Manager SOC - Cyber Security

KPMG International

Toronto

On-site

CAD 74,000 - 123,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

KPMG in Canada is seeking a dynamic Senior Cyber Security professional to join our Cyber Security Services team in Toronto. You will lead incident response efforts, guide SOC analysts, and help advance threat detection and cloud security across services.

The role emphasizes hands-on security operations, governance, and collaboration with CSIRT, CTI, and engineering teams to deliver end-to-end cyber security transformations.

Qualifications

  • Requires 7+ years in a SOC or security operations role.
  • Certifications such as CISSP, CISM, SANS, CISA, and CompTIA security certs are preferred.
  • Hands-on experience with SIEM/SOAR tech and Microsoft Defender endpoints.

Responsibilities

  • Serve as primary incident contact for high-severity events with CSIRT collaboration.
  • Evaluate escalated L2 SOC issues for business risk impact.
  • Review logs and refine threat-detection rules and alerts.
  • Coordinate with SIEM Engineers to improve alert coverage.
  • Develop and maintain incident response playbooks and consider automation.
  • Collaborate with CTI teams to enhance threat detection using TTPs.
  • Analyze security events and tickets to improve incident management.
  • Stay updated on threats, tools, and cloud security advancements.
  • Track incidents against MITRE ATT&CK and other frameworks.
  • Provide technical leadership and mentorship to analysts.

Skills

Incident response
SOC operations
Threat detection
Leadership
Communication
Azure Sentinel

Education

CISSP
CISM
SANS
CISA
CompTIA Security+
CompTIA CySA+
GIAC

Tools

Microsoft Sentinel
SIEM/SOAR
Microsoft Defender Endpoint
CSPM/CWP
EDR/XDR tools

Job description

At KPMG in Canada, our people bring their unique perspectives to Canada’s most important challenges. Here, you can build momentum that reaches beyond our business, develop skills for the future, and take ownership of your career with support at every stage. Join a firm where your career can make a difference.

You’ve got big plans. We have opportunities to match, and we’re committed to empowering you to become a better you, no matter what you do. When you join KPMG, you’ll be one of over 227,000 professionals providing audit, tax, advisory and business enablement services across 146 countries.

With the support to do things differently, grow personally and professionally and bring your whole self to work, there’s no limit to the impact you can make. Let’s do this! The opportunity We are looking for a dynamic, experienced Cyber security professional to join our growing Cyber Security Services team as Senior Consultant KPMG’s leading cyber security practice provides a comprehensive suite of cyber security services, from cyber governance, strategy, defense and response, through to complete end-to-end cyber security transformation services.

This is an exciting opportunity for talented, energetic people to join a practice that is experiencing significant growth. We are looking for candidates who have demonstrated academic, business and technical excellence, strong all-around capabilities, and fit with our culture. Individuals who can work in a dynamic, fluid and entrepreneurial environment will excel, and will find a wide range of opportunities within our growing practice. It is an excellent opportunity for those that are looking to work in a firm and department with great career progression opportunities and wanting to be part of building a premier cyber consulting team.

Value to the Team:

I contribute a substantial amount of practical experience to the team, specifically in the field of cybersecurity and incident response. My adeptness in Azure Sentinel, combined with my proficiency in KQL queries and Threat Use Cases Logic, establishes me as a significant resource. I excel in Incident Response and possess the capability to guide a team of SOC experts as an Incident Commander. Furthermore, I am skilled at clearly communicating the root cause and containment measures to external clients.

I am well-versed in playbook automation, adept at crafting effective threat hunting queries, and familiar with EDR/XDR toolsets. Moreover, my background includes hands-on experience in tabletop exercises and collaboration with CSIRT teams. Please note that this role may involve off-hours shift coverage, rotations, or on-call duties.

What you will do
  • - Serve as the primary point of contact during high-severity incidents, ensuring swift containment and resolution in collaboration with the CSIRT team, if necessary.
  • - Assess escalated issues from L2 SOC analysts to determine increased risk to the business.
  • - Review log data against security technology rules, proposing enhancements to threat detection.
  • - Collaborate with SIEM Engineers to fine-tune security events and improve alert detection rates.
  • - Develop and maintain incident response playbooks, identifying areas for improvement and suggesting task automation.
  • - Work closely with CTI teams to enhance our threat detection, suggesting threat use cases development based on Tactics, Techniques, Procedures (TTPs).
  • - Analyze critical events and security tickets to evaluate the effectiveness of incident management processes and suggest improvement plans.
  • - Stay updated on security threats, countermeasures, security tools, and advancements in Cloud Security and SaaS technologies.
  • - Track incidents against frameworks such as SANS and MITRE ATT&CK.
  • - Provide technical and thought leadership within the SOC, guiding and teaching other analysts.
What you bring to the role
  • Over 7 years of highly technical experience in a SOC environment.
  • - Relevant certifications such as CISSP, CISM, SANS, CISA, CompTIA Security+, or CompTIA CySA+, GIAC.
  • - Hands‑on experience with Microsoft Sentinel or other SIEM and SOAR technologies.
  • - Proficient in Microsoft Defender Endpoint, CSPM/CWP, or similar technologies, with a focus on vulnerability assessment and recommendation.
  • - Experience in malware analysis and reverse engineering.
  • - Business development expertise, including research, analysis, and proposal writing.
  • - Evaluation of control frameworks, risk assessment, and opportunities for enhancement.
  • - Enterprise asset lifecycle management knowledge, including patch management, vulnerability management, security architecture, and endpoint management.
  • - Expertise in cloud transformation, architecture, and security operations.
  • - Leadership experience in managing complex projects.
  • - Strong communication skills, effectively presenting strategies, solutions, and insights to stakeholders.
  • - Leadership role experience, providing mentorship and knowledge sharing to the team and junior/intermediate analysts.
KPMG Ontario Region Pay Range Information

