Incident Response Analyst, Digital Forensics & Incident Response

ISA Cybersecurity Inc

Toronto

On-site

CAD 75,000 - 105,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Flexible sick days
Health plan
Education reimbursement
Parental leave top‑up
Referral bonus
RRSP matching
Remote working policy
LinkedIn Learning

Job summary

ISA Cybersecurity Inc. is seeking an Incident Response Analyst to join our DFIR team. The role involves hands‑on forensic collection, analysis, and containment across endpoint, network, and cloud environments, under the IR Commander.

You will support triage, evidence collection, and post‑incident reporting while collaborating with SOC and client teams. Strong English skills and willingness for on‑call rotation are essential.

Qualifications

  • 3+ years in cybersecurity with incident response or digital forensics.
  • Experience with incident response lifecycle, containment and eradication.
  • Hands‑on with host, network, or cloud forensics and chain‑of‑custody requirements.

Responsibilities

  • Support the Incident Commander in IR retainer engagements and emergency IRs.
  • Perform digital forensic acquisition and analysis across endpoints, servers, network, mobile, and cloud sources.
  • Maintain chain‑of‑custody discipline for evidence handling.

Skills

Incident response
Digital forensics
Endpoint forensics
Network forensics
Cloud forensics
MITRE ATT&CK
Technical writing
24x7 on‑call

Education

Bachelor's degree in CS/Info Security

Tools

Windows
Linux
MacOS
AWS
Azure
GCP

Job description

About the Role

The Incident Response (IR) Analyst is a hands‑on technical responder within ISA Cybersecurity's Digital Forensics & Incident Response (DFIR) function, delivering the Security Incident Response (SIR) service across client engagements. The role executes forensic collection, analysis, and containment work under the direction of the Cyber Incident Response Commander, building the case‑based experience and technical depth that lead toward Incident Commander and Senior Analyst career paths.

The IR Analyst supports every stage of active engagements, from triage and evidence acquisition through eradication and post‑incident reporting, working alongside the IR Commander, DFIR team members, and SOC teams. Strategic direction rests with the Incident Commander and final accountability for the DFIR program rests with the Senior Director, DFIR Services.

The successful candidate will have practical experience supporting incident response and forensic investigations, strong technical fundamentals across endpoint, network, and cloud environments, and the composure to work effectively under the pressure of active incidents.

Responsibilities
  • Support the Incident Commander in the execution of IR Retainer engagements and Emergency IRs, carrying out assigned workstreams within the incident.
  • Perform digital forensic acquisition and analysis across endpoint, server, network, mobile, and cloud sources.
  • Maintain chain‑of‑custody discipline suitable for legal proceedings throughout evidence handling.
  • Gather and analyze evidence from logs, email, endpoint artifacts, and other sources to identify indicators of compromise and attacker activity.
  • Reconstruct attack timelines from collected evidence to support root‑cause analysis and scope determination.
  • Apply and help refine DFIR playbooks and runbooks in the course of live engagements, flagging gaps or improvements to the IR Commander.
  • Contribute to incident and digital evidence reports, including drafting technical findings for review by the IR Commander prior to client, legal, or law enforcement delivery.
  • Participate in post‑incident reviews and lessons‑learned sessions, translating findings into playbooks, tooling, or training improvements.
  • Assist with technical scoping input for proposals, Statements of Work (SOWs), and RFP responses as requested.
  • Correlate threat intelligence and observed TTPs into incident analysis, and feed findings back to detection and threat hunting teams.
  • Track and report on assigned incident metrics and contribute to continuous‑improvement initiatives for the DFIR practice.
  • Support the IR readiness program, including IR Plan engagements, Tabletop Exercises (TTX), and playbook validation.
  • Act as a client‑facing technical resource during engagements under the direction of the IR Commander.
  • Collaborate with SOC analysts and Service Owners to keep incident response work aligned with detection capabilities.
Qualifications
  • 3+ years of progressive experience in cybersecurity, including direct experience in incident response and/or digital forensics.
  • Working knowledge of the incident response lifecycle, containment and eradication strategies, and digital forensic methodologies.
  • Hands‑on experience with host, network, or cloud forensics, including exposure to chain‑of‑custody requirements.
  • Proficient working with Windows, Linux, and MacOS environments.
  • Exposure to cloud forensics or investigations (AWS, Azure, GCP, Microsoft 365, Google Workspace).
  • Working knowledge of security control families such as EDR, SIEM, SOAR, NDR, identity, email security, or DLP.
  • Familiarity with MITRE ATT&CK and current ransomware/APT TTPs.
  • Familiarity with frameworks such as NIST SP 800‑61, ISO 27035, or NIST CSF is an asset.
  • Clear written and verbal communication skills; ability to document technical findings for both technical and non‑technical audiences.
  • Bachelor's degree in computer science, Information Security, or related field, or equivalent professional experience.
  • Willingness to participate in 24x7 on‑call rotation for IR Retainers and Emergency IRs.
  • Ability to obtain Government of Canada security clearance.
  • Strong English language skills, written and verbal.
Nice to Have
  • Experience supporting MSSP service delivery, including contractual SLAs and 24x7 operations.
  • Exposure to OSINT gathering and correlation in support of threat actor attribution or exposure analysis.
  • Experience supporting law enforcement engagements or regulatory investigations.
  • Exposure to dark web or social‑media threat monitoring.
  • Multilingual capability is an asset.
Certifications
  • Preferred: GCIH, GCFA, GCFE
  • Nice to have: OSCP, CySA+, CHFI, ECIH, CompTIA Security+, CISSP (or actively pursuing)
  • Cloud (any of): AWS Security Specialty, Azure Security Engineer, Google Professional Cloud Security Engineer
Benefits and Programs
  • Flexible sick and personal days for all employees
  • Generous health plan with enhanced mental health resources and programs
  • Professional development opportunities and education reimbursement up to $2,000 annually for all employees
  • Maternity and parental leave top‑up
  • Employee referral bonus of $2,000
  • Competitive salaries complemented with RRSP matching and bonus programs
  • Distance remote working policy
  • LinkedIn Learning access for all team members
Service Recognition
  • Service anniversary recognition and generous five‑year milestone service awards
  • President’s Club recognizing special achievement awards: Team Member of the Year for Sales, CIOC and Cyber Services, the Rich Uhrich Founder’s Award nominated by all employees and four President’s Awards (Risk Taker, Lost Without You, Money Maker and On the Rise)
  • Spot rewards providing opportunities for instant peer recognition
Team Building
  • Annual kick‑off meeting to communicate our strategic priorities
  • Quarterly town‑hall meetings
  • Regular team get‑togethers and client events
  • Scheduled employee feedback surveys and goal‑setting focus groups
Vacancy Status

