--- title: 'Senior Manager, Information Security at Benevity' canonical: 'https://feeny.ai/job/senior-manager-information-security-benevity-calgary-0nd0w9xa9rpr' type: 'job' last_seen: '2026-09-11' --- # Senior Manager, Information Security at Benevity - **Company:** Benevity - **Location:** Calgary, Canada - **Employment:** full-time - **Work type:** hybrid - **Posted:** 2026-08-24 - **Last confirmed live:** 2026-09-11 - **Apply:** https://jobs.ashbyhq.com/benevity/2315b452-191d-4930-9c9a-f1842fb327ec ## Job description Meet Benevity Benevity is the way the world does good, providing companies (and their employees) with technology to take social action on the issues they care about. Through giving, volunteering, grantmaking, employee resource groups and micro-actions, we help most of the Fortune 100 brands build better cultures and use their power for good. We’re also one of the first B Corporations in Canada, meaning we’re as committed to purpose as we are to profits. We have people working all over the world, including Canada, Spain, Switzerland, the United Kingdom, the United States and more! Benevity is seeking a Senior Manager, Information Security to lead our security operations, product and application security, and corporate security teams. Accountable for the posture of our cloud-native platform, you will manage both leaders and senior individual contributors while maintaining the technical depth needed to critically review architectures, incident timelines, and risk ratings. In this role, you will partner closely with GRC and fraud operations to drive alignment across the organization. Additionally, you will define how Benevity secures its AI-powered product capabilities and shapes the adoption of AI tooling to accelerate our internal security practice. What you’ll do: - Lead and coach a multi-disciplinary security team, driving team development, hiring, and a sustainable operating cadence. - Own critical security KPIs and ensure continuous improvement on various metrics to improve Benevity’s security posture. - Drive the information security roadmap and manage security vendors, aligning execution directly with CISO strategy and direction. - Oversee end-to-end security operations and incident response, serving as the senior escalation lead during major events. - Hold external security partners (including MDR providers) accountable for high-fidelity coverage, triage quality, and rapid response. - Establish AI security standards for LLM integrations, RAG pipelines, and agentic workflows using frameworks like OWASP and MITRE ATLAS. - Operationalize AI within the security team to enhance triage, threat detection, investigation, and reporting capabilities. - Embed security into the SDLC via CI/CD automation, SAST/SCA/DAST tooling, secure API patterns, and threat modeling. - Maintain the enterprise security risk register and vulnerability management lifecycle, prioritizing remediation by real-world risk. - Direct corporate security hygiene, phishing simulations, security awareness training, and the Responsible Disclosure Program. - Partner with DevOps and GRC to implement infrastructure-as-code security, meet audit compliance obligations, and deliver clear posture metrics. What you’ll bring: - 10+ years of progressive experience in information security, including 5+ years leading teams - Experience managing managers as well as individual contributors, with a track record of developing both - Breadth across security operations, product and application security, and cloud security Hands-on experience managing security operations on AWS, and other cloud providers. - Hands-on experience leading major incident response, including acting as incident commander, coordinating cross-functional responders and managing communications under pressure - Practical understanding of AI and LLM security risks, including the OWASP Top 10 for LLMs, prompt injection and the security implications of agentic systems - A clear, evidence-based point of view on where AI adds value in security work, where it falls short, and how to get it production-ready — and the curiosity to keep revising that view as the tooling changes - Working knowledge of SAST, SCA, DAST, API and microservices security, proven ability to set direction and evaluate the quality of the work - Deep understanding of cloud security, threat detection and modern attacker tactics, techniques and procedures in containerized, API-driven environments. Hands-on WAF experience is a must. - Experience owning budget, vendor selection and managed-service relationships - Experience building or scaling a security awareness program and developer security champions program. - Familiarity with security frameworks including NIST CSF, ISO 27001, SOC 2 Type II, CIS Controls, and