Senior Cybersecurity Specialist - Incident Response

Colonial Group

Toronto

On-site

CAD 90,000 - 120,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

QFG is seeking a Senior Cybersecurity Specialist, Incident Response to lead incident response activities and threat hunting across our corporate environment. You will work with IT and cybersecurity teams to triage alerts, conduct in-depth investigations, and implement containment and remediation using playbooks and SOAR-enabled automation.

This role emphasizes developing and refining detection rules, running tabletop exercises, and reporting on security metrics like MTTD/MTTR.

Qualifications

  • 5+ years of Cybersecurity Incident Response and Threat Hunting experience.
  • Hands-on in detection rule creation and fine-tuning.
  • Experience integrating security tools via APIs for automation and SOAR concepts.
  • Deep investigations with EDR tools (CrowdStrike Falcon) and SIEM (Elastic Security).
  • Forensic triage across Mac, Linux, Windows; multi-OS experience.
  • Strong incident management and communication under pressure.
  • Knowledge of Python/JavaScript.
  • Familiar with NIST CSF and MITRE ATT&CK.

Responsibilities

  • Mentor junior SOC analysts with technical guidance.
  • Monitor, analyze, and report cybersecurity threats.
  • Investigate threat indicators and gather IOC data.
  • Leverage Elastic Security and CrowdStrike for analysis.
  • Execute containment and eradication per playbooks.
  • Coordinate IR with internal teams and third parties.
  • Document timelines, evidence, and post-incident reviews.
  • Maintain and improve IR playbooks and runbooks.

Job description

What’s in it for you as an employee of QFG?
  • Health & wellbeing resources and programs
  • Paid vacation, personal, and sick days for work-life balance
  • Competitive compensation and benefits packages
  • Work-life balance
  • Career growth and development opportunities
  • Opportunities to contribute to community causes
  • Work with diverse team members in an inclusive and collaborative environment

This job posting is for an existing vacancy.

We’re looking for our next Senior Cybersecurity Specialist, Incident Response. Could It Be You?

The Senior Cybersecurity Specialist, Incident Response is a critical contributor to delivering sustainable and measurable results in identifying and responding to cyber threats - safeguarding our company's infrastructure and data. You will be primarily involved in supporting the alert development cycle, triaging and investigating alerts, managing the full incident response lifecycle (investigation, containment, eradication, and recovery) and collecting and tracking metrics for reporting. The Senior Cybersecurity Specialist, Incident Response works alongside internal customers and our vendor support teams to ensure we are utilizing our security tools in accordance with corporate policies and growing business needs. You will work closely with Cybersecurity and IT teams to align priorities and execute plans for new initiatives, as well as contribute to process improvements and build documentation for new tools.

Need more details? Keep reading…

In this role, responsibilities include but are not limited to:

