Sibylline is a leading intelligence and strategic risk consultancy in the security sector. Since 2010 we have supported businesses, governments and NGOs through the provision of high-quality risk analysis, due diligence and consultancy services.
The firm provides an innovative, entrepreneurial and fast-growing working environment, offering employees ever greater exposure to high profile clients and challenges. Sibylline offers fantastic opportunities for career progression within a successful company, and we aim to help our employees to build their own personal profiles as well-regarded analysts within the broader industry.
Key attributes of Sibylline employees are:
Expected Compensation: C$100,000 – C$125,000 per year
Location: Onsite, Toronto, ON
PTO: 20 days per annum
Sick: 5 paid days per annum
Vacancy Status: Existing Vacancy
This role will close for applications at 0900 EDT on Monday 14 September 2026.
We are looking for an experienced security and intelligence professional to join us as an embedded GSOC Intelligence Team Leader for a newly established Global Security Operations Centre (GSOC) at a multinational e-commerce client. The GSOC Manager will lead a 24/7/365 team of GSOC Intelligence Analysts providing threat monitoring, incident response, intelligence analysis, and physical security operations.
You will be responsible for leading, managing, and developing the GSOC team. This will include line management, scheduling, identifying training needs and delivering training, and performance management. The Team Leader will also be responsible for setting the standard for high-quality intelligence analysis work and as a power user for all tools and systems used by the GSOC. This role will also involve working closely with Sibylline management and the client to ensure a smooth transition as the new team comes online. You will proactively engage with the client and stakeholders on monitoring and intelligence needs and priorities, and help to scope the output and strategic deliverables of the team.
This is an onsite role at the client’s Toronto office, working Monday to Friday, 9am-5pm. There may be occasional need to work out-of-hours during emergencies and time sensitive matters.
Essential Functions / Responsibilities
Drive the implementation of the new GSOC team, identifying the client’s immediate delivery needs and any team training requirements
Set team priorities, delegate tasks, manage deadlines, provide feedback, and ensure high-quality service delivery
Manage the 24/7/365 shift schedule and ensure full shift coverage
Monitor and direct the team’s use of security systems, intelligence and open-source tools
Lead oversight of GSOC’s adherence to incident response, triage, and escalation Standard Operating Procedures (SOPs)
Provide continuous editorial and mentoring support for the GSOC team
Define and agree on key intelligence priorities with security stakeholders to optimise the production and delivery of intelligence products and briefings
Build and maintain cross-functional stakeholder relationships
Identify process gaps, training gaps, configuration issues, or workflow friction, and implement corrective actions in a timely manner
Display creating thinking and consulting skills to deliver a continually improving service for the client
Other duties as assigned
Knowledge, Skills, and Abilities
Experience, knowledge, and interest in current affairs, international relations and emerging security threats
Advanced research, intelligence gathering and analytical skills, and the ability to write high-quality products and deliver high-impact briefings for a senior security audience
Excellent English written and verbal communication skills, with a high attention to detail and strong ability to quality assure (peer review) intelligence products
Excellent time management and prioritisation skills, with the ability to set and meet deadlines and manage own / team’s workload accordingly
Ability to solve complex problems with patience and precision, whilst retaining focus on customer needs
Ability to build rapport, strong and sustainable relationships, and interact within all levels of the client
Ability to develop and deliver training and support direct reports’ professional development
Undergraduate or Postgraduate qualifications in International Security, Intelligence, Risk, Geopolitics or other related disciplines, or equivalent professional experience
Experience with GSOC and intelligence tools, including threat monitoring, OSINT, and SOCMINT platforms
At least 5+ years total experience working in a corporate setting or similar public or private sector environments, with at least 2+ year line management experience
Fluent written and spoken English
Preferred cross-functional experience within a global security team (e.g. threat monitoring, travel security, business continuity, crisis management), particularly in a leadership role
Work Environment/Physical Requirements
This position is moderately self-directed and requires understanding and compliance with company policies, procedures, and values. While performing the duties of this job, the employee is regularly required to interact collaboratively with the team and stakeholders, and communicate via phone, videophone, or text messaging. The position may require travel up to 5%.
Interview Process
Artificial Intelligence: Not used in candidate screening
Research indicates that certain groups are less likely to apply for a position unless they meet every single requirement. If you feel you meet some of the requirements and can offer a unique perspective to this role, we strongly encourage you to apply—you might be the perfect fit we're looking for!
Sibylline is committed to the recruitment and selection of candidates without regard for sexual orientation, gender, ethnicity, age, political beliefs, culture, and lifestyle. We are committed to fostering a business culture that reflects these values and promotes equal opportunity.

Sibylline is the world’s leading private consultancy for geopolitical risk, intelligence, and strategic insight, dedicated to helping leaders and organisations anticipate change, manage risk, and build resilience.
Since 2010 we have supported businesses, governments and NGOs through the provision of high quality risk analysis and due diligence services. We do not believe in one-size-fits-all solutions. Instead, our global source network, professional intelligence analysis processes and specialist expertise allows us to produce high-quality, insightful work that has direct relevance to our clients’ business.
We strive to offer clients actionable assessments that go beyond the obvious and offer implications of geopolitical events in the regions they operate.
Our flagship product, the World Risk Register, provides both written and quantifiable analysis on world events, by region. Our proprietary software gives clients the ability to gain any level numerical data on world-wide locations as needed, in tandem with an overall rating system and backed up by written analysis with predictions of how events will unfold and impact business.
Our services and experience include fully-run in-house GSOCs, virtual GSOCs, embedded analysts, consultation and training for existing security operations with insight for improvement, project work, regular reporting, social media monitoring and due diligence services.
As subject matter experts, our analysts are frequently called upon for speaking engagements, media interviews and in-house corporate presentations.
We are always looking over the horizon to keep clients’ personnel, sites, assets and supply chains safe.