Principal Cybersecurity Specialist, Incident Response

Colonial Group

Toronto

Hybrid

CAD 120,000 - 140,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Comprehensive benefits
Bonus program

Job summary

QFG is seeking a Principal Cybersecurity Specialist, Incident Response in a hybrid Canada-based role to lead incident response, threat hunting, and SOC process improvements. You will mentor the SOC team, coordinate containment and eradication, and drive post-incident reviews while collaborating with IT and vendor teams.

The role emphasizes a strong command of EDR and SIEM tools, incident timelines, and cross-functional communication with senior leadership.

Qualifications

  • 8+ years of Cybersecurity Incident Response and Threat Hunting experience in a complex environment.
  • Experience designing and optimizing detection rules and detection-as-code frameworks.
  • Hands-on automation and SOAR workflows integration with security tools via APIs.

Responsibilities

  • Mentor and elevate the SOC team's technical capabilities.
  • Monitor, analyze and report potential cybersecurity attacks.
  • Investigate and analyze threat indicators; gather IOCs for threat hunts.
  • Lead containment and eradication efforts during high-severity incidents.
  • Participate in on-call rotations, including after-hours.

Skills

Incident Response
Threat Hunting
SOAR automation
Python
JavaScript
Cloud security monitoring

Tools

Elastic Security
CrowdStrike Falcon
SIEM (Elastic)

Job description

What’s in it for you as an employee of QFG?
  • Health & wellbeing resources and programs
  • Paid vacation, personal, and sick days for work-life balance
  • Competitive compensation and benefits packages
  • Work-life balance in a hybrid environment with at least 3 days in office
  • Career growth and development opportunities
  • Opportunities to contribute to community causes
  • Work with diverse team members in an inclusive and collaborative environment

This job posting is for an existing vacancy.

We’re looking for our next Principal Cybersecurity Specialist, Incident Response. Could It Be You?

The Principal Cybersecurity Specialist, Incident Response is a critical contributor to delivering sustainable and measurable results in identifying and responding to cyber threats - safeguarding our company's infrastructure and data. You will be primarily involved in leading the alert development cycle, triaging and investigating alerts, managing the full incident response lifecycle (investigation, containment, eradication, and recovery) and collecting and tracking metrics for reporting. The Principal Cybersecurity Specialist, Incident Response works alongside internal customers and our vendor support teams to ensure we are utilizing our security tools in accordance with corporate policies and growing business needs. You will work closely with Cybersecurity and IT teams to align priorities and execute plans for new initiatives, as well as drive process improvements and establish documentation for new tools.

Need more details? Keep reading…

In this role, responsibilities include but are not limited to:

  • Mentoring and elevating the technical capabilities of the SOC team.
  • Monitoring, analyzing and reporting possible cybersecurity attacks.
  • Investigating and performing analysis of threat indicators.
  • Gathering Indicators of compromise and any relevant data to use with threat hunting activities.
  • Leveraging security tools (Elastic, CrowdStrike and more) for analysis to identify malicious activities.
  • Analyzing identified malicious activity to determine Tactics, Techniques and Procedures.
  • Conducting research, analysis and correlating gathered data from various resources to determine the impact of the incident.
  • Leading containment and eradication efforts, making critical decisions during high-severity incidents.
  • Participating in on-call and hands-on scheduled shift rotations, including outside of business hours.
  • Leading Security Incident Response and serving as the escalation point for complex investigations across internal teams and third party providers.
  • Documenting incident timelines, evidence, and actions taken for post‑incident review.
  • Leading post‑incident reviews and driving continuous improvement from lessons learned.
  • Defining and continuously improving the SOC's incident response playbooks, runbooks, and detection strategy.
  • Designing and leading tabletop exercises and IR simulations.
  • Coordinating and running proactive investigations and threat hunts across corporate environments and detecting malicious activities.
  • Maintaining up‑to‑date understanding of security threats, countermeasures, security tools, cloud security and SaaS technologies.
  • Setting the standard for technical proficiency; evaluating and recommending tools, techniques, and methodologies for the team.
  • Presenting investigation, incident response findings and strategic recommendations to senior leadership and executive stakeholders.
  • Defining, owning, and reporting on SOC operational metrics (MTTD, MTTR, alert fidelity) and using data to drive strategic improvements.
So are YOU our next Principal Cybersecurity Specialist, Incident Response?