This posting is for an existing vacancy.

Salary Range

$75,000–90,000–105,000

AI Disclosure

ISA Cybersecurity does not currently use artificial intelligence tools as part of our recruitment process.

Accessibility

ISA Cybersecurity is committed to providing accommodations for applicants with disabilities. If you require specific accommodation because of a disability or medical need, please inform ISA's Human Resources team (peopleoperations@e-isa.com) so arrangements can be made for appropriate accommodation to be in place during the recruitment process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Incident Response Commander
Cybersecurity Incident Response Commander

ISA Cybersecurity Inc • Toronto

On-site
CAD 135,000 - 180,000
Flexible sick and personal days
Generous health plan
RRSP matching and bonus programs
+1
Incident Response Lead (Cyber)
Incident Response Lead (Cyber)

CyberClan • Canada

On-site
CAD 100,000 - 130,000
Incident Response Senior Consultant
Incident Response Senior Consultant

Jobgether • Canada

Remote
CAD 100,000 - 165,000
Remote work opportunity
Equity opportunities
Professional development
Senior Information Security Analyst
Senior Information Security Analyst

IKO North America • Mississauga

On-site
CAD 106,000 - 120,000
Competitive compensation
Health care
Challenging workplace
+1
Lead Service Manager - Incident Response Analyst
Lead Service Manager - Incident Response Analyst

OpenText • Southwestern Ontario

On-site
CAD 122,000 - 184,000
Consulting Associate/Cybersecurity & Incident Response (Forensic Services practice)
Consulting Associate/Cybersecurity & Incident Response (Forensic Services practice)

Charles River Associates • Toronto

Hybrid
CAD 120,000 - 140,000
Comprehensive benefits package
Wellness programming
Work from home flexibility
Security Analyst
Security Analyst

mjolnirsecurity • Toronto

Hybrid
CAD 65,000 - 95,000
Hybrid flexibility
Mentorship from senior DFIR/M365
Exposure to internal security tools
Senior SOC Analyst
Senior SOC Analyst

Exchange Technology Services • Winnipeg

On-site
CAD 90,000 - 120,000
Competitive salary
RRSP matching
Employee Share Purchase Plan
+4
L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

Hybrid
CAD 90,000 - 120,000
Remote working available
Flex Office work environment
Annual training and certification
Analyst - Cybersecurity and IT Help Desk
Analyst - Cybersecurity and IT Help Desk

Canadian Institute of Actuaries / Institut canadien des actuarires • Ottawa

On-site
CAD 61,000 - 74,000