Incident Response Analyst

Cyberwall Inc

Vaughan

Hybrid

CAD 80,000 - 110,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

A cybersecurity services provider is seeking an experienced Incident Response Analyst in Vaughan, ON. The role involves leading incident response engagements and managing security incidents. Candidates should have over 3 years of experience with a strong background in digital forensics and incident management. Excellent communication skills and experience with EDR/XDR platforms are essential. The position is onsite and requires GTA candidates only. Apply by sending your resume to the provided email.

Qualifications

  • 3+ years of experience in Incident Response, Digital Forensics, or advanced SOC roles.
  • Experience in MSSP, consulting, or enterprise security environments.
  • Strong written and verbal communication skills, including executive reporting.

Responsibilities

  • Lead and manage incident response engagements across client environments.
  • Serve as a primary technical lead during security incidents.
  • Conduct advanced forensic investigations.

Skills

Incident Response
Digital Forensics
EDR/XDR platforms
Communication Skills
Analytical Skills

Tools

Python
PowerShell

Job description

Cyberwall is a cybersecurity services provider delivering advanced threat detection, digital forensics, and incident response services to organizations in Canada and USA. We are expanding our Incident Response practice and are seeking an Incident Response Analyst to lead client-facing engagements and manage complex security incidents.

This role is suited for an experienced cybersecurity professional who has handled real-world breaches end-to-end and can confidently guide both executive and technical stakeholders through high-impact incidents. If you have Incident Response experience, you are encouraged to apply.

Role Overview

As an Incident Response Analyst, you will act as a primary responder during active security incidents. You will lead investigations, coordinate containment efforts, provide strategic remediation guidance, and deliver detailed executive-level reporting. This role requires strong technical depth combined with clear communication and leadership skills.

Key Responsibilities
  • Lead and manage incident response engagements across client environments
  • Serve as a primary technical lead during security incidents
  • Conduct advanced host, network, and cloud-based forensic investigations
  • Analyze EDR/XDR telemetry, SIEM alerts, firewall logs, and threat intelligence
  • Develop and oversee containment, eradication, and recovery strategies
  • Deliver detailed root cause analysis and post-incident reports
  • Provide executive briefings and remediation roadmaps
  • Perform proactive threat hunting and compromise assessments
  • Support incident response readiness reviews and tabletop exercises
  • Contribute to the development and refinement of internal IR playbooks and methodologies
Technical Expertise
  • Strong hands-on experience with EDR/XDR platforms (SentinelOne or equivalent)
  • Advanced experience with SIEM platforms and log correlation
  • Experience investigating ransomware, business email compromise (BEC), insider threats, and advanced persistent threats
  • Deep understanding of MITRE ATT&CK and attacker TTPs
  • Familiarity with forensic methodologies and evidence handling best practices
  • Proficiency in investigating Windows and Linux OS systems
  • Strong knowledge of TCP/IP, DNS, VPNs, firewalls, and IPS technologies
  • Experience analyzing logs in JSON, Syslog, and CEF formats
  • Scripting capability (PowerShell, Python, or similar) preferred
Qualifications
  • 3+ years of experience in Incident Response, Digital Forensics, or advanced SOC roles
  • Experience in MSSP, consulting, or enterprise security environments
  • Demonstrated ability to independently lead investigations
  • Strong written and verbal communication skills, including executive reporting
  • Knowledge of security frameworks such as NIST, ISO 27001, and CIS Controls

Certifications are considered an asset: GCIA, GCIH, GCFA, CISSP, CEH, or equivalent.

What We’re Looking For
  • Strong investigative mindset and analytical depth
  • Ability to remain composed and decisive during high-severity incidents
  • Client-facing professionalism and advisory capability
  • Ability to translate technical findings into business risk and impact
  • Commitment to ongoing threat research and professional development
Location Requirement
  • GTA candidates only
  • Onsite role in Vaughan, ON
  • No relocation or work permit will be provided

If you are an experienced incident responder ready to lead complex investigations and play a key role in strengthening client security posture, we encourage you to apply.

Apply by sending your resume to: info@cyberwalldefense.com

Thank you! You’ll receive an email shortly.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

On-site
CAD 90,000 - 120,000
Remote working available
Flex Office work environment
Annual training and certification
Incident Response Lead (Cyber)
Incident Response Lead (Cyber)

CyberClan • Canada

On-site
CAD 100,000 - 130,000
Incident Response Manager
Incident Response Manager

CyberClan • Canada

Remote
GBP 75,000 - 91,000
Health Insurance
Dental Insurance
Remote Work
+1
Cybersecurity Incident Response Commander
Cybersecurity Incident Response Commander

ISA Cybersecurity Inc • Toronto

On-site
CAD 135,000 - 180,000
Flexible sick and personal days
Generous health plan
RRSP matching and bonus programs
+1
Incident Response Analyst, Digital Forensics & Incident Response
Incident Response Analyst, Digital Forensics & Incident Response

ISA Cybersecurity Inc • Toronto

On-site
CAD 75,000 - 105,000
Flexible sick days
Health plan
Education reimbursement
+5
Senior Analyst - Security Operations, Information & Cybersecurity
Senior Analyst - Security Operations, Information & Cybersecurity

Realign Llc • Toronto

On-site
CAD 90,000 - 120,000
Soc Analyst
Soc Analyst

Altis Technology • Toronto

On-site
CAD 90,000 - 130,000
Security Analyst
Security Analyst

EIZIE • West Hawk Lake

On-site
CAD 80,000 - 110,000
Competitive salary
Health and dental benefits
Professional development
+5
Senior Incident Response Lead — Forensics & IR Strategy
Senior Incident Response Lead — Forensics & IR Strategy

Cyberwalldefense • Vaughan

On-site
CAD 80,000 - 110,000
Senior Digital Forensic Investigator
Senior Digital Forensic Investigator

eSentire, Inc. • Southwestern Ontario

Hybrid
CAD 120,000 - 160,000
Paid parental leave
Matching RRSP program
Competitive employee referral bonus