  • Mentoring and providing technical guidance to junior SOC analysts.
  • Monitoring, analyzing and reporting possible cybersecurity attacks.
  • Investigating and performing analysis of threat indicators.
  • Gathering Indicators of compromise and any relevant data to use with threat hunting activities.
  • Leveraging security tools (Elastic, CrowdStrike and more) for analysis to identify malicious activities.
  • Analyzing identified malicious activity to determine Tactics, Techniques and Procedures.
  • Conducting research, analysis and correlate gathered data from various resources to determine the impact of the incident.
  • Executing containment and eradication actions following established playbooks.
  • Participating in on-call and hands-on scheduled shift rotations, including outside of business hours.
  • Coordinating Security Incident Response and investigation with other internal teams and 3rd party providers.
  • Documenting incident timelines, evidence, and actions taken for post-incident review.
  • Performing post-incident reviews and producing lessons-learned reports.
  • Maintaining and improving incident response playbooks and runbooks.
  • Participating in tabletop exercises and IR simulations.
  • Providing proactive security investigations and searches on corporate environments to detect malicious activities.
  • Maintaining up-to-date understanding of security threats, countermeasures, security tools, cloud security and SaaS technologies.
  • Maintaining technical proficiency through training, keeping up with industry best practices, and security frameworks.
  • Communicating investigation findings and risk posture to technical and non-technical stakeholders.
  • Owning and reporting on SOC operational metrics (MTTD, MTTR, alert fidelity).
So are YOU our next Senior Cybersecurity Specialist, Incident Response? You are if you have…
  • 5+ years of relevant experience in performing Cybersecurity Incident Response and Threat Hunting activities in a complex incident management or Security Operations Center environment
  • Hands-on experience in the creation and fine-tuning of detection rules
  • Practical experience integrating security tools via APIs for automation, and familiarity with Security Orchestration, Automation, and Response (SOAR) concepts
  • Deep experience with complex investigations and incident response using EDR tools such as CrowdStrike Falcon and SIEM tools such as Elastic Security (KQL, ESQL, Timeline analysis)
  • Experience with forensic triage (disk, memory, network) and multiple operating systems (Mac, Linux, Windows)
  • Solid experience with building SOC processes, playbooks, SIEM correlation rules, and incident reports
  • Proven experience in incident management and communication under pressure
  • Knowledge of programming languages such as Python, JavaScript and others
  • Knowledge of NIST Cybersecurity Framework, MITRE ATT&CK
  • Knowledge of security products and device monitoring tools including Firewalls, IDS/IPS, Phishing and e-mail security, content filtering, DDoS, WAF, etc.
Additional kudos if you…
  • Hold GCIH, GCED, CCFR, HTB CDSA, GCFA, CHFI or similar relevant certifications
Additional Information…
  • Operating hours for this role are 3 pm to 11 pm, Monday to Friday with on-call scheduled rotations, including weekends
Compensation Information:
  • Base salary range: $90,000 - $120,000
  • The final compensation package will be commensurate with the successful candidate's experience, skills, and geographic location (Canada). It includes a comprehensive benefits plan and a competitive incentive (bonus) program for Full-Time Permanent roles.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Cybersecurity Specialist, Incident Response
Principal Cybersecurity Specialist, Incident Response

Colonial Group • Toronto

Hybrid
CAD 120,000 - 140,000
Comprehensive benefits
Bonus program
Senior Manager, JSOC & Threat Hunting
Senior Manager, JSOC & Threat Hunting

Questrade Financial Group • Toronto

On-site
CAD 170,000 - 185,000
Hybrid work model with 3+ in-office</n
Security Engineer
Security Engineer

Kinvie • Toronto

Hybrid
CAD 115,000 - 130,000
Health benefits
Paid vacation
Hybrid work environment
+1
Senior Security Engineer, Detection and Response
Senior Security Engineer, Detection and Response

Jobgether SRL • Canada

Remote
CAD 137,000 - 171,000
Annual bonus
Health insurance
Remote work stipend
+5
JSOC - Cybersecurity Specialist - Incident Response
JSOC - Cybersecurity Specialist - Incident Response

Community Trust Company • Canada

Hybrid
CAD 81,000 - 101,000
Intermediate Forensics Mechanical Engineer
Intermediate Forensics Mechanical Engineer

j s held • Vancouver

On-site
CAD 90,000 - 115,000
Remote Senior Incident Response Analyst, MDR
Remote Senior Incident Response Analyst, MDR

Sophos • Milton

Remote
CAD 131,000 - 219,000
Bonus eligibility
Comprehensive benefits
Senior Security Operations Analyst, Detection & Response
Senior Security Operations Analyst, Detection & Response

Financeit • Toronto

On-site
CAD 110,000 - 125,000
Hybrid workplace options
Competitive pay and bonus
RRSP matching
+3
L3 SOC Analyst / Incident Responder
L3 SOC Analyst / Incident Responder

act digital • Montreal (administrative region)

On-site
CAD 90,000 - 120,000
Remote working available
Flex Office work environment
Annual training and certification
Cybersecurity Analyst / Incident Response (IR) →
Cybersecurity Analyst / Incident Response (IR) →

Cyberwall Inc • Vaughan

Hybrid
CAD 85,000 - 120,000
Diverse client exposure
Growth opportunities
Collaborative team