Incident Response Manager

CyberClan

Canada

Remote

GBP 75,000 - 91,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health Insurance
Dental Insurance
Remote Work
RRSP benefits

Job summary

CyberClan is seeking a DFIR Manager to lead a high-performing Security Incident Response function across global operations. The role focuses on developing incident response strategies, mentoring analysts, and ensuring legal and technical integrity during investigations.

The ideal candidate will drive metrics, own post-breach remediation, and partner with leadership to maintain organization resilience in a 24x7 environment. This is a remote Canada-based role with travel opportunities.

Qualifications

  • Minimum 3 years of management/leadership experience with client-facing exposure.
  • 6+ years of Incident Response experience.
  • Bachelor’s degree or matched work experience.
  • 5+ years of information security with incident response leadership.
  • Experience in Cyber Insurance and Legal markets.
  • Experience with EDR, SIEM and related security technologies.

Responsibilities

  • Lead security incidents across cross-functional teams, mentoring staff to scale in a high-growth environment.
  • Develop IR initiatives to rapidly respond and remediate events.
  • Oversee incident response plans, policies, and cross-team coordination.
  • Serve as technical point of contact during incidents and provide updates to stakeholders.
  • Prepare KPI reports for senior leadership and drive continuous improvement.

Skills

Leadership
Incident Response
DFIR Tools
EDR Technology
Communication

Education

Bachelor's degree or equivalent experience

Tools

SIEM
AWS
EDR Technology

Job description

CyberClan provides enterprise security, and human response to small and midsize enterprises and

channel partners through comprehensive risk assessment services, 24/7/365 managed detection and response services, and lightning-fast breach response. Formerly known as Network Test Labs established in Canada and specializing in vulnerability assessments and penetration testing in the gaming industry,

CyberClan has grown from three employees in 2006 in one market to over 75 employees with clients in nine countries and offices in the Australia, Canada, United Kingdom, and United States as a leading Managed Services Provider.

Our mission is to make the online world a safer and more secure place by delivering sophisticated

cybersecurity solutions in a highly personalized — and human — way.

CyberClan is hiring a DFIR Manager who will be leading a high-performing Security Incident Response

function, overseeing cross-functional investigations, incident resolution, and remediation efforts across global operations. This position is responsible for developing and implementing incident response strategies, driving key performance metrics, mentoring team members, and ensuring legal and technical integrity throughout forensic investigations. As a strategic partner to leadership, the role provides detailed reporting, resource management, and operational oversight while also acting as a technical authority during incidents. The ideal candidate foster innovation, ensures constant readiness through training and tooling, and plays a critical role in post-breach remediation, client communication, and maintaining organizational resilience in a 24x7 environment.

The successful candidate will work closely with the Director of Global Incident Response Operations. The ideal candidate will have an energetic, can-do attitude and be comfortable working in a metrics-driven environment, delivering results and supporting team members.

