← Back to job listings
C
Senior Corporate Security Analyst
Clio · Burnaby, Canada
About The Role
Join Clio, a mission-driven company, as a Senior Corporate Security Analyst. In this role, you will be responsible for unifying and adopting security systems, leading investigations, owning incident response, and improving operational quality. You will work closely with various teams to ensure appropriate security coverage and protect Clio from internal and external threats. The position requires senior technical expectations, including leading investigations, owning detection engineering, and driving root-cause analysis. You will also support security compliance requirements and maintain Clio's trust through transparent communication.
- Adopting and unifying security systems, communication, and oversight across IT Systems, Application Security, and Compliance.
- Leading investigations, owning incident response end-to-end, and improving the operational quality of threat detection and response.
- Coaching junior analysts, leading high-severity investigations, and partnering with adjacent teams to close gaps that no single team owns.
- Demonstrated ability to coach or mentor more junior analysts — you raise the bar of those around you, not just your own
- Deep hands-on experience with at least three of: EDR, DLP, Phishing platforms, SIEM, or Google Workspace security controls — you've configured, tuned, and operated them in production
- 5–8 years of hands-on experience in security operations, detection engineering, or incident response
- Demonstrated experience leading security incidents end-to-end — you've been the incident commander, not just a contributor
- Experience using, observing, and securing AI systems, platforms, and agents
- A healthy curiosity to look for the why and fix the problem rather than the symptom
- Growth mindset when it comes to process improvement and new technologies, especially AI
- Strong written communication — your runbooks, post-incident reviews, and decisions are easy to follow for engineers outside CorpSec
- Comfort with ambiguity — you can take an open-ended problem ("our DLP signal-to-noise is bad") and produce a concrete, prioritized plan
- Track record of root-cause investigation — you fix the problem, not the symptom, and translate the fix into a durable control or automation
- Experience designing or operating SIEM or detection-as-code pipelines
- Scripting fluency (Python, Bash, PowerShell) for automating investigation, evidence collection, and remediation
- You lead with calm under pressure — when an incident lands, people feel the response tighten, not panic
- Comfortable jumping onto due-diligence calls if Compliance requires assistance with customer Risk Interviews
- You're energized by improving systems, not just operating them — you leave every tool, runbook, and process measurably better than you found it
- Experience contributing to security compliance programs including SOC 2, ISO 27001, GovRAMP, or FedRAMP
- You document decisions for the engineer who comes after you — your runbooks outlive the on-call rotation that wrote them
- You're principled about the visibility-trust tension — you treat security communication as a trust-building exercise
- You're a force multiplier — when you're on a project, the whole team gets better
- Industry certifications such as CISSP, CISM, GCIH, GCIA, or CompTIA Security+
This listing was posted by a verified recruiter at Clio. Report this listing
JobSpring