OWASP SAMM or BSIMM - Strong problem-solving and analytical skills, with the ability to communicate security concepts effectively to both technical and non-technical audiences - A strong sense of ownership and accountability, and the ability to lead initiatives from concept to completion without being directed at every step - Bachelor's degree in Computer Science, Information Security, or equivalent practical experience Nice to have: - Relevant certifications such as CISSP, CISM or GCIH - IC-level credentials such as OSCP, CSSLP or GWAPT - Prior experience in a SaaS product company with a multi-tenant architecture - Experience in a regulated or high-trust environment where client security scrutiny is routine Discover your purpose at work We’re not employees, we’re Benevity-ites. From all locations, backgrounds and walks of life, who deserve more … Innovative work. Growth opportunities. Caring co-workers. And a chance to do work that fills us with a sense of purpose. If the idea of working on tech that helps people do good in the world lights you up ... If you want a career where you’re valued for who you are and challenged to see who you can become … It’s time to join Benevity. We’re so excited to meet you. Where We Work At Benevity, we embrace a flexible hybrid approach to where we work that empowers our people in a way that supports great work, strong relationships, and personal well-being. For those located near one of our offices, while there’s no set requirement for in-office time, we do value the moments when coming together in person helps us build connection and collaboration. Whether it’s for onboarding, project work, or a chance to align and bond as a team, we trust our people to make thoughtful decisions about when showing up in person matters most. Join a company where DEIB isn’t a buzzword Diversity, equity, inclusion and belonging are part of Benevity’s DNA. You’ll see the impact of our massive investment in DEIB daily — from our well-supported employee resources groups to the exceptional diversity on our leadership and tech teams. We know that diverse backgrounds, experiences, skills and passions are what move our business and our people forward, so we're committed to creating a culture of belonging with equal opportunities for everyone to shine. That starts with a fair and accessible hiring process. If you want to feel seen, heard and celebrated, you belong at Benevity. Candidates with disabilities who may require accommodations throughout the hiring or assessment process are encouraged to reach out to accommodations@benevity.com. ## About Benevity ## Company Overview - **One-liner**: Benevity provides an AI-native enterprise platform for corporate social responsibility, unifying employee giving, volunteering, grants, employee resource groups, challenges, and impact reporting. - **Entity Type**: Private (late-stage with minority investment; received a $38M minority equity investment from JMI Equity in 2026) - **Headquarters**: Calgary, Canada - **Founded**: 2008 - **Founders**: Rick Essex (co-founder) ## Core Business - **Primary industry/industries**: Corporate Social Responsibility (CSR) software, Employee Engagement, Grants Management, Impact Reporting - **Target customers**: B2B, primarily large enterprises (965+ purpose-driven clients globally) - **Mission or purpose statement**: “Be a force of good” — embedding purpose into business strategy while ensuring trust, security, and measurable impact. ## Products & Services - **Enterprise Impact Platform**: Unified, AI-native SaaS platform for giving, volunteering, grants, employee groups, challenges, and reporting. - **Donate**: Employee giving module with payroll deduction, company matching, and real-time tax receipts. - **Volunteer**: Manage and track volunteer hours, including mobile-first experiences for deskless workers. - **Grants**: Full lifecycle grant management (applications, scoring, disbursement, compliance) with AI-powered grant application summaries. - **Employee Groups**: ERG management that scales globally, ties participation to business outcomes. - **Challenges**: Gamified experiences to drive behavior change and daily engagement. - **Reporting Suite**: Consolidates all impact data into a single “Trusted Impact” number (aggregate dollar value of every hour, dollar, and action). - **Match Assurance**: Fraud detection and anomaly flagging for donation matching. - **Global Money Movement**: Disbursement in 200+ countries with 99.7% payment success, automated sanctions/tax/governance compliance, and continuous nonprofit validation for 2.5M organizations. ## Market Standing - **Valuation/Market Cap**: Not disclosed (private company) - **Key Metric – Total Funding**: At least $38M minority equity investment from JMI Equity in 