Key Responsibilities
  • Leading security incidents in a cross-functional and collaborative environment, targeting incident resolution & mentoring team members to continue to scale in high-growth
  • Developing IR initiatives that improve our capabilities to respond and swiftly remediate security events.
  • Creating a culture of accountability, quality, agility, and high performance that will foster the attraction, development, and retention of security analysts.
  • Responsible for being a focal incident response point for all within the organization. This includes being able to provide initial analysis and identification of IOC’s, escalation to the appropriate business units and post-incident activities.
  • Oversee Incident Response Plans: Design, implement, and manage the client's incident response policies and procedures to ensure preparedness.
  • Coordinate Incident Response Teams: Lead cross-functional teams during security incidents, ensuring an organized and timely response.
  • Triage and Prioritize Incidents: Assess incidents for severity and potential impact, assigning appropriate resources and setting response priorities.
  • Serve as technical point of contact during an incident, providing updates to internal and external stakeholders.
  • Serve as an incident manager, reporting key findings, barriers, escalations and concerns to the Director of Global Incident Response Operations, while liaising with Legal, Director of Sales, and IRC team.
  • Maintain and prepare departmental reports for Key Performance Indicators (KPIs) to be presented to the Global Head of Incident Response Operations and EVP Sales & Revenue as needed.
  • Responsible for supporting a wide number of technologies and being able to proficiently perform advanced troubleshooting on the fly (packet captures, debugs, traffic analysis).
  • Responsible for developing and documenting Incident Response methods and guidelines for the organizations.
  • Support in the departments DFIR tooling selection process and any proof-of-concept projects.
  • Chain of Custody: Ensure that evidence is collected, handled, and preserved in a legally defensible manner, maintaining the chain of custody for potential litigation
  • Perform live-endpoint investigation.
  • Implements and deploys an Incident Response focused ticketing system to improve incident tracking, remediation and metrics for incidents worked.
  • Post-incident Analysis: Conduct root cause analysis after incidents to identify vulnerabilities and develop strategies to prevent recurrence.
  • Responsible for working with 3rd parties in order to assist with incident response, business email compromise, security breach, improve overall security, investigations, recommendations and remediation.
  • Assists Sales and SOC in the successful conversion from incident response, PBR, RMS, eDiscovery to SOC; including process and procedure build out.
  • Budget and Resource Management: Oversee the allocation of resources, including personnel, tools, and budgets, to effectively manage incident response and forensics operations.
  • Monitor and Manage Regional profit & loss metrics and requirements.
  • Create, maintain, and enhance onboarding program that is concise and repeatable, effectively covering all aspects of the CERT role.
  • Client Education: Raise awareness across external organizations about digital forensics, incident response protocols, and security best practices.
  • Maintain and manage AWS instances to ensure timely deletion and removal of data to minimize company and customer fees/overages.
  • Other duties as assigned.
Attributes
  • Successful track record of helping to implement security initiatives and frameworks in a flexible and innovative manner.
  • A collaborative approach to decision-making and the ability to influence with minimal guidance.
Qualifications:
  • Minimum 3 years of Management/Leadership experience & client facing experience in technical situations.
  • Minimum 6 years of experience in Incident Response.
  • Bachelor’s degree or matched work experience.
  • 5+ years of information security experience as well as leading teams with a deep passion for cybersecurity and incident response.
  • Experience in the Cyber Insurance and Legal markets.
  • Experience in conducting Tabletop Exercises in Incident Response.
  • Experience in the deployment and management of EDR Technology.
  • Experience with Security Technologies and NIST Framework.
  • Experience in forensic investigations both on-premises and cloud.
  • Experience in mentoring developing and delivering in-house training.
  • Must be available to provide coverage to meet business requirements in 3 regions.
  • Strong knowledge of DFIR Tools.
  • Strong knowledge of Virtualization Technologies, Operating Systems, Firewalls, VPN’s, SIEM, Enterprise Gateway Technologies, Networking Devices, Security Technologies, etc.
Nice to Have
Bilingual: Ability to communicate in English and French
Job Type

Full-Time

Location

100% Telecommuting

Compensation

Cyberclan is committed to equal pay for equal work in its compensation practices. The base salary range for this position in Canada is $140,000- 170,000 CAD per year + RRSP+ benefits. A candidate’s salary is determined by various factors including, but not limited to, relevant work experience, skills, certifications and location. This is Canadian-based employment, and it is expected that all employees maintain legal entitlement to work in Canada. Applicants selected to move forward in the hiring process are subject to background checks, including but not limited to criminal record, credit, and/or reference checks.,

  • Health, dental, vision, life and AD&D insurance, employee assistance program
  • 100% remote working environment
  • High performing and supportive team
% of Travel Required+

Ability to travel up to 10%

Physical Requirements

Prolonged periods of sitting at a desk and working on a computer

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Lead (Cyber)
Incident Response Lead (Cyber)

CyberClan • Canada

On-site
CAD 100,000 - 130,000
Information Technology Support Analyst
Information Technology Support Analyst

CyberClan • Kitchener, Cambridge, Southwestern Ontario

Hybrid
CAD 60,000 - 70,000
Incident Response Analyst, Digital Forensics & Incident Response
Incident Response Analyst, Digital Forensics & Incident Response

ISA Cybersecurity Inc • Toronto

On-site
CAD 75,000 - 105,000
Flexible sick days
Health plan
Education reimbursement
+5
Cybersecurity Incident Response Commander
Cybersecurity Incident Response Commander

ISA Cybersecurity Inc • Toronto

On-site
CAD 135,000 - 180,000
Flexible sick and personal days
Generous health plan
RRSP matching and bonus programs
+1
L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

On-site
CAD 90,000 - 120,000
Remote working available
Flex Office work environment
Annual training and certification
Director - CSIRT (Cybersecurity Incident Response Team)
Director - CSIRT (Cybersecurity Incident Response Team)

KellyOCG • Montreal (administrative region)

Hybrid
CAD 180,000 - 230,000
Sr. Cyber Consultant, DFIR
Sr. Cyber Consultant, DFIR

LevelBlue, LLC. • Canada

Hybrid
CAD 90,000 - 130,000
Sr. Cyber Consultant, DFIR
Sr. Cyber Consultant, DFIR

Forensic Focus Limited • Canada

Hybrid
CAD 95,000 - 158,000
Manager, Security Incident Response
Manager, Security Incident Response

TechAlliance of Southwestern Ontario, London Economic Development Corporation • Toronto

On-site
CAD 80,000 - 120,000
Sr. Cyber Security Analyst
Sr. Cyber Security Analyst

10 Percent Recruiting Ltd. • Canada

Hybrid
CAD 110,000 - 140,000