Senior Incident Response Analyst (Global Security)

Socket.dev

Toronto

On-site

CAD 90,000 - 140,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

The Royal Bank of Canada is seeking a Senior Incident Response Analyst to serve as the primary contact for Security Operations Centre management regarding security incidents as part of Blue team operations. You will support team members with critical incidents impacting RBC users, systems, infrastructure, and resources.

You’ll play a key role in safeguarding RBC through detailed investigations, coordinating remediation efforts across multiple teams, and drive security incidents to timely and

Qualifications

  • Bachelor's degree in Computer Science, IT, or related discipline.
  • 2+ years of cyber security incident response experience / Blue Team experience.
  • Advanced log analysis and SIEM query capabilities.

Responsibilities

  • Global accountability to respond to critical security incidents/events providing accurate and timely reporting to Global Security Leadership.
  • Provide 24/7 support for security incidents impacting mission critical business and IT infrastructure, including supporting global incident management and response, remediation, and reporting
  • Perform log review and analysis, examining both direct and collector-sourced logs
  • Collaborate with DevOps and other technical teams to execute complex remediation activities, including software patching and system re-imaging
  • Provide postmortem reporting for leadership detailing security vulnerabilities, technology gaps, shortcomings or miscellaneous security issues.
  • Maintain timely communication with the CSIRT extended teams

Skills

Security incident response
Log analysis
SIEM queries
Incident coordination
Clear communication

Education

Bachelor's degree in Computer Science or related field

Tools

SIEM tools

Job description

Job Description
What is the Opportunity?

The Senior Incident Response Analyst, will serve as the primary point of contact for Security Operations Centre management regarding security incidents as part of Blue team operations. You will support team members with critical incidents impacting RBC users, systems, infrastructure, and resources.

You’ll play a key role in safeguarding RBC through detailed investigations, coordinating remediation efforts across multiple teams, and drive security incidents to timely and effective resolution while prioritizing accuracy and thoroughness.

Inthisrole,afterhoursoncallsupport(rotationalbasis)isrequired.
What will you do?
  • Global accountability to respond to critical security incidents/events providing accurate and timely reporting to Global Security Leadership.
  • Provide 24/7 support for security incidents impacting mission critical business and IT infrastructure, including supporting global incident management and response, remediation, and reporting
  • Perform log review and analysis, examining both direct and collector-sourced logs
  • Assess the effectiveness of secondary security controls and determine the scope, impact, and urgency of cyber incidents
  • Address common attack vectors, particularly email based threats (phishing, malicious links, software installation)
  • Collaborate with DevOps and other technical teams to execute complex remediation activities, including software patching and system re-imaging
  • Provide postmortem reporting for leadership detailing security vulnerabilities, technology gaps, shortcomings or miscellaneous security issues.
  • Conduct distributed security incident reviews with teams as determined by management
  • Responsible for driving to resolution security incidents in a timely and effective manner.
  • Maintain timely communication with the Computer Security Incident Response Team (CSIRT) extended teams
  • Ensure global compliance with Enterprise standards regarding security incident response and related findings
  • Drive security incidents to timely and effective resolution while prioritizing accuracy over speed
What do you need to succeed?
Must have
  • Bachelor's degree in Computer Science, IT, or related discipline
  • 2+ years of cyber security incident response experience / Blue Team experience
  • Demonstrated experience conducting investigations for security-related events in a complex Incident Management or Security Operations Center environment
  • Advanced log analysis and SIEM query capabilities
  • Experience investigating security incidents across complex network environments
  • Strong operating system platform knowledge: Windows, Mac, UNIX, and Linux
  • Excellent written and verbal communication skills
  • Ability to work effectively across multiple teams and departments
  • Thorough understanding of Security Information and Incident Management methodologies
  • Strong problem solving and analytical skills
Nice to Have
  • Information security certifications (CISSP, GCIA, GCIH, GREM, CEH)
  • Malware analysis and digital forensics experience
  • Penetration testing experience or adjacent security testing background
  • Vulnerability assessment experience
What’s in it for you?

We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.

  • A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable
  • Leaders who support your development through coaching and managing opportunities
  • Ability to make a difference and lasting impact
  • Work in a dynamic, collaborative, progressive, and high-performing team
  • Opportunities to do challenging work
  • Opportunities to take on progressively greater accountabilities

#LI-POST

#TECHPJ

Job Skills

Business Perspective, Critical Thinking, Decision Making, Detail-Oriented, Forensic Computing, Group Problem Solving, Information Security Operation Center (ISOC), IT Incident Management, Security Information and Event Management (SIEM), Threat Management

Additional Job Details

Address: 16 YORK ST:TORONTO

City: Toronto

Country: Canada

Work hours/week: 37.5

Employment Type: Full time

Platform: TECHNOLOGY AND OPERATIONS

Job Type: Regular

Pay Type: Salaried

Posted Date: 2026-09-11

Application Deadline: 2026-09-25

Note

Applications will be accepted until 11:59 PM on the day prior to the application deadline date above

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Incident Response Analyst (Global Security)
Senior Incident Response Analyst (Global Security)

RBC • Toronto

On-site
CAD 90,000 - 120,000
Senior Security Specialist - Cloud (Global Security)
Senior Security Specialist - Cloud (Global Security)

RBC • Toronto

Hybrid
CAD 120,000 - 180,000
Total Rewards program with bonuses and
Annual training budget
Coaching & development
+3
Senior Security Specialist - Cloud (Global Security)- EN
Senior Security Specialist - Cloud (Global Security)- EN

RBC • Montreal (administrative region)

Hybrid
CAD 95,000 - 130,000
Total Rewards Program (bonuses, stock)
Annual training budget
Hybrid-remote flexibility
+1
Senior Endpoint Security Operations Analyst (Global Security)
Senior Endpoint Security Operations Analyst (Global Security)

RBC • Toronto

On-site
CAD 90,000 - 130,000
Total Rewards Program
Flexible benefits
Work-life balance
+1
Senior Security Specialist - Attack Path Management (Global Security)
Senior Security Specialist - Attack Path Management (Global Security)

Socket.dev • Toronto

Hybrid
CAD 110,000 - 170,000
Flexible work/life balance
Hybrid-remote working environment
Bonuses and stock where applicable
+1
Senior Information and Data Security Analyst (Global Security)
Senior Information and Data Security Analyst (Global Security)

RBC • Toronto

On-site
CAD 120,000 - 170,000
Bonuses and flexible benefits
Stock where applicable
Flexible work/life balance
Analyst, Global Physical Security Operations Center (Global Security)
Analyst, Global Physical Security Operations Center (Global Security)

Socket.dev • Vancouver

Hybrid
CAD 90,000 - 120,000
Bonuses
Stock where applicable
Flexible benefits
+1
Analyst, Global Physical Security Operations Center (Global Security)
Analyst, Global Physical Security Operations Center (Global Security)

RBC • Vancouver

Hybrid
CAD 70,000 - 90,000
Total Rewards Program
Career development opportunities
Senior Security Specialist - Attack Path Management (Global Security)
Senior Security Specialist - Attack Path Management (Global Security)

RBC • Vancouver

On-site
CAD 110,000 - 150,000
Total rewards program
Annual training budget
Hybrid-remote work environment
+2
Cyber Controls Assurance Analyst (Global Security)
Cyber Controls Assurance Analyst (Global Security)

Socket.dev • Toronto

On-site
CAD 90,000 - 120,000
Total rewards program
Stock options
Flexible benefits
+2