Information Security Operations Lead

Jobtailor

Toronto

On-site

CAD 110,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a seasoned Security Operations Center (SOC) Lead in Toronto to guide a 팀 of analysts and SMEs in incident response and digital forensics. You will drive continuous improvement in security processes, oversee triage and investigations across cloud, endpoint, and network environments, and communicate findings to diverse audiences.

You will mentor staff, coordinate tabletop exercises, and partner with other teams to enhance detection and containment capabilities, while aligning

Qualifications

  • 5+ years in an in-house SOC role including cyber incident response and digital forensics.
  • Experience leading and developing a team of subject matter experts and managers in Information & Cyber Security.
  • Understanding of AWS Cloud Solutions or other public clouds.
  • Experience with cloud systems (GCP, AWS) incident response.
  • Experience supporting analytics/SIEM platforms and IR engagements.
  • Experience in endpoint based investigations and cloud based investigations.
  • Experience in incident command and tabletop exercises.

Responsibilities

  • Lead a team of SMEs and analysts to manage and improve Information Security aligned with Bank policy.
  • Support development and progression of the Information Security Analyst team.
  • Manage incident triage, response, and investigations across multiple sources (cloud, endpoint, perimeter).
  • Quality Assurance for triage case handling, mitigations, and handovers; capture lessons learned.
  • Interpret logs from cloud/endpoint/network to determine containment and recovery steps.
  • Collaborate with cross-functional teams to contain and recover from incidents.
  • Develop and maintain incident handling, response, and readiness processes.
  • Support detection engineering and threat hunting using threat intelligence.
  • Document incidents and investigations, including findings and containment steps.
  • Plan and participate in Tabletop Exercises; present findings to technical and non-technical audiences.

Skills

Incident Response
Team Leadership
Cloud Security
Forensics
Threat Hunting
SIEM Platforms
Communication
Senior Stakeholder Engagement

Education

Cyber/Information Security degree
Cyber Security qualifications

Tools

SIEM Platforms
Cloud Infrastructure/Security
Endpoint Detection and Response
Perimeter Detection Tooling
Incident Command Tools

Job description

  • Lead a team of subject matter experts and analysts to ensure Information Security is managed and continuously improved in line with Bank policy and procedure.
  • Supporting the development and progression of the Information Security Analyst team from both a technical and professional perspective.
  • Incident Triage, Response, and Investigations based on Alerts received from multiple sources which include: - Cloud Infrastructure/Security.- Endpoint Detection and Response.- Perimeter detection tooling.
  • Conduct Quality Assurance for Triage case handling, mitigation actions and shift handover, collating lessons learned and implementing improvements where required.
  • Interpret logs from a variety of sources (e.g. cloud, endpoint, network) to identify root cause and determine next steps for containment, eradication and recovery as part of incident response activities.
  • Work together with other teams in the organisation to analyse, contain, eradicate and recover from cyber security incidents
  • Continuous development and maintaining of incident handling, response and readiness processes.
  • Support the wider SecOps team with detection engineering - creating and optimising analytic triggers to enhance alert efficacy - and threat hunting based on threat intelligence.
  • Documentation of incidents and investigations, including analysis findings, containment steps and root cause.
  • Plan and participate in Tabletop Exercises.
  • Present investigation findings to technical and non-technical audiences.
Requirements
  • 5+ years experience in an in-house SOC role and team, including cyber incident response and digital forensics function.
  • Experience in a similar role leading, developing and motivating a team of subject matter experts and other managers in Information and Cyber Security.
  • Understanding of AWS Security Solutions (or other Public Cloud Solutions)
  • Analysis and Incident Response experience with Cloud systems (GCP, AWS)
  • Experience working and supporting analytics/SIEM platforms.
  • Experience supporting and conducting Incident Response engagements.
  • Experience in endpoint based investigations.
  • Experience in cloud based investigations.Experience with Incident Command and conducting Tabletop Exercises.
  • Experience in acting as both Commander and SME during incidents and investigations.
  • Be a Self Starter with the ability to lead, inspire and drive change through an organisation.
  • Excellent communication skills (both verbal and written), ability to communicate technical concepts to both technical and non-technical audiences.
  • Demonstrated teamwork and collaboration skills as part of a multi-functional team
  • Time management, problem-solving and interpersonal skills.
  • Eagerness to learn and apply knowledge to new security challenges.
  • Willingness to share knowledge with the team and mentor colleagues.
  • A high level understanding of mobile, network and operating system security controls.
  • Preferred
  • Experience in forensics: cloud (GCP, AWS); endpoint/server (Windows, MacOS, Linux); and/or network.
  • Any experience of programming in Python, Go and/or Java.
  • A Cyber/Information Security related degree and/or relevant cyber security qualification(s) would be desired but not required
  • Understanding of malware analysis techniques
Core Competencies

Demonstrates expertise in Incident Response, Cyber Security, and Team Leadership, with a strong focus on Cloud Security Solutions and forensic analysis. Capable of effectively communicating technical concepts to diverse audiences while driving continuous improvement in security processes.

Highest-signal resume keywords
  • Incident Response Management
  • Cloud Security Solutions (AWS, GCP)
  • Team Leadership and Development
  • Forensics (Cloud, Endpoint, Network)
  • Analytic/SIEM Platform Support
ATS Optimization Keywords
Hard Skills
  • Incident Triage
  • Digital Forensics
  • Cloud Investigations
  • Endpoint Investigations
  • Malware Analysis Techniques
  • Python Programming
  • Go Programming
  • Java Programming
  • Quality Assurance
  • Threat Hunting
Soft Skills
  • Excellent Communication Skills
  • Teamwork and Collaboration
  • Time Management
  • Problem-Solving
  • Interpersonal Skills
Certifications & Qualifications
  • Cyber/Information Security Degree
  • Relevant Cyber Security Qualifications
Industry Keywords
  • Information Security
  • Cyber Security
  • Incident Response
  • Security Operations Center (SOC)
  • Tabletop Exercises
Tools & Technologies
  • Cloud Infrastructure/Security
  • Endpoint Detection and Response
  • Perimeter Detection Tooling
  • SIEM Platforms
  • Incident Command Tools
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Jobtailor • Boisbriand

On-site
CAD 90,000 - 130,000
Information Security Specialist – Attack Surface Reduction
Information Security Specialist – Attack Surface Reduction

Jobtailor • Toronto

On-site
CAD 120,000 - 160,000
Cyber Use Case Developer
Cyber Use Case Developer

Jobtailor • Toronto

On-site
CAD 90,000 - 130,000
Cyber Security Analyst
Cyber Security Analyst

koundinyasa Technology Services • Montreal (administrative region)

On-site
CAD 70,000 - 100,000
Manager, Security Incident Response
Manager, Security Incident Response

TechAlliance of Southwestern Ontario, London Economic Development Corporation • Toronto

On-site
CAD 80,000 - 120,000
L3 SOC Analyst - Calgary
L3 SOC Analyst - Calgary

Integrity360 • Calgary

On-site
CAD 90,000 - 120,000
SOC Manager
SOC Manager

Jobtailor • Montreal (administrative region)

On-site
CAD 110,000 - 165,000
L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

Hybrid
CAD 90,000 - 120,000
Remote working available
Flex Office work environment
Annual training and certification
Senior Associate, Information Security
Senior Associate, Information Security

Publicis Groupe Holdings B.V • Toronto

On-site
CAD 100,000 - 120,000
Senior DevSecOps Analyst
Senior DevSecOps Analyst

Jobtailor • Mississauga

On-site
CAD 110,000 - 170,000