Senior Security Operations Analyst, Detection & Response

Financeit

Toronto

On-site

CAD 110,000 - 125,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid workplace options
Competitive pay and bonus
RRSP matching
In-office massage
Virtual events
Career learning and development

Job summary

Financeit is seeking a seasoned cybersecurity professional to join as the first SOC hire, reporting to the VP of IT. You will own threat detection, incident response, and forensics across endpoint, cloud, and SaaS environments, building automation and playbooks with an emphasis on AI tooling.

You will help establish runbooks, support on-call rotations, and drive detections as code, while collaborating with leadership to align security with business risk.

Qualifications

  • Bachelor's degree or equivalent in a technical discipline.
  • 5+ years of cybersecurity experience, including at least 3 years in security operations, IR or detection engineering.
  • Experience in financial services or regulated environments is preferred.
  • Certifications in GCIH, GCFA, GCDA, GNFA, CompTIA CySA+, vendor endpoint detection credentials, and CISSP are assets.
  • Familiarity with Kubernetes, OWASP Top 10 for LLMs, prompt injection risks, and MITRE ATLAS.
  • Proven lead on complex investigations, root cause analysis, and containment across Endpoint, Identity, and Cloud environments.
  • Hands-on experience authoring detections as code, building SIEM/SOAR playbooks, mapping to MITRE ATT&CK, and threat hunting.
  • Strong Python and REST API skills.

Responsibilities

  • Lead complex investigations, cloud/host forensics, and containment for high-severity incidents; participate in on-call rotation.
  • Write, test, tune, and manage detection rules and response playbooks as code across EDR, cloud, and log analytics platforms, mapping coverage to MITRE ATT&CK.
  • Conduct hypothesis-driven threat hunts and translate financial-sector threat intel into durable detections.
  • Document attacker activity for executive briefings and regulatory reports; drive post-incident actions with IT and engineering partners.
  • Document and maintain investigation runbooks, operational data, and case detail for SOC metrics and audits.
  • Partner with cybersecurity to align detection and response priorities with the organization’s risk picture.
  • Build and maintain automated response and enrichment playbooks; evaluate new security tooling and automation.
  • Supervise AI triage and investigation agents; develop detection capability for AI-related threats.

Skills

Threat detection
Incident response
Forensics
Python scripting
REST APIs
AI tooling

Education

Bachelor's degree in Computer Science/IT/Cybersecurity or equivalent

Tools

Kubernetes
SIEM/SOAR
MITRE AT T&ACK

Job description

Who we are:

Financeit is a point-of-sale financing provider serving some of the largest home improvement and retail organizations in Canada. Our platform helps businesses close more sales by offering customers affordable monthly payment options for their next big home improvement, vehicle or retail purchase.

We are small enough that you can make an impact within the company and large enough to make an impact in the market. Financeit is a company where collaboration, inclusivity, fairness, and respect aren't just ideas that get talked about, but are part of who we are. If such a workplace intrigues you, we hope you'll join us.

About the role:

Reporting to the Vice President of Information Technology as the first hire on our Security Operations Centre (SOC) team, you will be responsible for threat detection, investigation and incident response across endpoint, cloud, identity and production environments across the Financeit business.

In partnership with our cybersecurity team, you will handle escalated and complex investigations, build and maintain SOC detection content, and service as the main point of contact for confirmed security incidents. As this is a new team you will help establish the investigation standards, runbooks and working practices for the SOC team.

With a focus on automation and AI tooling, you'll help build and tune automated detection and response workflows, apply judgement to the output they produce, and develop detection coverage for AI-related threats. This is a hands-on and technical role with a growing team!

