration and in-person events. No matter where you work, you’ll be part of a dynamic, people-first community that drives success together.
Be yourself at Quadient
Our values define how we work as a team: Empowerment, Passion, Inspiration and Community. They inspire us to be EPIC. Together. What makes Quadient different is how different we are. We’re a team of individuals with one goal but many perspectives. When you connect with Quadient, you become part of a community that cares - in a culture that embraces differences and values every voice.
We will consider any reasonable modifications to the interview process. If you require any assistance with the application process, please email us at View email address on jobs.smartrecruiters.com
Quadient is an Equal Employment Opportunity Employer. *: We firmly believe in zero discrimination in employment on any basis, including race, color, religion, sex, national origin, age, disability, veteran or military status, genetic information, citizenship status, and any other characteristics protected by local, state, or federal law.
People. Connected.
$82k - $95k per year
...with purpose and passion. **Are you ready to add your unique flavor to our journey?** **Job Description** Barilla is looking for an **OT Cyber Security Sr. Analyst** to join our **OT Cyber Security** team. The role is based in either Northbrook, IL, Ames, IA, or Avon, NY, with...SuggestedFull timeLocal areaRemote workWorldwide- About us Common Room is the customer intelligence platform that captures every buying signal, giving companies superpowers with AI enrichment and automation to reach the right person with the right context at the right time. Despite an explosion of buyer signals, companies...SuggestedRemote jobLong term contractLocal areaWork from homeHome office
- ...Infrastructure as Code (IaC) Strengthen observability, monitoring, and incident response practices Occasionally jump in to resolve critical... ...Empathetic toward creators and end users Calm and clear-headed during high-traffic events or critical incidents Benefits...SuggestedLong term contractFull timeRemote workWorldwideFlexible hours
$130k - $145k per year
...safeguarding systems, data, and people. In this role, your primary responsibility will be to strengthen our security posture across the... ...play a key role in security monitoring, access management, incident response, and audit readiness, while partnering with internal teams to...SuggestedRemote job$185k - $225k per year
...systems that manage real capital in live crypto markets. Responsibilities Design, implement, and operate scalable distributed systems... ..., and operational correctness. Participate in incident response, debugging production issues and driving root-cause fixes....SuggestedFull timeContract workWork at officeRemote workWork from home$160k - $180k per year
...products and ensure they meet user needs effectively. Your Responsibilities Develop customer-focused applications by building new features... ...sharing thoughts and input; we value open communication over a heads-down environment. Experience working with Agile...Remote jobImmediate start- ...from it. At Invert, adopting AI isn’t optional — it’s a shared responsibility and a growth opportunity. We look for people who are curious, adaptable... ...they have already participated in previous interviews). # Head of Engineering Chat: 30-minute meet-and-greet with our Head of...Remote job
- ...working on high-visibility enterprise security and compliance programs (SOC 2, FedRAMP, encryption key management) Infrastructure incident management and analysis experience Experience working with external enterprise partners on technical programs (e.g., Apple, AWS, Google...Full timeRemote workWork from home
- ...the codebase easier to work in over time Identify and address reliability, performance, or scalability issues before they become incidents Contribute to reducing tech debt in a way that's practical, not theoretical Develop engineers around you Act as a technical...Full timeSelf employmentRemote workFlexible hours
$140k per year
...conversations, articulating the strategic impact of Array’s platform. Collaborate with senior client stakeholders (e.g., CIOs, CTOs, Heads of Product) to translate their goals into compelling solution architectures. Conduct technical discovery to map customer...Remote jobFull timeSummer workWork at officeImmediate start$200k - $276k per year
...individual contribution with strategic thinking and mentorship responsibilities. You'll be responsible for architecting and implementing... ...for critical data systems including monitoring, alerting, and incident response Implement comprehensive data quality frameworks and...Remote jobLong term contractWorldwideHome office- ...SUMMARY Overall responsibility for the management and operation of the Utility systems for manufacturer in the north Richmond, Virginia area including boilers, steam turbines, filtered water & wastewater treatment plants, and landfill. The objective of the role is to provide...Full timeContract workFor contractors
- ...provide engineering input, support field evaluations and ensure technical information is shared clearly across the business. Key responsibilities Provide technical support for mining customers and regional Sales teams. Support product performance reviews, field...Immediate startVisa sponsorshipWork visaFlexible hours
$140k per year
...product knowledge and the ability to support custom requirements. Position Description The Regional Sales Manager will be responsible for developing new business across the Northeast United States, with a focus on high-volume food processors and manufacturers...Permanent employmentFull timeContract workTemporary workRemote workRelocationRelocation package- ...technical reliability expertise, and a collaborative mindset to lead a diverse team and manage complex vendor relationships. RESPONSIBILITIES Lead and coach a multidisciplinary team , fostering collaboration and servant leadership. Drive strategic alignment across departments...Long term contractFull time
$67.1k - $109k per year
...performance outcomes. Partners with HR Technology, Talent, HR Operations, and vendors to deliver scalable, user-friendly solutions. Key Responsibilities Configure and maintain Workday (Learning, Recruiting, Talent & Performance). Manage business processes, notifications, and...Full time$70k - $80k per year
...quarterly basis for amazing off-sites where we can connect IRL. Responsibilities Write emails people actually open and read and hopefully... ...social copy across formats: captions, threads, tweets, random responses to comments, all in our brand tone. Refresh site copy to...Full timeInternshipImmediate startRemote work- ...expertise with the public, and driving adoption. The Platform pillar builds the internal machinery that powers these surfaces, and is responsible for making our websites fast, stable, and easy to update. Together we design and build stripe.com and other sites that amount to...
