Information Security Specialist – Attack Surface Reduction

Jobtailor

Toronto

On-site

CAD 120,000 - 160,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a Senior Threat Hunter to join our Toronto-based security team. You will hunt for TTPs, detect threats, and design mitigations aligned with the MITRE ATT&CK framework across enterprise and cloud environments.

You will leverage threat intel, big data analytics, and automation to build detection logic, dashboards, and playbooks while collaborating with SOC, IR, and security engineering. A strong background in malware reverse engineering and SIEM tooling is essential.

Qualifications

  • Bachelor’s degree in an IT/cyber-related field or equivalent experience.
  • At least 7+ years of cybersecurity experience.
  • 3+ years of experience in malware reverse engineering, threat hunting, DFIR, threat detection, or threat intelligence.
  • Expert knowledge of log management, security analytics, and SIEM platform mechanics.
  • Experience with SIEM, SOAR, EDR, cloud-native tools, and other cybersecurity toolsets.
  • Advanced knowledge of Endpoint and Identity/IAM architectures, operations, and investigations.
  • Proficiency with Splunk ES, CrowdStrike, Logscale, Defender for Endpoint, MS Sentinel, and Wiz Defend.
  • Deep understanding of coding, scripting, and APIs for investigations, automation, and integrations.
  • Ability to identify and generate detection logic.
  • Experience writing analytics queries, threat visualization dashboards, and large data analysis using Splunk, Logscale, KQL, and syslog.
  • Strong knowledge of network protocols and common services.
  • Extensive knowledge of Windows, Mac, and Linux endpoints.
  • Excellent written and oral communication skills.
  • Organizational and self-directing skills.
  • Ideal candidates have at least two certifications from listed cyber, endpoint/forensic, cloud, penetration-testing, or coding/SIEM categories.

Responsibilities

  • Hunt for TTPs and mitigations aligned to MITRE ATT&CK.
  • Identify threats and gaps; produce detection and mitigation recommendations.
  • Participate in proactive attack surface reduction across enterprise and cloud.
  • Use threat intelligence and logs to detect threats.
  • Develop methodologies to identify adversary tools and techniques.
  • Produce metrics and dashboards identifying threats and malware.
  • Tune detection infrastructure with tech teams.
  • Document best practices for hunting playbooks and procedures.
  • Serve as SME in host- and network-based hunting analysis.
  • Collaborate with intelligence, SOC, IR, and security engineering teams.
  • Review processes; identify improvement opportunities.
  • Influence behavior to reduce risk and strengthen security culture.
  • Monitor emerging issues and changes to security landscape.

Skills

Threat Hunting
Malware Reverse Engineering
SIEM Platform Mechanics
Splunk ES
Endpoint Security
Log Management
Security Analytics
Coding
Scripting
APIs
Analytics Queries
Data Analysis
Network Protocols
Operating Systems

Education

Bachelor's degree

Tools

Splunk ES
CrowdStrike
Logscale
Defender for Endpoint
MS Sentinel
Wiz Defend
Netskope
Akamai
AppOmni
Qualys
Symantec DLP

