Senior Security Operations Engineer (Talent pool building)

Leagueinc

Toronto

Hybrid

CAD 131,000 - 163,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Flexible remote days
Toronto office location

Job summary

League's Toronto-based Security Engineering team is seeking a Senior SecOps Engineer to scale security across the development lifecycle and to lead incident response efforts.

You will monitor events, drive containment and recovery, and develop robust incident response playbooks. The role emphasizes automation, cloud security, and cross-functional collaboration to strengthen League's security posture.

Qualifications

  • BS in Computer Science or related field
  • 7+ years in cybersecurity with focus on incident response, or 3+ years in security operations with SOAR
  • Strong knowledge of security monitoring tools and incident response processes
  • Proven ability to lead and coordinate incident response activities

Responsibilities

  • Monitor security events and alerts from SIEM/EDR/SASE sources and identify incidents.
  • Lead security incident response efforts including containment, eradication and recovery.
  • Develop and maintain incident response playbooks and procedures.
  • Collaborate with IT, Legal and Engineering during incidents and provide clear communication.

Skills

Security mindset
Incident response leadership
Communication
Team collaboration

Education

Bachelor of Science in Computer Science

Tools

SIEM
EDR
SASE
Terraform
GCP
Cloud Functions
Cloud Run
BigQuery
Dataflow
Pub/Sub

Job description

About League

League is one of the fastest-growing technology companies in Canada and the leading healthcare experience platform. Getting healthcare is often the easy part — finishing it is where things fall apart: people book the appointment and skip the follow‑up, fill the prescription and stop taking it, get the referral and never make the call. That gap costs health plans and health systems money, and it costs people their health. League closes that gap — identifying what each person needs to do next, clearing what’s in their way, and getting it done, for the 70 million+ people whose care already runs through our platform. Health plans and health systems trust us to do this at scale. Organizations like Manulife, SCAN, Geisinger, and Medibank on the payer side, and Baptist and Shoppers Drug Mart on the provider side.

Position Summary

League’s Security Engineering teams are responsible for scaling security in the development lifecycle and managing security incident management. We believe in security by design and follow a paved road philosophy by building or buying tools that we can integrate into our platform to ultimately make it easier for our engineers to do the right thing. As a Senior SecOps Engineer you will care deeply about “what goes bump in the night”. You have peers in Security Engineering who care about “build it secure” at League, your role is to ensure both validation and response occurs when inevitable challenges arise. This role will focus on detection, response, tuning, and refinement. Security Engineers and Analysts on our SecOps team take pride in response.

We also accept and encourage applicants who have existing software engineering experience and want to explore security and applicants who may have done a security program in a post‑secondary institution. There are people across the engineering organization who are ready to help grow technical skills and who want to learn more about security.