What you'll be doing:
  • Lead complex investigations, cloud/host forensics, and containment for high-severity incidents across endpoint, cloud, and SaaS environments; participate in an on-call rotation.
  • Write, test, tune, and manage detection rules and response playbooks as code across EDR, cloud, and log analytics platforms, mapping coverage to MITRE ATT&CK.
  • Conduct hypothesis-driven threat hunts and translate financial-sector threat intel and purple team findings into durable detections.
  • Document attacker activity for executive briefings and regulatory reports, driving post-incident corrective actions with IT and engineering partners.
  • Document and maintain investigation runbooks, operational data and case detail behind SOC metrics and reporting, and evidence of audit, assurance, and client security
  • Partner with cybersecurity function to align detection and response priorities with the organizations risk picture
  • Build and maintain automated response and enrichment playbooks within approved guardrails and evaluate new security tooling and automation
  • Supervise AI triage and investigation agents day to day, develop detection and investigation capability for AI-related threats, and tune agent configuration with results and analyst feedback
  • As you are supporting cybersecurity, evening and weekend hours may be required
Who you are:
  • You enjoy evaluating AI/automated triage outputs with healthy skepticism to override or validate machine conclusions
  • You can write clear technical reports and translate complex security incidents for executive and non-technical stakeholders
  • You're a team player and can participate in an on-call rotation for critical security incidents
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related technical discipline, or equivalent practical experience
  • 5+ years of experience in cybersecurity, including a minimum of 3 years in a security operations, incident response or detection engineering role
  • Experience in financial services or regulated environments is strongly preferred
  • Certifications in GCIH, GCFA, GCDA, GNFA, CompTIA CySA+, vendor endpoint detection credentials, and cloud security certifications, and CISSP are strong assets
  • Familiarity with Kubernetes, OWASP Top 10 for LLMs, prompt injection risks, and MITRE ATLAS
  • Proven lead on complex investigations, root cause analysis, and containment across Endpoint (EDR), Identity, and Cloud (AWS) environments
  • Hands-on experience authoring detections as code (version control), building SIEM/SOAR playbooks, mapping to MITRE ATT&CK, and executing threat hunts
  • Strong query and scripting skills (Python preferred), with experience working directly with REST APIs

Winner of Canada's Most Admired Corporate Cultures, twice. We offer more than just the basics, take advantage of:

  • An award-winning culture with a collaborative & inclusive team.
  • Competitive pay and performance-based bonus:
    • Annual Base Salary: $110,000 - $125,000
    • Annual Bonus: 20%
  • Committed to flexible work arrangements, offering hybrid workplace options.
  • Comprehensive medical, dental and vision coverage + Lifestyle Account.
  • RRSP Matching and Parental Leave Top UP Program.
  • In office massage, meditation & workout sessions.
  • Virtual events such as Lunch & Learns, company parties, fun team activities and charity initiatives.
  • Career learning and development programs.

Financeit is an equal opportunity employer. We celebrate diverse backgrounds and perspectives because we know they make our team stronger and our product better. We hire based on talent, potential, and culture add - no matter your background, identity, or life experience, you are welcome here.

We may use AI to support our hiring process. While these tools assist our team, applications are ultimately reviewed and assessed by our recruiters. If you require accommodation at any stage of the recruitment process, please let our People Success team know. Please note that this posting is for an existing vacancy, and all employment offers are contingent upon a successful background and credit check, among other verifications.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

EQ Bank | Equitable Bank • Toronto

Hybrid
CAD 100,000 - 140,000
Competitive discretionary bonus
Market-leading RRSP match program
Medical, dental, vision, life, and disability benefits
+3
Senior Manager, JSOC & Threat Hunting
Senior Manager, JSOC & Threat Hunting

Questrade Financial Group • Toronto

On-site
CAD 170,000 - 185,000
Hybrid work model with 3+ in-office</n
Security Advisor Specialist, Offensive Security (Global Red Team)
Security Advisor Specialist, Offensive Security (Global Red Team)

Intact • Saint-Hyacinthe

Hybrid
CAD 80,000 - 110,000
Competitive financial rewards
Employee Share Purchase Plan
Comprehensive pension and benefits package
+1
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Calgary

Hybrid
CAD 140,000 - 190,000
Hybrid work environment
Profit sharing
RRSP matching
+2
Incident Response Analyst, Digital Forensics & Incident Response
Incident Response Analyst, Digital Forensics & Incident Response

ISA Cybersecurity Inc • Toronto

On-site
CAD 75,000 - 105,000
Flexible sick days
Health plan
Education reimbursement
+5
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Vancouver

Hybrid
CAD 150,000 - 190,000
Hybrid work environment
Competitive salary
Profit sharing
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Toronto

Hybrid
CAD 140,000 - 180,000
Cybersecurity Incident Response Commander
Cybersecurity Incident Response Commander

ISA Cybersecurity Inc • Toronto

On-site
CAD 135,000 - 180,000
Flexible sick and personal days
Generous health plan
RRSP matching and bonus programs
+1
Detection Engineer, Information Security
Detection Engineer, Information Security

CIBC • Toronto

On-site
CAD 95,000 - 135,000
Competitive salary
Pension plan
Employee share plan
+2
JSOC - Cybersecurity Specialist - Incident Response
JSOC - Cybersecurity Specialist - Incident Response

Community Trust Company • Canada

Hybrid
CAD 81,000 - 101,000