Incident Response Specialist

Integriti

Toronto

On-site

CAD 90,000 - 130,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Integriti is seeking a seasoned cybersecurity professional in Toronto to lead incident response efforts. You will monitor security alerts, triage incidents, and conduct end-to-end investigations spanning phishing, malware, and cloud-related events.

The role requires hands-on experience with SIEM/EDR/XDR, log analysis, and IOC enrichment, with emphasis on threat hunting using KQL and SOAR playbooks.

Qualifications

  • 3–5 years of cybersecurity experience, with 2–3 years in incident response, SOC, or cyber investigations.
  • Strong understanding of the incident response lifecycle: preparation, identification, containment, eradication, recovery, and lessons learned.
  • Hands-on experience with phishing, malware, endpoint compromise, suspicious authentication activity, privilege misuse, and cloud security events.
  • Hands-on experience with SIEM, EDR/XDR, and identity & cloud logs (Azure, GCP).
  • Strong skills in log analysis, IOC identification, and root cause determination.
  • Experience documenting incidents and producing actionable remediation guidance.
  • Experience performing Threat hunting using KQL or other query languages, SOAR/playbook automation.

Responsibilities

  • Monitor, assess, and triage security alerts and events from SIEM, EDR/XDR, email security, cloud security, and other monitoring platforms.
  • Validate security incidents and determine severity, scope, and business impact.
  • Conduct end-to-end investigations of cybersecurity incidents including phishing, malware, ransomware, account compromise, insider threat, unauthorized access, data exfiltration, and cloud-related incidents
  • Document investigative findings, timelines, indicators of compromise (IOCs), and remediation recommendations.
  • Contribute to use case development, threat hunting, and IOC enrichment where needed.

Skills

Cybersecurity experience
Incident response
SOC operations
Threat hunting
KQL queries
SOAR playbooks
Log analysis
IOC identification
Root cause analysis
Phishing incidents
Cloud security events
SIEM
EDR/XDR
Azure logs
GCP logs

Tools

SIEM
EDR/XDR
Azure logs
GCP logs

Job description

Responsibilities:

  • Monitor, assess, and triage security alerts and events from SIEM, EDR/XDR, email security, cloud security, and other monitoring platforms.
  • Validate security incidents and determine severity, scope, and business impact.
  • Conduct end-to-end investigations of cybersecurity incidents including phishing, malware, ransomware, account compromise, insider threat, unauthorized access, data exfiltration, and cloud-related incidents
  • Document investigative findings, timelines, indicators of compromise (IOCs), and remediation recommendations.
  • Contribute to use case development, threat hunting, and IOC enrichment where needed.

Required Skills:

  • 3-5 years of cybersecurity experience, with at least 2-3 years in incident response, SOC, or cyber investigations.
  • Strong understanding of the incident response lifecycle: preparation, identification, containment, eradication, recovery, and lessons learned.
  • Hands-on experience with common incident categories such as phishing, malware, endpoint compromise, suspicious authentication activity, privilege misuse, and cloud security events
  • Hands-on experience with:
    • SIEM, EDR/XDR, Identity & cloud logs (Azure, GCP)
  • Strong skills in log analysis, IOC identification, and root cause determination
  • Experience documenting incidents and producing actionable remediation guidance
  • Experience performing Threat hunting using KQL or other query languages, SOAR/playbook automation
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Incident Response Specialist
Incident Response Specialist

Integriti Group Inc. • Toronto

On-site
CAD 90,000 - 130,000
Manager, Security Incident Response
Manager, Security Incident Response

TechAlliance of Southwestern Ontario, London Economic Development Corporation • Toronto

On-site
CAD 80,000 - 120,000
Incident Response Senior Consultant
Incident Response Senior Consultant

Forensic Focus Limited • Canada

On-site
CAD 120,000 - 180,000
Senior Digital Forensics & Incident Response Consultant (ID#5314)
Senior Digital Forensics & Incident Response Consultant (ID#5314)

New Value Solutions • Canada

Remote
CAD 80,000 - 120,000
Cyber Security Analyst
Cyber Security Analyst

koundinyasa Technology Services • Montreal (administrative region)

On-site
CAD 70,000 - 100,000
Security Operations Analyst
Security Operations Analyst

NextGenEnergyJobs • Canada

Hybrid
CAD 80,000 - 110,000
Health benefits
Paid vacation
Competitive retirement plan
L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

On-site
CAD 90,000 - 120,000
Remote working available
Flex Office work environment
Annual training and certification
L3 SOC Analyst - Calgary
L3 SOC Analyst - Calgary

Integrity360 • Calgary

Hybrid
CAD 80,000 - 110,000
Security Engineer – SIEM, EDR, IAM & Cloud Security
Security Engineer – SIEM, EDR, IAM & Cloud Security

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision! • Montreal (administrative region)

On-site
CAD 90,000 - 130,000
Junior SOC Analyst - Systems Integrator
Junior SOC Analyst - Systems Integrator

Hamilton Barnes Associates Limited • Golden Horseshoe

On-site
CAD 50,000 - 57,000
Health insurance after 90 days
Dental insurance after 90 days
Vision insurance after 90 days
+1