About the Role
  • Security Monitoring and Incident Response:
    • Monitors security events and alerts from various sources (SIEM, endpoint detection, SASE, etc.) and analyzes them to identify potential security incidents.
    • Leads security incident response efforts, including investigation, containment, eradication, and recovery.
    • Develops and maintains incident response plans, playbooks, and procedures.
    • Coordinates with cross-functional teams (IT, Engineering, Legal, etc.) during security incidents.
    • Perform root cause analysis of security incidents and recommend preventive measures. Independently analyzes complex security incidents, identifying root causes and developing solutions and drives them to completion.
    • Participate in an on‑call rotation.
  • Security Tooling and Automation:
    • Manage and maintain security tools and technologies, such as SIEM, EDR, and SASE platforms.
    • Develop and implement automation scripts and workflows to improve security operations efficiency and effectiveness.
    • Demonstrated ability to leverage GCP services (e.g., Cloud Functions, Cloud Run) to host and automate security scripts and tools for event enrichment and response.
    • Proficiency in utilizing GCP services like Pub/Sub, Dataflow, BigQuery, and Cloud Storage for data processing, analysis, and enrichment.
    • Evaluate and recommend new security tools and technologies to enhance our security posture.
    • Manage and maintain infrastructure through Terraform.
  • Threat Management:
    • Conduct threat research and analysis to identify emerging threats and vulnerabilities.
    • Develop and implement threat detection rules and use cases.
  • Security Engineering and Architecture:
    • Contribute to the design and implementation of security systems architectures and solutions.
    • Evaluate and recommend security controls for new and existing systems.
    • Ensure security best practices are followed in system development and implementation.
  • Collaboration and Communication:
    • Collaborate with other teams to ensure security is integrated into all aspects of the organization’s operations.
    • Communicate security risks and issues to technical and non‑technical audiences, including leadership.
    • Mentors and provides guidance to junior security analysts and engineers to develop their technical growth.
  • Compliance and Reporting:
    • Ensure compliance with relevant security standards and regulations (e.g., HITRUST, NIST, GDPR).
    • Prepare and present security reports to management.
    • Participate in routine audits within the organization
About You
  • Bachelor of Science degree (BS) in Computer Science (or a related field)
  • Minimum of 7 years in Cybersecurity with a strong focus on Incident Response, or
  • Minimum of 3 years in Security Operations with hands‑on experience in SOAR and other automation tools.
  • Deep and broad technical understanding of security concepts, principles, and technologies.
  • Experience with security monitoring tools (e.g., SIEM, EDR), including configuration and administration of these tools.
  • Proven leading and coordinating incident response processes and methodologies.
  • Proficiency in scripting languages (e.g., Python, Go).
  • You have some Infrastructure as Code (Terraform, Ansible) experience or a strong desire to learn.
  • Experience with threat intelligence platforms and implementing these in security operations.
  • Strong analytical and problem‑solving skills.
  • You are a collaborator at your core
  • Excellent communication and interpersonal skills.
Nice to Haves
  • Security certifications (e.g., OffSec Certifications, GIAC Certifications).
  • Experience with digital forensics
  • Experience with cloud security (AWS, Azure, GCP).
  • Experience with Security Orchestration, Automation and Response (SOAR).
  • Knowledge of networking protocols and security.
  • Contributions to the security community at League, and more broadly (eg. blog posts, conference presentations, etc.)
AI Fluency & Ways of Working
What this means in practice:
  • Use AI tools as part of your daily workflow to enhance productivity, problem‑solving, and decision‑making (e.g., drafting, analysis, coding, research, or process automation)
  • Apply judgment and accountability when using AI by reviewing outputs for accuracy, bias, and quality before use
  • Continuously learn and adapt as new AI tools and capabilities emerge, incorporating them into your ways of working
  • Identify opportunities to improve how work gets done from personal productivity to team‑level workflows by leveraging AI effectively
  • Operate with strong data responsibility and security awareness, especially when working with sensitive or regulated information
What we look for
  • Demonstrated experience using AI tools in a practical, responsible way
  • Curiosity and openness to experimenting with new technologies
  • Ability to balance efficiency with quality and sound judgment
Security-Related Responsibilities
  • Compliance with Information Security Policies
  • Compliance with League’s secure coding practice
  • Responsibility and accountability for executing League's policies and procedures
  • Notification of HR, Legal, Compliance & Security of any incidents, breaches or policy violations
Compensation range for Canada applicants only

The Canada-specific compensation range below for this full-time position is exclusive of bonus, equity and benefits. This range reflects the minimum and maximum target for base salaries for the position across all Canadian locations. Where in the band you may land is determined by job-related skills/experience. Your recruiter can share more about the specific salary range specific to your skills and experience during the hiring process.

$130,600 — $163,200 CAD

Our employees come from different backgrounds, and we celebrate those differences. We are looking for the best candidates for our open roles, but do not expect applicants to meet every qualification in order to be considered. If you are excited about what you could accomplish at League and believe you can add value to our team, we would love to hear from you.

We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. If you are an individual in need of assistance at any time during our recruitment process, please contact us at recruitinginfo@league.com.

Work Location

We have a mix of office-centric roles based in our vibrant Toronto office, and remote‑eligible roles based anywhere in Canada or US. Each job posting will indicate where the role will be based. Regardless of the role’s posted location, all Toronto‑area Leaguers (living within 65 km of our downtown HQ) collaborate in‑office Monday through Thursday. Depending on your distance to the office, you’ll enjoy 10 or 20 Flexible Remote Days each quarter for focus and deep‑work time. We are committed to fostering a meaningful work environment and connections for all Leaguers regardless of location.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Operations Engineer (Talent pool building)
Senior Security Operations Engineer (Talent pool building)

League Inc. • Toronto

On-site
CAD 131,000 - 163,000
Security Engineer
Security Engineer

League • Toronto

On-site
CAD 109,000 - 136,000
Security Engineer
Security Engineer

Leagueinc • Toronto

Hybrid
CAD 109,000 - 136,000
Security Engineer
Security Engineer

League-Inc. • Toronto

Hybrid
CAD 109,000 - 136,000
Security Engineer
Security Engineer

League Inc. • Toronto

Hybrid
CAD 109,000 - 136,000
Senior Software Engineer, Security
Senior Software Engineer, Security

Portage Ventures GP Inc. • Toronto

Hybrid
CAD 159,000 - 198,000
Clinical Lead, Health Solutions
Clinical Lead, Health Solutions

League • Toronto

Hybrid
CAD 121,000 - 150,000
Manager, Marketing Programs and Events
Manager, Marketing Programs and Events

League • Toronto

Hybrid
CAD 95,000 - 115,000
Clinical Lead, Health Solutions
Clinical Lead, Health Solutions

League-Inc. • Toronto

Hybrid
CAD 121,000 - 150,000
Clinical Lead, Health Solutions
Clinical Lead, Health Solutions

League Inc. • Toronto

Hybrid
CAD 121,000 - 150,000