Director, P&T Operations - Incident Management & Risk
Job Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
In this role, you'll build and lead the operating mechanisms that help Product & Technology respond effectively to incidents, reduce enterprise risk, and give leaders clear visibility into where attention and action are needed. You'll bring together fragmented processes and practices, establish common standards, improve communications and follow-through, and ensure the right data reaches engineering teams, executives, and security leaders.
You'll work at the intersection of Product & Technology Operations, Engineering, Security, and executive leadership. The scope spans operational and security incidents, vulnerability management, and the mechanisms used to identify, assess, track, and reduce technology risk. You'll also help connect broader enterprise risk areas—including responsible AI, application and infrastructure security, identity and access, data protection, digital supply-chain risk, shadow IT/AI, security compliance, and operational resilience—into a coherent leadership view without becoming the functional owner for each domain.
This is not a traditional PMO role. We're looking for someone who can design and improve how the organization operates, bring structure to complex cross-functional problems, drive action and accountability, and enable the CTO and Security leadership team to operate effectively at executive and board-committee level.
What you'll be doing
Unify and evolve incident management
Establish a consistent P&T-wide incident management framework, including clear standards, roles, severity definitions, escalation paths, communications, and expectations for follow-through.
Bring together existing incident practices across teams, preserving what works while creating greater consistency, clarity, and organizational visibility.
Strengthen post-incident practices so actions are owned, tracked to completion, and translated into systemic improvements rather than isolated fixes.
Partner with Engineering and Security leaders to continuously improve incident readiness, response effectiveness, and operational resilience.
Strengthen security incident and vulnerability operations
Partner with Security and Engineering to strengthen the operating mechanisms for security incidents and vulnerability management, including intake, prioritization, ownership, remediation tracking, escalation, and reporting.
Create clear visibility into material vulnerabilities, remediation progress, aging, exceptions, and areas requiring leadership intervention.
Ensure security incidents and vulnerabilities connect into broader P&T incident, risk, and executive reporting mechanisms while maintaining clear functional ownership within Security and Engineering.
Help identify recurring breakdowns in process, ownership, or controls and drive cross-functional improvements.
Create an integrated view of technology risk
Build the mechanisms that give P&T and Security leadership a clear, actionable view of material technology and operational risks, trends, mitigations, and decisions required.
Partner with domain owners across responsible AI and AI governance, application and infrastructure security, digital supply-chain risk, identity and access management, Zero Trust, data protection, shadow IT/AI, security compliance, and operational resilience.
Translate complex risk information into clear priorities, tradeoffs, and actions without duplicating the accountability of the teams that own each risk domain.
Identify patterns across incidents, vulnerabilities, and risk signals and use them to inform priorities and systemic improvement.
Improve reporting, communications, and executive readiness
Define the metrics and reporting needed to understand incident health, vulnerability exposure, remediation progress, risk trends, and operational resilience.
Develop clear executive-level views that surface what matters, where risk is changing, what actions are underway, and where decisions or intervention are required.
Improve incident and risk communications across technical teams, business stakeholders, executives, and other partners so information is timely, accurate, and appropriate for the audience.
Enable the CTO and Security leadership team with the operating cadence, insights, and materials needed for executive and board-committee discussions.
Drive cross-functional action and continuous improvement
Lead complex work across Engineering, Security, Product, Legal, Compliance, and other partners through influence rather than formal authority.
Create clear ownership and accountability for cross-functional actions, ensuring critical issues do not stall between teams.
Establish operating cadences that keep material incidents, vulnerabilities, and risks moving toward resolution without creating unnecessary process.
Continuously assess where processes, tooling, data, or organizational interfaces need to improve and drive those changes through implementation.
Lead the function
Set the vision and operating model for incident management and technology risk operations within P&T Operations.
Build strong partnerships with Engineering and Security leadership and act as a trusted advisor on operational readiness, risk visibility, and organizational response.
Develop the capabilities, processes, and team needed as the scope matures, while remaining willing to operate hands-on where the organization needs it most.
What you need to bring
Significant experience leading incident management, technology operations, security operations, risk programs, or a closely related function in a complex technology organization.
Demonstrated experience designing or materially improving incident management processes, standards, communications, reporting, and post-incident follow-through across multiple teams.
Working knowledge of security incident response and vulnerability management, with the ability to partner credibly with Security and Engineering leaders without needing to be the deepest technical expert in every domain.
Experience building executive-level risk, incident, or operational reporting that turns complex technical information into clear insights, actions, and decisions.
Strong understanding of how technology and security risks are identified, prioritized, mitigated, tracked, and communicated in an enterprise environment.
Experience leading cross-functional change and driving accountability across teams where you do not have direct authority.
Strong executive communication skills, including the judgment to tailor communications for technical teams, senior executives, and board-level audiences.
Ability to bring structure to ambiguity, identify systemic issues, and build durable operating mechanisms rather than simply coordinate activity.
Strong judgment, calm under pressure, and the ability to operate effectively during high-severity or high-visibility incidents.
A collaborative leadership style and the ability to build trust across Product, Engineering, Security, Legal, Compliance, and executive leadership.
How would you rate this job post?
See what other professionals think about this role.
Similar Opportunities
More Openings at Lightspeed Commerce
Senior Product Designer
Lightspeed Commerce
TorontoSales Development Representative (Ownership Role) - Remote (British Columbia, Canada)
Lightspeed Commerce
VancouverSales Development Representative
Lightspeed Commerce
ManilaSoftware Development Manager
Lightspeed Commerce
TorontoExplore Top Companies in this Space
Trading 212
FinTech & Wealth Management / Retail Brokerage & Trading Apps / Commission-Free Investing SaaS / Financial Technology Platforms
Seed
Biotechnology / Pharmaceuticals / Health & Wellness / Consumer Packaged Goods
Toucanberry
Insurance / Reinsurance / Enterprise Software / AI
Doctor Care Anywhere
Telehealth / Digital Health / Healthcare Services / SaaS
Lightspeed Commerce
View Company ProfileLightspeed Commerce is a premier, enterprise-grade unified point-of-sale (POS), payments, and e-commerce platform engineered to orchestrate massive-scale retail, hospitality, and golf-management ecosystems. Operating as a cloud-native commerce hub, the company eliminates the operational friction of traditional, legacy hardware-heavy systems—which frequently suffer from disconnected data silos, limited inventory visibility, and manual reporting overhead—by seamlessly deploying advanced real-time inventory telemetry, rigorous omnichannel synchronization architectures, and cohesive global payment-processing frameworks. Moving beyond rigid legacy brick-and-mortar paradigms, Lightspeed empowers over 170,000+ global locations to dynamically synchronize their in-person, e-commerce, and wholesale pipelines with elite, scalable, and autonomous execution. Under the hood, their sophisticated proprietary operational infrastructure natively manages complex multi-location SKU ingestion, instantaneous sales-data routing, and automated financial-reporting workflows, providing the necessary operational foundation for complex multi-site retail and restaurant groups to operate as a single, unified business entity. What sets Lightspeed apart is its uncompromising dedication to frictionless commerce orchestration; by bridging the gap between highly technical, performance-intensive hospitality demands and accessible, high-velocity digital-retail interfaces, the platform empowers modern merchants to radically accelerate their transaction velocity, eliminate systemic operational bottlenecks, and build an unassailable foundation for continuous commercial and institutional dominance in the modern, AI-transformed digital-economy landscape.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.