The expected base salary range for this position is $73,500 to $122,500 and may be eligible for bonus awards. The determination of an applicant’s base salary within this range is based on the individual’s location, skills & competencies, and unique qualifications. In addition, KPMG offers a comprehensive and competitive Total Rewards program.

Providing you with the support you need to be at your best
Our Values, The KPMG Way

Integrity, we do what is right |Excellence, we never stop learning and improving |Courage, we think and act boldly | Together, we respect each other and draw strength from our differences |For Better, we do what matters

KPMG in Canada is a proud equal opportunities employer and we are committed to creating a respectful, inclusive and barrier-free workplace that allows all of our people to reach their full potential. A diverse workforce is key to our success and we believe in bringing your whole self to work. We welcome all qualified candidates to apply and hope you will choose KPMG in Canada as your employer of choice.

Adjustments and accommodations throughout the recruitment process

At KPMG, we are committed to fostering an inclusive recruitment process where all candidates can be themselves and excel. We aim to provide a positive experience and are prepared to offer adjustments or accommodations to help you perform at your best. Adjustments (informal requests), such as extra preparation time or the option for micro breaks during interviews, and accommodations (formal requests), such as accessible communication supports or technology aids, are tailored to individual needs and role requirements. You will have an opportunity to request an adjustment or accommodation at any point throughout the recruitment process. If you require support, please contact KPMG’s Employee Relations Service team by calling 1-888-466-4778.

AI Usage

Weembrace the use of artificial intelligence (AI) to enhance the candidate experience and streamline our recruitment processes. AI tools may help with organizing applications or surfacing relevant qualifications. However, no hiring decisions are made using AI. Every hiring decision is made by our hiring managers and recruitment professionals, who are equipped with training that empowers them to use these tools responsibly. AI technologies used in our recruitment process undergo detailed risk assessments, including security and privacy requirements, that align with KPMG’s Trusted AI framework.

We believe technology should empower human judgment, not replace it. It’s one of the many ways we’re delivering on our vision of being a technology-first, people-driven firm.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Manager, Major Projects Advisory
Senior Manager, Major Projects Advisory

KPMG International • Toronto

On-site
CAD 140,000 - 190,000
Enterprise Architect, AI Engineering – Security & Compliance
Enterprise Architect, AI Engineering – Security & Compliance

KPMG International • Toronto

On-site
CAD 130,000 - 180,000
Consultant, Regulatory Compliance (Regulatory and Risk Advisory)
Consultant, Regulatory Compliance (Regulatory and Risk Advisory)

KPMG International • Toronto

On-site
CAD 57,000 - 84,000
Administrative Assistant, Department of Professional Practice (12 months contract)
Administrative Assistant, Department of Professional Practice (12 months contract)

KPMG International • Toronto, Oakville, Vaughan

Hybrid
CAD 47,000 - 72,000
Solution Integration Manager
Solution Integration Manager

KPMG International • Toronto, Calgary, Vancouver, Halifax

On-site
CAD 78,000 - 137,000
Total Rewards program
HR Governance & Quality Manager
HR Governance & Quality Manager

KPMG International • Toronto

On-site
CAD 74,000 - 111,000
Partner Administrative Assistant/Receptionist- 12 Month Contract
Partner Administrative Assistant/Receptionist- 12 Month Contract

KPMG International • Kingston

On-site
CAD 47,000 - 72,000
Senior Manager Valuations
Senior Manager Valuations

Cari • Canada

On-site
CAD 110,000 - 150,000
Partner Administrative Assistant, Family Office
Partner Administrative Assistant, Family Office

KPMG International • Oakville

On-site
CAD 47,000 - 65,000
Resource Management Lead, Public Audit (Part Time Position)
Resource Management Lead, Public Audit (Part Time Position)

KPMG International • Toronto

On-site
CAD 90,000 - 130,000