Senior Security Engineer - Detection & Response

EvenUp

Toronto

On-site

CAD 150,000 - 210,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision
Life and critical illness insurance
Flexible PTO and disability
Holidays by province
Home office stipend
RRSP/401(k) plans
Paid parental leave
In-person meetups
Hubs in Toronto

Job summary

EvenUp in Toronto is seeking a hands-on Senior Security Engineer to build our detection and response program across telemetry pipelines, SIEM, and incident response. This role shapes security at a fast-growing vertical SaaS company and collaborates with engineers to embed security in product data flows.

You will lead SIEM evaluation, write detections, define telemetry, and own post-incident reviews, with hybrid work in Toronto three days a week and opportunities to influence security

Qualifications

  • 5+ years in security operations, detection engineering, or incident response, including startup or high-growth tech experience.
  • Hands-on SIEM implementation and customization experience.
  • Strong detection engineering skills: Python/SQL/dsl, version control, and quality metrics.
  • Real incident response leadership with playbooks and retros.
  • Experience with cloud-native telemetry (AWS/GCP/Azure) and security visibility.
  • Programming/automation skills; comfortable building integrations for security workflows.
  • Experience instrumenting applications for security visibility and telemetry.
  • Familiarity with AI/LLM security considerations is a plus.
  • Experience with MDR/MSSP providers and evaluating security services.
  • Builder mentality: engineer the alert away, not just triage.
  • Security certifications (GIAC/GCIA/GCIH, CISSP, etc.) are a plus.

Responsibilities

  • Build Our Detection Platform: Lead SIEM evaluation and implementation, design log ingestion and retention trade-offs.
  • Engineer High-Signal Detections: Develop detections across cloud, identity, endpoint, SaaS, and application telemetry.
  • Define the Telemetry Contract: Specify logs with Engineering/DevOps to detect key risks.
  • Lead Incident Response: Create IR playbooks, runbooks, and post-incident reviews.
  • Detect Data Exposure: Identify sensitive data movement across apps, endpoints, and SaaS.
  • Manage 24/7 Coverage: Direct managed detection partners and escalation procedures.

Skills

SIEM engineering
Detection engineering
Python
Incident response
Cloud telemetry
Automation
Cross-functional collaboration
Security certifications

Tools

AWS/GCP/Azure
Audit logs
MDR/MSSP partnerships

Job description

EvenUp is on a mission to close the justice gap using technology and AI. We empower personal injury lawyers and victims to get the justice they deserve. Our products enable law firms to secure faster settlements, higher payouts, and better outcomes for victims injured through no fault of their own in vehicle collisions, accidents, natural disasters, and more.

We are one of the fastest-growing vertical SaaS companies in history, and we are just getting started. EvenUp is backed by top VCs, including Bessemer Venture Partners, Bain Capital Ventures, SignalFire, and Lightspeed. We are looking to expand our team with talented, driven, and collaborative individuals who seek to have a lasting impact. Learn more at www.evenuplaw.com.

Life as an Engineer at EvenUp

Security at EvenUp is still early enough to shape — and detection and response is the part we're building next, from the ground up.

We're looking for a hands-on Senior Security Engineer to build our detection and response program: the telemetry pipelines, the SIEM, the detection content, and the incident response muscle behind them. You won't inherit a SOC — you'll design one.

This isn't a role where you'll stare at a queue of vendor alerts. The threats that matter most to us don't come out of any box: they live in our own applications and data flows, and detecting them means partnering with the engineers who build those systems. We believe security should accelerate the business, not slow it down. If you're excited about treating detection as an engineering discipline, we'd love to chat.

Why this role is exciting
  • Build the program, not just the rules: select the SIEM, design the telemetry architecture, and write the first generation of detections; your technical decisions become the foundation.

  • Detect what actually matters: focus on highest-stakes risks unique to our business, like sensitive data moving to the wrong place, misuse of internal systems, and exposure of health information, as generic detection content cannot address these.

  • Detection as code: detections are written, version-controlled, tested, and reviewed like software.

  • Own incident response: define how EvenUp responds to incidents, including playbooks, tabletop exercises, and post-incident reviews.

  • Direct the vendors, don't answer to them: when using managed providers for 24/7 coverage, you set the requirements, escalation logic, and quality standards.

What You'll Do
  • Build Our Detection Platform: Lead SIEM evaluation and implementation, design log ingestion and routing pipelines, and make deliberate cost/retention trade-offs across hot search and long-term archive.

  • Engineer High-Signal Detections: Develop and tune detection content across cloud, identity, endpoint, SaaS, and application telemetry — with an emphasis on business-logic detections built on our own products' audit events.

  • Define the Telemetry Contract: Partner with Engineering and DevOps to specify what our applications and infrastructure must log — the audit events that make our most important risks detectable in the first place.

  • Lead Incident Response: Build and maintain IR playbooks and runbooks, coordinate response during security events, run the annual tabletop exercise, and drive post-incident reviews that actually change things.

