Engineer - Security Operations and Incident Response
jobgether · Canada
About The Role
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Engineer - Security Operations and Incident Response based in Canada.
This role is central to strengthening and continuously evolving a global Security Operations and Incident Response <program.You> will help protect enterprise environments by identifying, investigating, containing, and eradicating sophisticated cybersecurity threats.The position combines deep technical investigations with detection engineering, threat intelligence, automation, and incident <response.You> will work across hybrid cloud environments while improving security processes, technologies, and operational resilience.Your expertise will help close visibility gaps, strengthen detection capabilities, and reduce risk across the <organization.You> will also contribute to playbooks, threat models, documentation, and continuous optimization of SOC tooling and workflows.This is an opportunity to make a direct impact on enterprise security while working with advanced cybersecurity technologies and frameworks.
Accountabilities
- Conduct expert-level investigations into complex security incidents, including digital forensics involving memory, network traffic, and malware analysis.
- Develop, author, and continuously refine incident response playbooks and operational guidelines to ensure effective responses to evolving threats.
- Develop and maintain threat models, incorporating penetration testing findings into detection strategies and security improvements.
- Design, implement, and optimize sophisticated detection rules and automated remediation workflows to identify and respond to adversarial behavior.
- Leverage threat intelligence and the MITRE ATT&CK framework to identify visibility gaps and proactively mitigate emerging cybersecurity risks.
- Maintain comprehensive documentation covering detection strategies, active investigations, incident timelines, and response activities.
- Partner with SIEM teams to continuously tune detection rules, improving detection fidelity while minimizing false positives and alert fatigue.
- Review and optimize threat intelligence capabilities, including brand protection and dark web monitoring systems.
- Develop scripts and queries using technologies such as Python, XQL, PowerShell, and Bash to support security investigations and operational efficiency.
- Implement and maintain automation and orchestration capabilities through SOAR tools and related technologies.
- Support incident response leadership as a backup resource for incident response activities and operational priorities.
- Contribute to the continuous improvement of security operations processes, technologies, and overall incident response maturity.
Requirements
- Bachelor's degree and at least 5 years of relevant professional experience in incident response and Security Operations Center (SOC) tooling.
- In-depth knowledge of SIEM and SOAR platforms, with experience in technologies such as Microsoft Sentinel, Palo Alto Cortex XSIAM, and Cortex XSOAR.
- Strong understanding of incident response processes within hybrid cloud environments, including GCP and Azure.
- Experience serving as an incident commander during security incidents and leading coordinated response efforts.
- Proven ability to conduct root cause analysis and drive continuous optimization of SOC tools, processes, and detection capabilities.
- Strong scripting and query-building skills using Python, PowerShell, Bash, and/or XQL.
- Understanding of cybersecurity frameworks and regulatory requirements, including MITRE ATT&CK, NIST, and ISO.
- Experience with threat intelligence, detection engineering, security automation, and incident response processes.
- Strong analytical and problem-solving skills, with the ability to investigate complex security events and develop practical solutions.
- Ability to prioritize effectively, manage multiple concurrent priorities, and work independently as well as collaboratively.
- Excellent written and verbal communication skills, including the ability to translate sophisticated technical security concepts into clear, concise business-focused explanations.
Benefits
- Remote or hybrid work options.
- Opportunity to work on the ongoing transformation of a global Security Operations and Incident Response program.
- Exposure to advanced cybersecurity technologies, including SIEM, SOAR, threat intelligence, security automation, and cloud security platforms.
- Opportunity to work with modern security frameworks and methodologies such as MITRE ATT&CK, NIST, and ISO.
- High-impact role focused on strengthening enterprise resilience and protecting against evolving cybersecurity threats.
- Opportunity to contribute to continuous process improvement and the advancement of security operations capabilities.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