Job description

  • Hunt for TTPs, threats, risks, and vulnerabilities aligned to the MITRE ATT&CK framework using internal and external intelligence data
  • Identify threats, risks, and security control gaps and produce detection and mitigation recommendations to reduce the bank’s attack surface
  • Participate in proactive attack surface reduction operations across enterprise and cloud environments
  • Use threat intelligence, anomalous log analysis, and brainstorming-session results to detect and mitigate threats
  • Develop methodologies to identify adversary tools, techniques, and procedures
  • Produce metrics and dashboards identifying potential threats, suspicious or anomalous activity, and malware
  • Tune detection infrastructure with technology teams to identify emerging threats
  • Document best practices for hunting playbooks, procedures, and courses of action
  • Serve as a subject matter expert in host-based and network-based hunting analysis
  • Collaborate with intelligence, SOC, incident response, and security engineering teams
  • Review internal processes and activities and identify improvement opportunities
  • Influence behavior to reduce risk and strengthen the enterprise information security culture
  • Monitor emerging issues, industry trends, and relevant changes to the security landscape
Requirements
  • Bachelor’s degree in an IT/cyber-related field or equivalent experience
  • At least 7+ years of cybersecurity experience
  • 3+ years of experience in malware reverse engineering, threat hunting, DFIR, threat detection, or threat intelligence preferred
  • Expert knowledge of log management, security analytics, and SIEM platform mechanics
  • Experience with SIEM, SOAR, EDR, cloud-native tools, and other cybersecurity toolsets
  • Advanced knowledge of Endpoint and Identity/IAM architectures, operations, and investigations
  • Proficiency with Splunk ES, CrowdStrike, Logscale, Defender for Endpoint (MDE), MS Sentinel, and Wiz Defend
  • Hands-on experience with Netskope, Akamai, AppOmni, Qualys, and Symantec DLP is optional/good to have
  • Deep understanding of coding, scripting, and APIs for investigations, automation, and integrations
  • Ability to identify and generate detection logic
  • Experience writing and implementing complex analytics queries, threat visualization dashboards, and large-volume data analysis using tools such as Splunk, Logscale, KQL, and syslog
  • Strong knowledge of network protocols, ports, and common services including TCP/IP, HTTP/S, DNS, FTP, SMTP, and Active Directory
  • Extensive knowledge of Windows, Mac, and Linux endpoints, operating systems, services, file systems, and agents
  • Excellent written and oral communication skills
  • Organizational and self-directing skills
  • Ability to initiate, coordinate, prioritize, and complete responsibilities with minimal supervision
  • Ideal/preferred candidates have at least two certifications from the listed general cyber, endpoint/forensic, cloud, penetration-testing, or coding/scripting/SIEM certifications
Core Competencies

Demonstrates expertise in threat hunting, risk assessment, and security control gap analysis, utilizing the MITRE ATT&CK framework and advanced cybersecurity tools. Proficient in developing detection methodologies, producing metrics, and collaborating with cross-functional teams to enhance the security posture of the organization.

Highest-signal resume keywords
  • Threat Hunting
  • Malware Reverse Engineering
  • SIEM Platform Mechanics
  • Splunk ES
  • Endpoint Security
ATS Optimization Keywords
Hard Skills
  • Threat Detection
  • Log Management
  • Security Analytics
  • Coding
  • Scripting
  • APIs
  • Complex Analytics Queries
  • Data Analysis
  • Network Protocols
  • Operating Systems
Soft Skills
  • Excellent Communication Skills
  • Organizational Skills
  • Self-Directing Skills
Industry Keywords
  • Cybersecurity
  • Threat Intelligence
  • Incident Response
  • Cloud Security
  • Forensics
Tools & Technologies
  • SIEM
  • SOAR
  • EDR
  • Splunk
  • CrowdStrike
  • Logscale
  • Defender for Endpoint
  • MS Sentinel
  • Wiz Defend
  • Netskope
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Use Case Developer
Cyber Use Case Developer

Jobtailor • Toronto

On-site
CAD 90,000 - 130,000
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Jobtailor • Boisbriand

On-site
CAD 90,000 - 130,000
Information Security Operations Lead
Information Security Operations Lead

Jobtailor • Toronto

On-site
CAD 110,000 - 150,000
Senior Software Developer
Senior Software Developer

Jobtailor • Ottawa

On-site
CAD 120,000 - 180,000
Cyber Security Analyst
Cyber Security Analyst

koundinyasa Technology Services • Montreal (administrative region)

On-site
CAD 70,000 - 100,000
Senior Software Engineer
Senior Software Engineer

Jobtailor • Halifax

On-site
CAD 90,000 - 130,000
Cybersecurity Analyst
Cybersecurity Analyst

Spait Infotech • Toronto

On-site
CAD 60,000 - 90,000
Security Designer
Security Designer

Jobtailor • Quebec

On-site
CAD 90,000 - 130,000
Security Operations Specialist
Security Operations Specialist

Jobtailor • Montreal (administrative region)

On-site
CAD 90,000 - 130,000
Senior DevSecOps Analyst
Senior DevSecOps Analyst

Jobtailor • Mississauga

On-site
CAD 110,000 - 170,000