Manager, Security Incident Response

TechAlliance of Southwestern Ontario, London Economic Development Corporation

Toronto

On-site

CAD 80,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

An established industry player is seeking a Security Incident Response Manager to lead their cybersecurity efforts. This pivotal role involves overseeing the incident response lifecycle, managing a team of analysts, and collaborating with various departments to enhance the organization's security posture. The ideal candidate will possess extensive experience in incident response, strong leadership capabilities, and a deep understanding of cybersecurity frameworks. This is an exciting opportunity to make a significant impact on the safety of sensitive information and the overall resilience of the organization. Join a forward-thinking team dedicated to protecting data and clients in a rapidly evolving threat landscape.

Qualifications

  • 5+ years of cybersecurity experience with a focus on incident response.
  • Strong leadership skills and ability to manage major security incidents.

Responsibilities

  • Lead the end-to-end security incident response process and manage communications.
  • Conduct security investigations and collaborate with external partners.

Skills

Incident Response
Cybersecurity
Threat Detection
Digital Forensics
Malware Analysis
Network Security
Project Management
Critical Thinking
Communication Skills

Education

Bachelor's degree in Computer Science
Certifications (GCIH, GCFA, CISSP, CISM, CRISC)

Tools

SIEM Tools
EDR/XDR Platforms
Forensic Tools
SOAR Platforms
Cloud Security (Azure, AWS, GCP)

Job description

We are seeking an experienced Security Incident Response Manager to lead and manage our security incident response function. This role is critical to protecting our business, data, and clients by ensuring rapid, effective, and efficient responses to cybersecurity incidents and threats. The ideal candidate will have deep expertise in the incident response lifecycle, strong leadership skills, and the ability to collaborate across various departments and stakeholders.

As part of our Information Security team, you will manage a team of analysts, lead high-profile investigations, and develop and implement response plans for diverse security incidents. Your work will directly contribute to minimizing risks, safeguarding sensitive information, and enhancing the overall cybersecurity posture of our organization.

What you will do:
  • Develop, lead, and oversee the end-to-end security incident response process, including preparation, detection, analysis, containment, eradication, recovery, and post-incident review.
  • Act as the primary point of contact and coordinator during major security incidents, managing incident communications and escalating as needed.
  • Establish and maintain incident response playbooks, procedures, and runbooks aligned with industry frameworks (NIST, ISO 27035, SANS, etc.).
  • Coordinate with the Security Operations Center (SOC) team, Threat Intelligence, and Vulnerability Management to proactively detect and respond to potential threats.
  • Ensure incidents are properly documented, classified, and reported, and lead root cause analysis (RCA) efforts to identify lessons learned.
  • Regularly conduct tabletop exercises and simulations to assess and improve the organization’s incident response readiness.
Security Investigations and Threat Management
  • Manage and conduct security investigations to determine the cause, scope, and impact of security breaches.
  • Oversee evidence gathering to support investigations, ensuring chain of custody and compliance with legal and regulatory standards.
  • Work with threat intelligence team to analyze and respond to advanced persistent threats (APTs), malware outbreaks, ransomware incidents, and other cyberattacks.
  • Collaborate with external partners, law enforcement, and industry groups to stay informed of emerging threats and incorporate intelligence into incident response processes.
Collaboration and Stakeholder Engagement
  • Act as a liaison between the Security Incident Response Team (SIRT) and business units, IT, Legal, Compliance, Risk, and external vendors.
  • Work closely with internal audit, governance, and risk management teams to ensure alignment with corporate security policies and regulatory requirements.
  • Communicate effectively with senior leadership during high-severity incidents, providing regular updates on impact, response activities, and mitigation plans.
  • Partner with business continuity and disaster recovery teams to ensure seamless integration of incident response with overall organizational resilience.
Process Development and Maturity
  • Continuously enhance and refine the incident response framework to align with evolving threats, business objectives, and regulatory landscapes.
  • Develop and maintain comprehensive incident response policies, standards, and guidelines that address the needs of the business while aligning with global best practices.
  • Establish key performance indicators (KPIs) and metrics to measure the effectiveness and efficiency of the incident response program.
  • Lead initiatives to automate and optimize incident response activities through the integration of SOAR (Security Orchestration, Automation, and Response) platforms and other tools.
Leadership and Team Management
  • Build, mentor, and manage a team of incident responders and analysts, fostering a culture of continuous learning and collaboration.
  • Provide ongoing training and development for the team to ensure they are up-to-date with the latest threat landscapes, tools, and techniques.
  • Foster strong relationships with third-party incident response providers to ensure additional support when required.
What you bring:
  • Bachelor’s degree in computer science, Information Security, or a related field.
  • 5+ years of experience in cybersecurity with at least 3 years in incident response or related roles.
  • Demonstrated experience leading security incident response teams and managing major incidents.
  • Deep understanding of incident response frameworks (NIST 800-61, ISO 27035, MITRE ATT&CK, etc.) and industry best practices.
  • Strong knowledge of threat detection, digital forensics, malware analysis, network security, and endpoint security.
  • Experience in handling cloud-based incidents (Azure, AWS, GCP) and familiarity with cloud security principles.
  • Proficient in SIEM (Security Information and Event Management) tools, EDR/XDR platforms, and forensic tools.
  • Strong project management skills and the ability to manage multiple investigations and priorities simultaneously.
  • Certifications such as GCIH, GCFA, CISSP, CISM, or CRISC are highly desirable.
  • Experience in the insurance or financial services sector is a strong asset.
  • Familiarity with privacy regulations (GDPR, PIPEDA, CCPA) and industry compliance requirements.
  • Experience working with executive leadership and Board-level communications during incidents.
  • Critical thinking and problem-solving under pressure.
  • Excellent communication skills with the ability to explain technical concepts to non-technical audiences.
  • Strong collaboration and interpersonal skills to work effectively across teams and business units.
  • Detail-oriented with a high level of integrity and professionalism.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Operations Lead
Information Security Operations Lead

Jobtailor • Toronto

On-site
CAD 110,000 - 150,000
L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

Hybrid
CAD 90,000 - 120,000
Remote working available
Flex Office work environment
Annual training and certification
Incident Response Senior Consultant
Incident Response Senior Consultant

Jobgether • Canada

Remote
CAD 100,000 - 165,000
Remote work opportunity
Equity opportunities
Professional development
Senior Associate, Information Security
Senior Associate, Information Security

Publicis Groupe Holdings B.V • Toronto

On-site
CAD 100,000 - 120,000
Information Security Manager
Information Security Manager

Insight Global • Toronto

On-site
CAD 100,000 - 120,000
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

Jobtailor • Boisbriand

On-site
CAD 90,000 - 130,000
Cyber Security Analyst
Cyber Security Analyst

koundinyasa Technology Services • Montreal (administrative region)

On-site
CAD 70,000 - 100,000
Manager, Cyber Intelligence Centre
Manager, Cyber Intelligence Centre

Bell Cyber • Mississauga

On-site
CAD 135,000 - 165,000
Information Security Analyst 3 (Cybersecurity Incident Response)
Information Security Analyst 3 (Cybersecurity Incident Response)

Canada Life • Toronto

On-site
CAD 85,000 - 135,000
Career Development
Health & Wellness
Time Off
+3
Incident Coordinator
Incident Coordinator

CyberClan • Canada

On-site
GBP 60,000 - 90,000
Wellness Leave
Birthday Day
Pension