Lead the technical direction of detection capabilities in a fast-growing legal AI company. Drive security analytics and logging engineering for legal professionals across multiple platforms.
Responsibilities
Lead the design and implementation of sophisticated, production-ready detection rules and queries across the ELK stack, security data lakes, and multi-cloud logging platforms.
Architect and optimize complex search queries, aggregations, and analytics dashboards for high-velocity security monitoring, focusing on performance and cost efficiency.
Design and build automated detection and response workflows (SOAR), ensuring seamless and reliable integration with critical incident response systems.
Serve as the primary liaison with the threat intelligence team, developing and owning the framework to translate intelligence into scalable, actionable detection capabilities (e.g., MITRE ATT&CK coverage).
Establish and maintain a robust detection rule library, query templates, and lead the creation of security analytics playbooks for the wider team.
Drive performance optimization and resource utilization strategies across petabyte-scale log datasets, including index design and data tiering.
Develop and standardize custom visualizations, dashboards, and executive reporting capabilities for security stakeholders.
Lead complex threat hunting operations, mentor junior team members on investigative techniques, and proactively refine detection logic to achieve near-zero false positive rates.
Collaborate closely with the platform team to define the logging architecture roadmap based on future detection requirements and security observability goals.
Proactively research emerging threats and attack patterns, translating novel techniques into strategic, forward-looking detection logic and advising security leadership.
Requirements
Senior-level expertise building and scaling enterprise-grade detection capabilities and security monitoring systems.
Expert-level query language proficiency in at least two of the following: Elasticsearch/Lucene, SQL, KQL (Kusto), or SPL (Splunk), demonstrating advanced optimization techniques.
Extensive Detection Engineering experience owning the full lifecycle of rules, alerts, and automated response workflows within a SIEM/SOAR environment.
Advanced log analysis skills across diverse, large-scale data sources, including multi-cloud logs (AWS, Azure, GCP), network flows, and advanced security tool outputs.
Deep dashboard and visualization expertise with tools like Kibana, Grafana, or Tableau, specifically for security metrics and executive reporting.
Proven expertise in leading threat hunting efforts using log data to proactively identify and track sophisticated threats and anomalous behavior across the environment.
Senior-level scripting and automation abilities (Python/Go/PowerShell), used to build custom tools, manage APIs, and drive detection automation at scale.
Architectural experience integrating and optimizing SIEM platforms, SOAR tools, and security orchestration systems.
Expert performance optimization skills covering query tuning, index design, data partitioning, and overall resource-efficient analytics on big data.
Significant incident response experience providing expert-level technical analysis and forensic support during major security incidents.
Demonstrate a keen interest in improving your craft by using AI.
Benefits
Competitive, equitable salary with top-tier health benefits, dental, and vision insurance
Hybrid work environment, with expectation for local Clions (Vancouver, Calgary, Toronto, Dublin, London, New York City and Sydney) to be in office min. twice per week.
Flexible time off policy, with an encouraged 20 days off per year.
$2000 annual counseling benefit
RRSP matching and RESP contribution
Clioversary recognition program with special acknowledgement at 3, 5, 7, and 10 years
Ingénieur(e) en mécanique industrielle chez AtkinsRéalis, déterminant les besoins des projets et concevant des solutions techniques. Évaluant les coûts et soutenant le développement d’équipe dans divers domaines.
Urban Engineer designing infrastructure projects including water and sewage networks for Quebec development team. Collaborating on plans, studies, and specifications with a hybrid working option.
Unit Cell Engineer designing and developing electrochemical cell components for flow batteries. Focused on performance optimization and cost reduction in energy storage solutions.
Senior Privacy Engineer leading projects to protect user privacy and drive innovation at DuckDuckGo. Collaborating with cross - functional teams using technologies like Node.js, Go, and Python.
Water Resources Engineer focusing on urban drainage and surface water management projects for private and public clients. Collaborating with multi - disciplinary teams and regulatory agencies in Alberta, BC, and SK.
Project Engineer leading Digital Transformation and R&D efforts for Framatome Canada. Coordinating with IT and product lines with remote work flexibility.
Process Engineer at Hexion handling Mechanical/Chemical projects for the Edmonton Chemical Plant. Responsible for project management from scoping to execution and ensuring safety and productivity.
Industrial Engineer providing technical project management and consulting for digital transformation in Québec. Leading projects in manufacturing improvement and AI integration with long - term client engagement.
Lead Protection & Control Engineer at GE Vernova responsible for designing protection schemes in T&D substations. Collaborating with a team to ensure project specifications and safety in the energy sector.