You are if you have…

  • 8+ years of relevant experience in performing and leading Cybersecurity Incident Response and Threat Hunting activities in a complex incident management or Security Operations Center environment
  • Extensive experience designing, implementing and optimizing detection rules and detection-as-code frameworks
  • Demonstrated expertise integrating security tools via APIs for automation, and hands‑on experience implementing Security Orchestration, Automation, and Response (SOAR) workflows
  • Deep expertise leading complex, multi-vector investigations and incident response using EDR tools such as CrowdStrike Falcon and SIEM tools such as Elastic Security (KQL, ESQL, Timeline analysis)
  • Advanced experience with forensic triage (disk, memory, network) and multiple operating systems (Mac, Linux, Windows)
  • Proven track record of designing and maturing SOC processes, playbooks, detection strategies, SIEM correlation rules, and incident reports
  • Proven ability to lead incident management for high‑severity incidents, with excellent communication under pressure
  • Proficiency in programming languages such as Python, JavaScript and others for security automation and tooling development
  • Deep understanding of NIST Cybersecurity Framework, MITRE ATT&CK, and ability to apply them to detection engineering and threat modeling
  • Comprehensive understanding of security products and device monitoring tools including Firewalls, IDS/IPS, Phishing and e-mail security, content filtering, DDoS, WAF, and more
  • Demonstrated experience mentoring and developing technical skills across a security team
  • Strong ability to translate technical findings into strategic recommendations for leadership
  • Experience with cloud‑native security monitoring (GCP, AWS, Azure)
Additional kudos if you…
  • Hold GCIH, GCED, CCFR, HTB CDSA, GCFA, CHFI, GREM, OSCP, CISSP or similar relevant certifications
Additional Information…
  • Operating hours for this role are standard office hours, Monday to Friday with on‑call scheduled rotations, including weekends and evenings
Compensation Information:
  • Base salary range: $120,000 - $140,000
  • The final compensation package will be commensurate with the successful candidate's experience, skills, and geographic location (Canada). It includes a comprehensive benefits plan and a competitive incentive (bonus) program for Full-Time Permanent roles.

#LI-NP1

#LI-Hybrid

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Specialist - Incident Response
Senior Cybersecurity Specialist - Incident Response

Colonial Group • Toronto

On-site
CAD 90,000 - 120,000
Senior Manager, JSOC & Threat Hunting
Senior Manager, JSOC & Threat Hunting

Questrade Financial Group • Toronto

On-site
CAD 170,000 - 185,000
Hybrid work model with 3+ in-office</n
Intermediate Forensics Mechanical Engineer
Intermediate Forensics Mechanical Engineer

j s held • Vancouver

On-site
CAD 90,000 - 115,000
L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

On-site
CAD 90,000 - 120,000
Remote working available
Flex Office work environment
Annual training and certification
JSOC - Cybersecurity Specialist - Incident Response
JSOC - Cybersecurity Specialist - Incident Response

Community Trust Company • Canada

Hybrid
CAD 81,000 - 101,000
Cybersecurity Analyst – Tier 2
Cybersecurity Analyst – Tier 2

Vanderlande Industries GmbH • Vancouver

On-site
CAD 90,000 - 115,000
Senior Security Engineer, Detection and Response
Senior Security Engineer, Detection and Response

Jobgether SRL • Canada

Remote
CAD 137,000 - 171,000
Annual bonus
Health insurance
Remote work stipend
+5
Incident Response Manager
Incident Response Manager

CyberClan • Canada

Remote
GBP 75,000 - 91,000
Health Insurance
Dental Insurance
Remote Work
+1
Senior Security Operations Analyst, Detection & Response
Senior Security Operations Analyst, Detection & Response

Financeit • Toronto

On-site
CAD 110,000 - 125,000
Hybrid workplace options
Competitive pay and bonus
RRSP matching
+3
Remote Senior Incident Response Analyst, MDR
Remote Senior Incident Response Analyst, MDR

Sophos • Milton

Remote
CAD 131,000 - 219,000
Bonus eligibility
Comprehensive benefits