Information Security Operations Analyst (Toronto, Canada)

Starling

Toronto

Hybrid

CAD 85,000 - 120,000

Full time

22 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Discretionary benefits stipend
20 days annual leave

Job summary

Starling is expanding its Toronto-based SOC team to protect customers, assets, and systems across a 24/7 operational window with UK, Sydney and Toronto coverage. The role emphasizes incident triage, response, investigations, and proactive threat hunting using the latest security technologies.

You will work in a collaborative, global SecOps environment, contributing to incident handling, communications, and knowledge sharing across borders, while supporting Starling’s borderless culture and

Qualifications

  • Minimum 3+ years in an in-house SOC role.
  • Understanding of AWS Security Solutions or other Cloud platforms.
  • Experience with cloud-based investigations (GCP, AWS).

Responsibilities

  • Triage, respond to, and investigate security incidents.
  • Investigate alerts from multiple sources including cloud and endpoint.
  • Develop analytic triggers to improve alert efficacy.
  • Document incidents and investigations and maintain readiness.

Skills

SOC Analyst
Cloud security
Incident Response
SIEM experience
Communication skills
Teamwork
Time management
Learning mindset
Mentoring

Education

Cyber/Information Security degree

Tools

AWS Security Solutions
GCP
SIEM platforms
Endpoint detection

Job description

We are Starling. We started by building a new kind of bank because we knew technology had the power to transform how people save, spend, and manage their money. Today, our ambition and our footprint have grown.

Our ecosystem encompasses our pioneering, fully licensed UK bank (Starling), our global Software-as-a-Service technology platform (Engine by Starling), alongside a growing portfolio of specialist financial and software businesses.

While our roots are in the UK, our operations are expanding globally. Though you may be based in one of our international offices (such as Sydney or Toronto), this role is critical to the entire Starling Group. The work you do will support, empower, and protect our businesses worldwide.

Our technologists are at the very heart of Starling and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and leveraging disruptive technology that keeps us on the cutting edge of fintech. We operate a flat structure to enable you to make decisions regardless of your location or primary responsibilities; innovation and collaboration will be at the core of everything you do. Help is never far away in our open, borderless culture - you will find support in your team and from across the global business. We are in this together!

The way to thrive and shine within Starling is to be a self-driven individual and take full ownership of everything around you: from building, discovering, and solving complex problems, to sharing knowledge with your international colleagues to ensure all processes are efficient and productive. Our purpose across all our businesses is underpinned by five Starling values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.

Hybrid Working

We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of place of work in Toronto, so that we're able to interact and collaborate in person.

About the Role

To support our growth, we are looking for SOC Analysts to join our growing cyber security function. This role will be supporting our 24/7 operational capabilities by providing coverage in working hours from Sydney and Toronto alongside our UK colleagues.

As a member of the Starling Group's SOC team, you will be working with the industry's brightest SecOps professionals to protect Starling Group's customers, assets, and systems using the latest technologies.

Incident Triage, Response, and Investigations based on Alerts received from multiple sources which include:

  • Endpoint Detection and Response.

Investigating and responding to security alerts raised by Users.

Enhancing and creating analytic triggers to enhance alert efficacy.

Continuous development of incident handling and readiness processes.

Proactive threat hunting based on threat intelligence.

Documentation of incidents and investigations.

About the Starling Group

We are Starling. We started by building a new kind of bank because we knew technology had the power to transform how people save, spend, and manage their money. Today, our ambition and our footprint have grown.

Our ecosystem encompasses our pioneering, fully licensed UK bank (Starling), our global Software-as-a-Service technology platform (Engine by Starling), alongside a growing portfolio of specialist financial and software businesses.

While our roots are in the UK, our operations are expanding globally. Though you may be based in one of our international offices (such as Sydney or Toronto), this role is critical to the entire Starling Group. The work you do will support, empower, and protect our businesses worldwide.

Our technologists are at the very heart of Starling and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and leveraging disruptive technology that keeps us on the cutting edge of fintech. We operate a flat structure to enable you to make decisions regardless of your location or primary responsibilities; innovation and collaboration will be at the core of everything you do. Help is never far away in our open, borderless culture - you will find support in your team and from across the global business. We are in this together!

The way to thrive and shine within Starling is to be a self-driven individual and take full ownership of everything around you: from building, discovering, and solving complex problems, to sharing knowledge with your international colleagues to ensure all processes are efficient and productive. Our purpose across all our businesses is underpinned by five Starling values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.

Hybrid Working

We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of place of work in Toronto, so that we're able to interact and collaborate in person.

About the Role

To support our growth, we are looking for SOC Analysts to join our growing cyber security function. This role will be supporting our 24/7 operational capabilities by providing coverage in working hours from Sydney and Toronto alongside our UK colleagues.

As a member of the Starling Group's SOC team, you will be working with the industry's brightest SecOps professionals to protect Starling Group's customers, assets, and systems using the latest technologies.

Incident Triage, Response, and Investigations based on Alerts received from multiple sources which include:

  • Cloud Infrastructure/Security.
  • Endpoint Detection and Response.
  • Perimeter detection tooling.

