Senior Security Operations Engineer (1 Yr Fixed Term)

League

Toronto

On-site

CAD 120,000 - 160,000

Full time

2 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

League is a leading healthcare experience platform in Canada, enabling customers to close gaps in care. We seek a Senior SecOps Engineer to join Security Monitoring, Incident Response, and Tooling teams, focusing on detection, response, tuning, and refinement.

You will work with security engineers and analysts to ensure secure operations across the platform. You will deploy and automate security workflows, leverage GCP services, and contribute to threat detection, tooling, and incident triage.

Qualifications

  • Bachelor of Science degree in Computer Science (or related field).
  • Minimum 7 years in Cybersecurity with a strong focus on Incident Response.
  • Minimum 3 years in Security Operations with hands-on SOAR and automation experience.
  • Advanced knowledge of Security Operations tools including configuration/administration.
  • Proven ability to lead and coordinate incident response processes.
  • Proficiency in scripting languages such as Python and Go.
  • Experience building/integrating LLM-based copilots into SIEM/SOAR/EDR workflows.
  • Experience with threat intelligence platforms in security operations.
  • Strong analytical and problem-solving skills.
  • Collaborative mindset with excellent communication.

Responsibilities

  • Security Monitoring and Incident Response: manage tools and automate workflows.
  • Develop automation scripts to improve security operations efficiency.
  • Leverage GCP services to host and automate security scripts and tools.
  • Utilize Pub/Sub, Dataflow, BigQuery, Cloud Storage for data processing and enrichment.
  • Evaluate and recommend new security tools to enhance posture.
  • Hands-on experience integrating LLM-based copilots into security workflows.
  • Security Tooling and Automation: manage SIEM/EDR/SASE platforms and Terraform.
  • Threat Management: conduct threat research and develop detection rules.
  • Collaboration: work with teams, communicate risks to leadership, mentor juniors.
  • Compliance: ensure alignment with HITRUST/NIST/GDPR and audit readiness.

Skills

Incident Response
Security Operations
SOAR
Automation
Python
Go
Cloud Security
GCP
LLM Copilots
Terraform
Threat Intelligence
Team Leadership

Education

Bachelor of Science in Computer Science

Tools

CrowdStrike NG SIEM
EDR
Falcon Complete
Netskope
Wiz Defend
Terraform
GCP
SIEM
SASE

Job description

League is one of the fastest-growing technology companies in Canada and the leading healthcare experience platform. Getting healthcare is often the easy part — finishing it is where things fall apart: people book the appointment and skip the follow-up, fill the prescription and stop taking it, get the referral and never make the call. That gap costs health plans and health systems money, and it costs people their health. League closes that gap — identifying what each person needs to do next, clearing what’s in their way, and getting it done, for the 70 million+ people whose care already runs through our platform. Health plans and health systems trust us to do this at scale. Organizations like Manulife, SCAN, Geisinger, and Medibank on the payer side, and Baptist and Shoppers Drug Mart on the provider side.

Position Summary (One year Fixed Term)

League’s Security Engineering teams are responsible for scaling security in the development lifecycle and managing security incident management. We believe in security by design and follow a paved road philosophy by building or buying tools that we can integrate into our platform to ultimately make it easier for our engineers to do the right thing. As a Senior SecOps Engineer you will care deeply about “what goes bump in the night”. You have peers in Security Engineering who care about “build it secure” at League, your role is to ensure both validation and response occurs when inevitable challenges arise. This role will focus on detection, response, tuning, and refinement. Security Engineers and Analysts on our SecOps team take pride in response.

As always, if this is your skillset we encourage you to apply. We also accept and encourage applicants who have existing software engineering experience and want to explore security and applicants who may have done a security program in a post‑secondary institution. There are people across the engineering organization who are ready to help grow technical skills and who want to learn more about security.

