Lead the technical direction of detection capabilities in a fast-growing legal AI company. Drive security analytics and logging engineering for legal professionals across multiple platforms.
Responsibilities
Lead the design and implementation of sophisticated, production-ready detection rules and queries across the ELK stack, security data lakes, and multi-cloud logging platforms.
Architect and optimize complex search queries, aggregations, and analytics dashboards for high-velocity security monitoring, focusing on performance and cost efficiency.
Design and build automated detection and response workflows (SOAR), ensuring seamless and reliable integration with critical incident response systems.
Serve as the primary liaison with the threat intelligence team, developing and owning the framework to translate intelligence into scalable, actionable detection capabilities (e.g., MITRE ATT&CK coverage).
Establish and maintain a robust detection rule library, query templates, and lead the creation of security analytics playbooks for the wider team.
Drive performance optimization and resource utilization strategies across petabyte-scale log datasets, including index design and data tiering.
Develop and standardize custom visualizations, dashboards, and executive reporting capabilities for security stakeholders.
Lead complex threat hunting operations, mentor junior team members on investigative techniques, and proactively refine detection logic to achieve near-zero false positive rates.
Collaborate closely with the platform team to define the logging architecture roadmap based on future detection requirements and security observability goals.
Proactively research emerging threats and attack patterns, translating novel techniques into strategic, forward-looking detection logic and advising security leadership.
Requirements
Senior-level expertise building and scaling enterprise-grade detection capabilities and security monitoring systems.
Expert-level query language proficiency in at least two of the following: Elasticsearch/Lucene, SQL, KQL (Kusto), or SPL (Splunk), demonstrating advanced optimization techniques.
Extensive Detection Engineering experience owning the full lifecycle of rules, alerts, and automated response workflows within a SIEM/SOAR environment.
Advanced log analysis skills across diverse, large-scale data sources, including multi-cloud logs (AWS, Azure, GCP), network flows, and advanced security tool outputs.
Deep dashboard and visualization expertise with tools like Kibana, Grafana, or Tableau, specifically for security metrics and executive reporting.
Proven expertise in leading threat hunting efforts using log data to proactively identify and track sophisticated threats and anomalous behavior across the environment.
Senior-level scripting and automation abilities (Python/Go/PowerShell), used to build custom tools, manage APIs, and drive detection automation at scale.
Architectural experience integrating and optimizing SIEM platforms, SOAR tools, and security orchestration systems.
Expert performance optimization skills covering query tuning, index design, data partitioning, and overall resource-efficient analytics on big data.
Significant incident response experience providing expert-level technical analysis and forensic support during major security incidents.
Demonstrate a keen interest in improving your craft by using AI.
Benefits
Competitive, equitable salary with top-tier health benefits, dental, and vision insurance
Hybrid work environment, with expectation for local Clions (Vancouver, Calgary, Toronto, Dublin, London, New York City and Sydney) to be in office min. twice per week.
Flexible time off policy, with an encouraged 20 days off per year.
$2000 annual counseling benefit
RRSP matching and RESP contribution
Clioversary recognition program with special acknowledgement at 3, 5, 7, and 10 years
Water resource engineer - in - training supporting flood, river, stormwater, and watercourse projects at Onterris. Assisting modelling, design, field investigations, and regulatory work.
Senior Process Engineer delivering mineral - processing design and improvements for Sedgman’s global resources business. Supporting mining projects from feasibility through detailed engineering in Montreal’s hybrid office.
Lead threat intelligence for Clio’s legal AI platform, tracking adversaries, fraud, and abuse. Building intelligence capabilities that protect law firms and Clio Payments.
Quantum Engineer improving T - centre qubit quality and scalability at Photonic, a quantum computing company. Collaborating across nanofabrication, hardware, software, and modelling teams.
Co - op ASIC Digital Verification Engineer contributing to verification of SiTime’s mixed - signal PLL integrated circuits. Learning testbench and test - case development within the ASIC verification team.
Co - op engineer validating SiTime’s MEMS timing ASIC devices through PCB debugging, lab characterization, and Python test automation. Supporting pre - silicon drivers and production - readiness verification.
Traffic signal and roadway lighting engineer designing transportation infrastructure for Arcadis. Preparing compliant drawings, specifications, photometrics, reports and field deliverables.
Staff Forward Deployed Engineer building AI - powered client integrations for OpenLoop’s telehealth infrastructure. Creating reusable SDKs, agents, API tooling, and deployment practices across U.S. virtual care.
Principal Geotechnical Engineer leading geotechnical infrastructure projects for AtkinsRéalis, an engineering and nuclear services organization. Mentoring teams and expanding transportation, tunnel, rail, and municipal geotechnics capability.