  • Detect Data Exposure: Partner with internal teams to detect sensitive data moving where it shouldn't — including PHI — across applications, endpoints, and SaaS.

  • Manage 24/7 Coverage: Define requirements for and direct our managed detection partners, own escalation procedures, and continuously raise the bar on what "monitored" means.

What We Look For
  • 5+ years in security operations, detection engineering, or incident response, including experience building (not just running) a detection and response capability at a startup or high-growth technology company.

  • Hands-on experience implementing or significantly maturing a SIEM, including custom log sources and detection content — not just operating one that was handed to you.

  • Strong detection engineering skills: writing detections in Python, SQL, or a rules DSL, managing them in version control, and measuring their quality.

  • Real incident response experience — you've led investigations, written the playbooks, and run the retros.

  • Experience with cloud-native telemetry (AWS/GCP/Azure control plane, identity providers, endpoint, SaaS audit logs).

  • Strong programming or automation skills (Python preferred); comfort building integrations and response automation.

  • Experience partnering directly with software engineers to instrument applications for security visibility is a strong plus.

  • Familiarity with securing or monitoring AI/LLM-powered systems is a strong plus.

  • Experience working with MDR/MSSP providers — and opinions about what they're good and bad at.

  • A builder mentality — you'd rather engineer the alert away than triage it forever.

  • Relevant security certifications (GIAC/GCIA/GCIH, CISSP, etc.) are a plus, but practical engineering experience matters more.

This is a hybrid role, with an expectation of being in our Toronto office three days per week.

#LI-Hybrid

Benefits & Perks:

As part of our total rewards package, we offer attractive benefits and perks to our employees, including:

  • Choice of medical, dental, and vision insurance plans for you and your family.

  • Additional insurance coverage options for life, accident, or critical illness.

  • Flexible paid time off, sick leave, short-term and long-term disability.

  • 10 US observed holidays, and Canadian statutory holidays by province.

  • A home office stipend.

  • 401(k) for US-based employees and RRSP for Canada-based employees.

  • Paid parental leave.

  • A local in-person meet-up program.

  • Hubs in San Francisco and Toronto.

(Please note the above benefits & perks are for full-time employees)

Please note that EvenUp may use AI notetakers and other recording devices in the recruiting process. If you interview with us, with your consent, we may record your conversations and summarize them into notes for internal use. Recording is optional, and declining will not affect your candidacy.

EvenUp is an equal opportunity employer. We are committed to diversity and inclusion in our company. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Backend Engineer, Growth & Agents
Backend Engineer, Growth & Agents

evenup • Toronto

Hybrid
CAD 120,000 - 180,000
Home office stipend
RRSP for Canada-based employees
401(k) for US-based employees
+3
Senior Backend Engineer, Cases Product
Senior Backend Engineer, Cases Product

EvenUp • Toronto

Hybrid
CAD 125,000 - 250,000
Medical, dental, and vision insurance
Flexible paid time off
401(k) for US employees and RRSP for Canada employees
Frontend Engineer, Cases Product
Frontend Engineer, Cases Product

EvenUp • Toronto

On-site
CAD 100,000 - 130,000
Medical, dental, and vision insurance options
Flexible paid time off
Home office stipend
+2
Frontend Engineer, Growth & Agents
Frontend Engineer, Growth & Agents

evenup • Toronto

Hybrid
CAD 100,000 - 150,000
Medical insurance
Dental insurance
Vision insurance
+2
Frontend Engineer, Growth & Agents
Frontend Engineer, Growth & Agents

EvenUp • Toronto

Hybrid
CAD 160,000 - 215,000
Home office stipend
Toronto office hubs
401(k)/RRSP matching
Frontend Engineer, Cases Product
Frontend Engineer, Cases Product

EvenUp • Toronto

Hybrid
CAD 177,000 - 303,000
Medical, dental, and vision insurance
401(k) / RRSP options
Flexible paid time off
+3
Senior Backend Engineer, Entities
Senior Backend Engineer, Entities

EvenUp • Toronto

Hybrid
CAD 120,000 - 180,000
Medical, dental, and vision insurance
Life and disability insurance
Flexible paid time off
+6
Senior Frontend Engineer, Cases Product
Senior Frontend Engineer, Cases Product

EvenUp • Toronto

On-site
CAD 152,000 - 215,000
Medical, dental, and vision insurance plans
401(k) for US employees and RRSP for Canada employees
Flexible paid time off
Senior Data Analyst
Senior Data Analyst

EvenUp • Toronto

Hybrid
CAD 182,244 - 209,581
Medical, dental, and vision insurance
Flexible paid time off
401(k) for US and RRSP for Canada employees
+1
Senior Machine Learning Engineer
Senior Machine Learning Engineer

EvenUp • Toronto

Hybrid
CAD 277,000 - 376,000
Home office stipend
401(k) for US-based employees
RRSP for Canada-based employees
+2