- ...a selling tool to drive specifications, sales, and brand awareness. ***** Saturdays are required for this role***** Primary Responsibilities: Provides interior design advice and product expertise, facilitates tile and stone selection, and project development/support,...Weekend workAfternoon shift
- ...live load pattern for each structural member that that causes the worst load effect on each member; ~ Identify the maximum structural response for different live load cases. ~ Perform load rating for different types of bridges under the guidance of AASHTO LRFD, AASHTO MBE,...Long term contractFull timeFor contractors
- ...service is the difference between solving a problem and making a customer feel personally attended to throughout the process. Key Responsibilities Be the primary point of contact for 2Modern customers across the full post-purchase experience: order status, delivery...Hourly payFull timeImmediate startRemote workMonday to fridayShift work
$55k - $70k per year
...creator who can own the full content pipeline and produce at the volume and quality modern social demands. What You’ll Own Key Responsibilities Create engaging short-form and long-form content for TikTok, Instagram Reels, YouTube Shorts, Facebook, and X/Twitter....Full timeRemote workWeekend workAfternoon shift- ...they shape user experiences, then translate them into high-quality designs that can be tested, shipped, and refined. Designers are responsible for building elegant, functional products that users love—and want to tell others about. The Dashboard team ensures Stripe works...
- ..., hands-on role where you’ll own content scheduling, community engagement, and continuous improvement of our social presence. Responsibilities Social Content Creation: Develop and curate content for Instagram, LinkedIn, TikTok, and Facebook. Write, edit, and adapt briefs...Full timeRemote workFlexible hours
- ...challenges, with a focus on making complex workflows feel fast, intuitive, and dependable. Extensibility The Extensibility team is responsible for our plugin, widget, and REST APIs that enable developers to build their own Figma integrations. Extensibility engineers also...Full timeRemote workWork from homeFlexible hours
- ...creative direction for areas like acquisition, global expansion, experimentation, and our annual customer event, Sessions. You'll be responsible for defining team strategy, planning roadmaps with partners, and evolving priorities over time. You'll coach and grow the...Long term contractInternship
$20.45 - $25.51 per hour
...an exceptional Customer Service/Warehouse Associate to join our TEAM! The Customer Service/Warehouse Associate will need someone responsible for providing a variety of support such as servicing walk-in customers, completing sales transactions in conjunction with material...Long term contractTemporary workWork at office- ...with corporate finance and restructuring colleagues across all Client industry platforms, on a variety of projects and accounts. Responsibilities & Deliverables: Participate in buy-side, sell-side, restructuring, and capital raising transaction advisory engagements...Full timeWorldwide
$21.5 per hour
...About the Role Our Contact Center Associates provide an exceptional customer experience through phone and email communication. Responsibilities include providing order information, product troubleshooting, issue resolution, and general customer support. Our team members...Long term contractFull timeTemporary workWork from homeFlexible hours- ...designer on the team to bring design quality and consistency to surfaces that are critical to how Stripe operates internally. Responsibilities Own end-to-end design for a portfolio of internal tools—from discovery and problem framing through interaction design, prototyping...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Head of Cyber Defence & Incident Response. Be the first to apply!

