Senior Security Engineer, Detection and Response
New
J
JobgetherCybersecurity
Fully remote work within Ontario or British Columbia, Canada., North American time zonesFull-TimeSenior
SalaryCompetitive base salary of CAD 136,800–171,000
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years of hands-on experience in security operations, with a strong focus on incident response and detection engineering.
- Required Skills
- AWS
Requirements
- 5+ years of hands-on experience in security operations, focused on incident response and detection engineering.
- Bring strong investigative instincts and the ability to analyze anomalies, follow evidence trails, and reconstruct incidents from fragmented data.
- Have technical expertise across EDR, NDR, CSPM, EASM, SIEM, SOAR, and cloud security platforms such as AWS GuardDuty.
- Know threat intelligence frameworks, particularly MITRE ATT&CK, and have experience applying them to assess detection capabilities and coverage gaps.
- Demonstrate the ability to develop detection use cases based on telemetry analysis, environment baselining, actionable threat intelligence, and incident response findings.
- Have experience identifying detection and visibility gaps and collaborating with stakeholders to improve logging and detection content.
- Have a strong understanding of AWS cloud services and containerization technologies.
- Additional experience in threat hunting, cyber threat intelligence, and digital forensics is highly valued.
- Industry certifications in incident response or related disciplines, such as GCIH, GCFA, GIME, OSIR, or GEIR, are strongly preferred.
- Programming experience with Python, JavaScript, or Go is an asset.
- Familiarity with infrastructure-as-code tools such as Terraform is an asset.
- Experience with forensic tools such as KAPE, EnCase, FTK, or Volatility is a plus.
- Experience with Detection-as-Code technologies such as Sigma or YARA is a plus.
- Experience conducting Purple Team exercises, validating vulnerabilities or reported bugs, and working with observability or SRE tools and processes is beneficial.
Responsibilities
- Lead security response across North American time zones by triaging and investigating complex alerts and supporting the Cybersecurity Incident Response Team.
- Participate in a 24x7x365 on-call rotation and provide senior-level expertise and escalation support during security events.
- Engineer, maintain, and optimize detection logic across security data sources using threat modeling and current threat intelligence.
- Design and maintain detection coverage maps to identify capabilities, visibility gaps, and monitoring needs.
- Develop and track security KPIs, including detection effectiveness, false-positive rates, and mean time to detect, respond, and recover.
- Create and maintain incident response runbooks, standard operating procedures, and technical documentation.
- Build automation workflows and orchestration playbooks for detection engineering, threat hunting, and incident response.
- Develop and use AI-driven tools to support security investigations and Security Operations and Incident Response.
- Conduct proactive, hypothesis-driven threat hunts across corporate and production environments.
- Support logging and monitoring infrastructure and mentor junior team members.
View Full Description & ApplyYou'll be redirected to the employer's site