Senior Security Detection Engineer (Global Security)

Socket.dev

Toronto

On-site

CAD 120,000 - 160,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Total rewards program
Flexible work options
World-class training

Job summary

RBC is seeking a Senior Security Detection Engineer in Toronto to provide SME support for the Detection Engineering & Automation team within Global Cyber Security. You will help develop and automate security use cases to improve threat detection and response.

You will partner with technology and application teams, build runbooks, tune SIEMs, and drive a maturing security monitoring program with metrics and cross-team collaboration.

Qualifications

  • 2–5 years of industry experience.
  • Experience in cloud environments (AWS, Azure, GCP, OCP).
  • Intermediate Python experience.
  • Experience building detections in SIEM.
  • Experience with automation in SOAR.
  • Background in IT, Engineering, Cybersecurity or equivalent.
  • Demonstrated technical leadership; SOC experience.
  • Understanding of security operations and threat landscape.
  • Strong networking and enterprise IT knowledge.

Responsibilities

  • Provide SME support for cyber use cases in security monitoring.
  • Collaborate with tech partners to strengthen security use cases.
  • Develop runbooks aligned with security operations processes.
  • Facilitate log ingestion and use case development in SIEM.
  • Review and tune use cases; propose improvements.
  • Maintain communication with security groups and SOC leadership.
  • Develop processes to mature the program.
  • Provide operational metrics and reports as needed.

Skills

Python
Cloud environments
SOC operations
SIEM knowledge
Threat detection
Automation

Education

Bachelor's degree in IT/Cybersecurity or equivalent

Tools

SIEM platforms
SOAR platforms

Job description

Job Description
What is the Opportunity?

The role of the Senior Security Detection Engineer is to provide specialized subject matter expertise for the Detection Engineering & Automation (DEA) team, for RBC's Global Cyber Security. This is a key technical role supporting mission critical enterprise network security operations and IT services protection. This role will drive development using automation to new or existing security use cases to reduce the overall mean time to detect and respond to incidents.

With your proven experience, collaboratively lead our RBC technology and application partners to develop and implement mission critical cyber use cases for security monitoring supporting security operations and Security Operations Centre capabilities.

What will you do?
  • Provide global accountability to provide technical and subject matter expertise supporting cyber uses cases developed from security systems and infrastructure for security monitoring.
  • Work with RBC technology and/or application partners (Cybersecurity, Technology Infrastructure, SOC) to develop and strengthen use cases for continuous security monitoring.
  • Develop runbooks for those use cases that align with security operations processes and streamline the incident investigation and response tasks.
  • Work with Defensive Threat Operations Correlation Engineering to facilitate log ingestion and use case development in our SIEM platforms.
  • Periodically review use case library, perform attestation on existing use cases, participate in tuning discussions/activities and provide improvement recommendations where necessary/possible.
  • Develop and maintain lines of communication with various security groups, Security Operations Centre leadership and technology stakeholders
  • Develop processes to support a maturing program
  • Provide operational metrics and reports as needed
What do you need to succeed?
Must have:
  • 2 to 5 years of industry experience.
  • Experience in cloud environments (AWS, Azure, GCP, OCP)
  • Intermediate experience with Python.
  • Experience with building detections in SIEM.
  • Experience with automation in SOAR.
  • Educational background in IT, Engineering, Cybersecurity and/or equivalent relevant experience
  • Demonstrated technical leadership ability
  • In-depth understanding of Security Operations and Security Technologies, with previous experience working in a SOC environment
  • Understanding of common exploitation techniques and awareness of new threats
  • Strong analytical and complex problem-solving skills
  • Expert understanding of SIEM technology and operations
  • Strong Networking and Enterprise IT Infrastructure knowledge with TCP/IP packet level knowledge
Nice-to-have:
  • Certifications in information security (GCIH, GCSA, GPCS, GCTD, GCFR)
  • Certifications in cloud platforms (AWS, Azure, GCP, or OCP)
  • Experience in working within a large, global financial services company.
  • A good understanding of modern, cloud centric architectures and DevOps principles.
What’s in it for you?

We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.

  • A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable
  • Leaders who support your development through coaching and managing opportunities
  • Ability to make a difference and lasting impact
  • Work in a dynamic, collaborative, progressive, and high-performing team
  • A world-class training program in financial services
  • Flexible work/life balance options
  • Opportunities to do challenging work

#techpj

#LI-post

Job Skills

Cloud Software, Communication, Cross-Departmental Collaboration, Cyber Operations, Cyber Security Management, Decision Making, Detail-Oriented, Group Problem Solving, High Impact Communication, Information Security Management, Information Technology Security, Network Security Operations, Security Automation, Security Operations, SIEM Tools, Strategic Thinking, Threat Detection, Threat Monitoring, Use Case Documentation

Additional Job Details

Address: 16 YORK ST:TORONTO

City: Toronto

Country: Canada

Work hours/week: 37.5

Employment Type: Full time

Platform: TECHNOLOGY AND OPERATIONS

Job Type: Regular

Pay Type: Salaried

Posted Date: 2026-03-25

Application Deadline: 2026-08-28

Note: Applications will be accepted until 11:59 PM on the day prior to the application deadline date above

Our Employment Opportunities

At RBC, we are guided by living shared values of Client First, Integrity, Collaboration, Respect and Excellence and winning together as One RBC. We believe an inclusive workplace that has diverse perspectives is core to our continued growth as one of the largest and most successful banks in the world. Maintaining a workplace where our employees feel supported to perform at their best, effectively collaborate, drive innovation, and grow professionally helps to bring our Purpose to life and create value for our clients and communities. RBC strives to deliver this through policies and programs intended to foster a workplace based on respect, belonging and opportunity for all.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer (Global Security)
Senior Security Engineer (Global Security)

RBC • Toronto

On-site
CAD 110,000 - 160,000
Total rewards program
Stock options (where applicable)
Bonuses
Senior Security Engineer (Global Security)
Senior Security Engineer (Global Security)

RBC • Vancouver

On-site
CAD 110,000 - 160,000
Sr Network Security Engineer (Global Security)
Sr Network Security Engineer (Global Security)

RBC • Toronto

On-site
CAD 120,000 - 170,000
Total rewards program including bonus
Leadership coaching and development
Technical growth opportunities
+3
Senior Software Developer, Security Automation(Global Security)
Senior Software Developer, Security Automation(Global Security)

RBC • Toronto

On-site
CAD 120,000 - 150,000
Senior Red Team Operator, Adversary Emulation (Global Security)
Senior Red Team Operator, Adversary Emulation (Global Security)

RBC • Calgary

On-site
CAD 120,000 - 180,000
Bonuses and flexible benefits
Stock where applicable
Senior Data Engineer, (Global Security)
Senior Data Engineer, (Global Security)

RBC • Toronto

On-site
CAD 140,000 - 190,000
Total rewards program
Coaching and development
Opportunities across geographies
Senior Application Developer- Python (Global Security)
Senior Application Developer- Python (Global Security)

RBC • Toronto

On-site
CAD 110,000 - 170,000
Senior Data Developer (Global Security)
Senior Data Developer (Global Security)

RBC • Vancouver

On-site
CAD 90,000 - 130,000
Associate Director, Physical Security Technology (Global Security)
Associate Director, Physical Security Technology (Global Security)

RBC • Toronto

On-site
CAD 120,000 - 160,000
Senior Red Team Operator, Adversary Emulation (Global Security)
Senior Red Team Operator, Adversary Emulation (Global Security)

RBC • Bedford

On-site
CAD 110,000 - 160,000