About the Role
Security Monitoring and Incident Response:
  • Manage and maintain security tools and technologies, such as CrowdStrike NG SIEM, EDR, Falcon Complete, Wiz Defend and Netskope SASE
  • Develop and implement automation scripts and workflows to improve security operations efficiency and effectiveness
  • Demonstrated ability to leverage GCP services (e.g., Cloud Functions, Cloud Run) to host and automate security scripts and tools for event enrichment and response
  • Proficiency in utilizing GCP services like Pub/Sub, Dataflow, BigQuery, and Cloud Storage for data processing, analysis, and enrichment
  • Evaluate and recommend new security tools and technologies to enhance our security posture
  • Direct hands‑on experience integrating Claude or OpenAI models into security workflows (e.g., incident summarization, IOC enrichment, case triage)
Security Tooling and Automation:
  • Manage and maintain security tools and technologies, such as SIEM, EDR, and SASE platforms.
  • Develop and implement automation scripts and workflows to improve security operations efficiency and effectiveness.
  • Demonstrated ability to leverage GCP services (e.g., Cloud Functions, Cloud Run) to host and automate security scripts and tools for event enrichment and response.
  • Proficiency in utilizing GCP services like Pub/Sub, Dataflow, BigQuery, and Cloud Storage for data processing, analysis, and enrichment.
  • Evaluate and recommend new security tools and technologies to enhance our security posture.
  • Manage and maintain infrastructure through Terraform.
Threat Management:
  • Conduct threat research and analysis to identify emerging threats and vulnerabilities.
  • Develop and implement threat detection rules and use cases.
  • Security Engineering and Architecture:
  • Contribute to the design and implementation of security systems architectures and solutions.
  • Evaluate and recommend security controls for new and existing systems.
  • Ensure security best practices are followed in system development and implementation.
Collaboration and Communication:
  • Collaborate with other teams to ensure security is integrated into all aspects of the organization's operations.
  • Communicate security risks and issues to technical and non-technical audiences, including leadership.
  • Mentors and provides guidance to junior security analysts and engineers to develop their technical growth.
Compliance and Reporting:
  • Ensure compliance with relevant security standards and regulations (e.g., HITRUST, NIST, GDPR).
  • Prepare and present security reports to management.
  • Participate in routine audits within the organization
About You
  • Bachelor of Science degree (BS) in Computer Science (or a related field)
  • Minimum of 7 years in Cybersecurity with a strong focus on Incident Response
  • Minimum of 3 years in Security Operations with hands‑on experience in SOAR and other automation tools
  • Deep and broad technical understanding of security concepts, principles, and technologies
  • Advanced knowledge of Security Operations tools (e.g., CrowdStrike NG SIEM, EDR, Falcon Complete, Netskope, Wiz Defend), including configuration and administration of these tools
  • Proven leading and coordinating incident response processes and methodologies
  • Proficiency in scripting languages (e.g., Python, Go)
  • Experience building or integrating LLM‑based agents/copilots into SIEM, SOAR, or EDR workflows (e.g., incident summarization, IOC enrichment, case triage)
  • Experience with threat intelligence platforms and implementing these in security operations
  • Strong analytical and problem‑solving skills
  • You are a collaborator at your core
  • Excellent communication and interpersonal skills.
Nice to Haves
  • Security certifications (e.g., OffSec Certifications, GIAC Certifications).
  • Experience with digital forensics
  • Experience with cloud security (AWS, Azure, GCP).
  • Experience with Security Orchestration,Automation and Response (SOAR).
  • Knowledge of networking protocols and security.
  • Contributions to the security community at League, and more broadly (eg. blog posts, conference presentations, etc.)
Security-Related Responsibilities
  • Compliance with Information Security Policies
  • Compliance with League’s secure coding practice
  • Responsibility and accountability for executing League's policies and procedures
  • Notification of HR, Legal, Compliance & Security of any incidents, breaches or policy violations
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Operations Engineer - 1 year Fixed Term
Senior Security Operations Engineer - 1 year Fixed Term

Socket.dev • Toronto

Hybrid
CAD 131,000 - 170,000
Senior Security Operations Engineer - 1 year Fixed Term
Senior Security Operations Engineer - 1 year Fixed Term

League Inc. • Toronto

On-site
CAD 131,000 - 170,000
Senior Security Operations Engineer (Talent pool building)
Senior Security Operations Engineer (Talent pool building)

Leagueinc • Toronto

Hybrid
CAD 131,000 - 163,000
Flexible remote days
Toronto office location
Senior Security Operations Engineer - 1 year Fixed Term
Senior Security Operations Engineer - 1 year Fixed Term

League • Toronto

Hybrid
CAD 131,000 - 170,000
Security Engineer
Security Engineer

League-Inc. • Toronto

Hybrid
CAD 109,000 - 136,000
Senior Security Operations Engineer - 1 year Fixed Term
Senior Security Operations Engineer - 1 year Fixed Term

League-Inc. • Toronto

On-site
CAD 131,000 - 170,000
Senior Software Engineer Backend
Senior Software Engineer Backend

League • Toronto

Hybrid
CAD 130,000 - 190,000
Comprehensive Health Benefits
Bonus Program
Employee Stock Option Program
+6
Senior Security Operations Engineer (Talent pool building)
Senior Security Operations Engineer (Talent pool building)

Portage Ventures GP Inc. • Toronto

On-site
CAD 120,000 - 160,000
Senior Software Engineer, Security
Senior Software Engineer, Security

Portage Ventures GP Inc. • Toronto

Hybrid
CAD 159,000 - 198,000
Senior Software Engineer (Security)
Senior Software Engineer (Security)

Super • Toronto

Hybrid
CAD 90,000 - 120,000
Competitive salary
Learning & development allowance
Generous equity options
+2