Investigating and responding to security alerts raised by Users.

Enhancing and creating analytic triggers to enhance alert efficacy.

Continuous development of incident handling and readiness processes.

Proactive threat hunting based on threat intelligence.

Documentation of incidents and investigations.

Requirements
About your Skills
  • 3+ years experience in an in-house SOC role and team
  • Understanding of AWS Security Solutions (or other Public Cloud Solutions)
  • Analysis and Incident Response experience with Cloud systems (GCP, AWS)
  • Experience working and supporting analytics/SIEM platforms.
  • Experience supporting and conducting Incident Response engagements.
  • Experience in endpoint based investigations.
  • Experience in cloud based investigations.
  • Experience with Incident Command and conducting Tabletop Exercises.
  • Excellent communication skills (both verbal and written), ability to communicate technical concepts to both technical and non-technical audiences.
  • Demonstrated teamwork and collaboration skills as part of a multi-functional team
  • Time management, problem-solving and interpersonal skills.
  • Eagerness to learn and apply knowledge to new security challenges.
  • Willingness to share knowledge with the team and mentor colleagues.
  • A high level understanding of mobile, network and operating system security controls.
Preferred
  • 3+ years experience in a cyber incident response and digital forensics function
  • Experience in forensics: cloud (GCP, AWS); endpoint/server (Windows, MacOS, Linux); and/or network.
  • Any experience of programming in Python, Go and/or Java.
  • A Cyber/Information Security related degree and/or relevant cyber security qualification(s) would be desired but not required
  • Understanding of malware analysis techniques
Interview Process
  • First Interview: 45 minutes
  • Technical Interview: 90 minutes
  • Final Interview: 30 minutes
Please Note

We require our successful candidatestopass background checks (including but not limited to employment references, fraud checks, financial probity, social media, and criminal history).

Starling welcomes and encourages applications from people with disabilities. Accommodations are available on request for candidates taking part in all aspects of the selection process.

We are unable to provide work permit or visa sponsorship for any role in Canada at this moment in time.

Benefits

A discretionary benefits stipend, payable on a monthly basis, is provided

20 days annual leave plus public holidays

You may be put off applying for a role because you don't tick every box. Forget that! While we can't accommodate every flexible working request, we're always open to discussion. So, if you're excited about working with us, but aren't sure if you're 100% there yet, get in touch anyway. We're on a mission to radically reshape banking - and that starts with our brilliant team. Whatever came before, we're proud to bring together people of all backgrounds and experiences who love working together to solve problems.

Starling is an equal opportunity employer, and we're proud of our ongoing efforts to foster diversity & inclusion in the workplace. Individuals seeking employment at Starling are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.

When you provide us with this information, you are doing so at your own consent, with full knowledge that we will process this personal data in accordance with our Privacy Notice. By submitting your application, you agree that the Starling Group will collect your personal data for recruiting and related purposes. Our Privacy Notice explains what personal information we will process, where we will process your personal information, its purposes for processing your personal information, and the rights you can exercise over our use of your personal information.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Soc Analyst
Soc Analyst

Altis Technology • Toronto

Hybrid
CAD 90,000 - 130,000
Technical Account Manager
Technical Account Manager

Engine by Starling • Toronto

Hybrid
CAD 90,000 - 130,000
Technical Account Manager - Engine by Starling
Technical Account Manager - Engine by Starling

Starling • Toronto

On-site
CAD 90,000 - 130,000
JSOC - Cybersecurity Specialist - Incident Response
JSOC - Cybersecurity Specialist - Incident Response

Community Trust Company • Canada

Hybrid
CAD 81,000 - 101,000
Senior Security Engineer
Senior Security Engineer

EQ Bank | Equitable Bank • Toronto

Hybrid
CAD 100,000 - 140,000
Competitive discretionary bonus
Market-leading RRSP match program
Medical, dental, vision, life, and disability benefits
+3
Senior Security Operations Analyst, Detection & Response
Senior Security Operations Analyst, Detection & Response

Financeit • Toronto

On-site
CAD 110,000 - 125,000
Hybrid workplace options
Competitive pay and bonus
RRSP matching
+3
Senior Software Developer, Security Automation(Global Security)
Senior Software Developer, Security Automation(Global Security)

RBC • Toronto

On-site
CAD 120,000 - 170,000
Total rewards program
Coaching and development
World-class tools and training
+1
Senior Incident Response Analyst (Global Security)
Senior Incident Response Analyst (Global Security)

Socket.dev • Toronto

On-site
CAD 90,000 - 140,000
Senior Security Specialist - Cloud (Global Security)
Senior Security Specialist - Cloud (Global Security)

RBC • Toronto

Hybrid
CAD 120,000 - 180,000
Total Rewards program with bonuses and
Annual training budget
Coaching & development
+3
Senior Incident Response Analyst (Global Security)
Senior Incident Response Analyst (Global Security)

RBC • Toronto

On-site
CAD 90,000 - 120,000