Skip to content
← Back to job listings

Engineer - Security Operations and Incident Response

jobgether · Canada

RemoteImported listingfull-time6 days ago

About The Role

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Engineer - Security Operations and Incident Response based in Canada.

This role is central to strengthening and continuously evolving a global Security Operations and Incident Response <program.You> will help protect enterprise environments by identifying, investigating, containing, and eradicating sophisticated cybersecurity threats.The position combines deep technical investigations with detection engineering, threat intelligence, automation, and incident <response.You> will work across hybrid cloud environments while improving security processes, technologies, and operational resilience.Your expertise will help close visibility gaps, strengthen detection capabilities, and reduce risk across the <organization.You> will also contribute to playbooks, threat models, documentation, and continuous optimization of SOC tooling and workflows.This is an opportunity to make a direct impact on enterprise security while working with advanced cybersecurity technologies and frameworks.

Accountabilities

  • Conduct expert-level investigations into complex security incidents, including digital forensics involving memory, network traffic, and malware analysis.
  • Develop, author, and continuously refine incident response playbooks and operational guidelines to ensure effective responses to evolving threats.
  • Develop and maintain threat models, incorporating penetration testing findings into detection strategies and security improvements.
  • Design, implement, and optimize sophisticated detection rules and automated remediation workflows to identify and respond to adversarial behavior.
  • Leverage threat intelligence and the MITRE ATT&CK framework to identify visibility gaps and proactively mitigate emerging cybersecurity risks.
  • Maintain comprehensive documentation covering detection strategies, active investigations, incident timelines, and response activities.
  • Partner with SIEM teams to continuously tune detection rules, improving detection fidelity while minimizing false positives and alert fatigue.
  • Review and optimize threat intelligence capabilities, including brand protection and dark web monitoring systems.
  • Develop scripts and queries using technologies such as Python, XQL, PowerShell, and Bash to support security investigations and operational efficiency.
  • Implement and maintain automation and orchestration capabilities through SOAR tools and related technologies.
  • Support incident response leadership as a backup resource for incident response activities and operational priorities.
  • Contribute to the continuous improvement of security operations processes, technologies, and overall incident response maturity.

Requirements

  • Bachelor's degree and at least 5 years of relevant professional experience in incident response and Security Operations Center (SOC) tooling.
  • In-depth knowledge of SIEM and SOAR platforms, with experience in technologies such as Microsoft Sentinel, Palo Alto Cortex XSIAM, and Cortex XSOAR.
  • Strong understanding of incident response processes within hybrid cloud environments, including GCP and Azure.
  • Experience serving as an incident commander during security incidents and leading coordinated response efforts.
  • Proven ability to conduct root cause analysis and drive continuous optimization of SOC tools, processes, and detection capabilities.
  • Strong scripting and query-building skills using Python, PowerShell, Bash, and/or XQL.
  • Understanding of cybersecurity frameworks and regulatory requirements, including MITRE ATT&CK, NIST, and ISO.
  • Experience with threat intelligence, detection engineering, security automation, and incident response processes.
  • Strong analytical and problem-solving skills, with the ability to investigate complex security events and develop practical solutions.
  • Ability to prioritize effectively, manage multiple concurrent priorities, and work independently as well as collaboratively.
  • Excellent written and verbal communication skills, including the ability to translate sophisticated technical security concepts into clear, concise business-focused explanations.

Benefits

  • Remote or hybrid work options.
  • Opportunity to work on the ongoing transformation of a global Security Operations and Incident Response program.
  • Exposure to advanced cybersecurity technologies, including SIEM, SOAR, threat intelligence, security automation, and cloud security platforms.
  • Opportunity to work with modern security frameworks and methodologies such as MITRE ATT&CK, NIST, and ISO.
  • High-impact role focused on strengthening enterprise resilience and protecting against evolving cybersecurity threats.
  • Opportunity to contribute to continuous process improvement and the advancement of security operations capabilities.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing