Senior Security Engineer, Detection and Response
M
MarqetaCybersecurity
Remote - Ontario OR British Columbia; this role can be performed remotely anywhere within the province where you reside, whether that’s Ontario, Canada or British Columbia, Canada., North American timezonesFull-TimeSenior
SalaryBase salary range for this full-time position, reflected in CAD, is: 136,800 - 171,000
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years of hands-on experience in security operations with emphasis on Incident Response and Detection Engineering.
- Required Skills
- AWS
Requirements
- Have 5+ years of hands-on security operations experience emphasizing incident response and detection engineering.
- Bring hands-on experience with enterprise security tools, including EDR, NDR, CSPM, EASM, SIEM, SOAR, and cloud security platforms such as GuardDuty.
- Apply threat intelligence frameworks such as MITRE ATT&CK to assess detection capabilities and coverage gaps.
- Develop threat detection use cases using security telemetry analysis, environment baselining, actionable threat intelligence, and incident response findings.
- Understand AWS cloud services and containerization technologies.
- Incident response or related industry certifications such as GCIH, GCFA, GIME, OSIR, or GEIR are strongly preferred.
- Additional expertise in threat hunting, cyber threat intelligence, and digital forensics is preferred.
- Experience with Python, JavaScript, or Go is a nice-to-have.
- Experience with Terraform, forensic tools such as KAPE, EnCase, FTK, or Volatility, or Detections-as-Code tools such as Sigma or YARA is a nice-to-have.
- Experience conducting Purple Team exercises, validating vulnerabilities or reported bugs, or using observability or SRE tools and processes is a nice-to-have.
Responsibilities
- Serve as the lead security responder in North American timezones, triaging and investigating complex alerts.
- Participate in 24x7x365 on-call rotations and provide senior-level expertise and escalation support.
- Engineer, maintain, and optimize detection logic across multiple data sources using threat modeling.
- Map detection coverage, document capabilities, and identify threat landscape blind spots.
- Develop and track detection effectiveness, false positive, and response-time KPIs with leadership.
- Create and maintain incident response runbooks, SOPs, and technical documentation.
- Mentor junior team members in security operations, detection engineering, and incident response.
- Build automation workflows and orchestration playbooks for detection engineering, threat hunting, and incident response.
- Develop and use AI-driven tools for Security Operations and Incident Response.
- Conduct proactive threat hunts across corporate and production environments and support logging and monitoring infrastructure.
View Full Description & ApplyYou'll be redirected to the employer's site