Lead Security Manager responsible for proactive threat hunting and incident response activities at Bullhorn. Collaborating with teams to enhance security posture and detection capabilities.
Responsibilities
Develop and execute hypothesis-driven hunts using EDR, SIEM, and network traffic analysis to find threats bypassing existing defenses
Lead complex investigations and CSIRT activities, providing technical expertise during containment, eradication, and post-incident analysis
Analyze adversary Tactics, Techniques, and Procedures (TTPs) and integrate intelligence feeds to drive targeted hunting scenarios
Collaborate with security engineering to convert hunting discoveries into permanent actionable alerts, reducing future risk
Mentor junior analysts, define the technical standards for hunting workflows, and report findings to stakeholders
Requirements
5-8 years of experience in security operations, threat hunting, or incident response
Proficiency in EDR tools (CrowdStrike, NeuVector), SIEM platforms (XSIAM), and network forensics
Deep understanding of the MITRE ATT&CK Framework and cyber kill chain
Strong query skills (SQL, KQL) and scripting ability (Python, PowerShell) for automation
Knowledge of AWS, Azure, and/or GCP security logging and controls (e.g., GuardDuty, CloudTrail)
Expert in application cybersecurity analyzing web components and supporting secure development practices within a dynamic team. Collaborate on cloud application security based in Quebec, Canada.
Penetration Testing Consultant at BMO conducting extensive manual security assessments for critical financial applications. Collaborating with stakeholders to enhance security strategies and practices.
Information Security Consultant leading Risk Control Self Assessments and risk governance at Manulife. Collaborating on technology, data, and operational risk management while ensuring strong governance.
Software Specialist at Xona developing secure software for the Pulsar ecosystem. Collaborating with teams to integrate security features in partner hardware.
Cybersecurity Intern at FloSports assisting in identity, cloud, and endpoint security. Work in a hybrid setup at the Waterloo office focusing on real - world cybersecurity practices.