2026; earlier Series C round (amount undisclosed) noted in company timeline. - **Notable Investors/Partners**: JMI Equity (minority investor) - **Growth Signals**: - Named to Fast Company Most Innovative Companies 2026. - Headcount: 742 employees. - $16.6B donated to nonprofits through the platform to date; $20.1B in total grants managed. - 965+ purpose-driven clients. - 27% average increase in employee participation for clients. ## Competitive Advantages - **Unified platform**: Replaces 5+ point solutions with one integrated system, reducing vendor sprawl and improving audit readiness. - **AI-native architecture**: Built on a responsible AI governance framework (not bolted-on), offering features like grant application summaries and receipt extraction. - **Risk mitigation**: Continuous nonprofit validation (2.5M orgs), intelligent fraud detection on every transaction, and automated sanctions/tax compliance — resulting in an average $100k annual tax savings per client. - **Global scale**: Disburses funds in local currencies across 200+ countries with 99.7% payment success and full tax reconciliation. - **Nearly two decades of refinement**: Platform has been built and optimized since 2008, with deep regulatory compliance and secure payment infrastructure. ## Strategic Focus - **AI-first social impact**: Embedding responsible AI across the entire platform to save time on administrative tasks (e.g., receipt extraction, grant scoring) and allow program managers to focus on strategic impact. - **Employee mobilization**: Expanding offerings for deskless/remote employees, ERG tools, and challenges to increase participation. - **Unified impact measurement**: Pushing the “Trusted Impact” number as a universal metric to justify CSR spending to CFOs and boards. - **Continued product innovation**: Recent launches include Employee Groups (2024) and Challenges (2026). ## Why Work Here - **Culture**: Strong emphasis on diversity, equity, inclusion, and belonging (DEIB) — described as part of Benevity’s DNA with active employee networks (Pride, Black Employee Network) and diverse leadership. - **Work model**: Hybrid — hub offices for connection/collaboration but flexibility to work in a way that suits individual and team needs. - **Perks**: - 4 weeks of vacation (encouraged to take all days). - Flexible health benefits tailored to individual/family needs globally. - Parental leave: short-term paid leave, salary top-up for extended leave, and a bonding bonus for any parent. - Stock options for all employees (private company). - Donation matching and volunteer rewards (company matches donations, rewards volunteer hours with funds to donate). - Mental health and wellbeing support: Employee and Family Assistance Program, regular wellbeing sessions, mental health training for leaders. - **Leadership development**: Internal and external training, ongoing learning opportunities, an online leader hub. - **Job opportunities**: Currently hiring across multiple roles; careers page at [jobs.ashbyhq.com/benevity](https://jobs.ashbyhq.com/benevity). ## Sources 1. [benevity.com](https://benevity.com/) 2. [benevity.com/join-the-team](https://benevity.com/join-the-team) 3. [benevity.com/about-us](https://benevity.com/about-us?hsLang=en) 4. [ca.linkedin.com/company/benevity](https://ca.linkedin.com/company/benevity) 5. [boards.greenhouse.io/benevity](https://boards.greenhouse.io/benevity/jobs/5219028004) ## Other roles at Benevity - [Senior Tax Analyst - 15 Month Term](https://feeny.ai/job/senior-tax-analyst-15-month-term-benevity-toronto-8c2f35x4zqdv) — Toronto, Canada - [Senior Tax Analyst - 15 Month Term](https://feeny.ai/job/senior-tax-analyst-15-month-term-benevity-calgary-s87sy3q699y9) — Calgary, Canada - [Product Marketing Manager - Term](https://feeny.ai/job/product-marketing-manager-term-benevity-vancouver-w1y0rj8a6w46) — Vancouver, Canada - [Senior Manager, Product Marketing](https://feeny.ai/job/senior-manager-product-marketing-benevity-calgary-ydm9czbegjva) — Calgary, Canada - [ABM Manager](https://feeny.ai/job/abm-manager-benevity-toronto-m825mebr7094) — Toronto, Canada - [ABM Manager](https://feeny.ai/job/abm-manager-benevity-calgary-ppkf6hzra5w3) — Calgary, Canada - [Senior Manager, Information Security](https://feeny.ai/job/senior-manager-information-security-benevity-toronto-8kff41883f40) — Toronto, Canada - [Client End User Specialist - 12 Month Term](https://feeny.ai/job/client-end-user-specialist-12-month-term-benevity-calgary-q2f2nf3yvmew) — Calgary, Canada - [Enterprise Account Executive](https://feeny.ai/job/enterprise-account-executive-benevity-california-qvv4y5nmm9kc) — California - [Enterprise Account Executive](https://feeny.ai/job/enterprise-account-executive-benevity-united-kingdom-nemq9j1hhtp1) — United Kingdom