Senior Security Engineer building EvenUp’s detection and response program for legal technology serving personal injury lawyers and victims. Designing SIEM, telemetry, detections, and incident-response operations.
Responsibilities
Build and implement the detection platform, including SIEM evaluation, log ingestion and routing pipelines, and hot-search versus long-term archive decisions
Develop and tune high-signal detection content across cloud, identity, endpoint, SaaS, and application telemetry
Build business-logic detections using product audit events
Partner with Engineering and DevOps to define application and infrastructure logging requirements and security telemetry contracts
Build and maintain incident-response playbooks and runbooks
Coordinate response during security events
Run the annual tabletop exercise and lead post-incident reviews
Detect sensitive data exposure, including PHI, across applications, endpoints, and SaaS
Define requirements for managed detection partners, own escalation procedures, and manage 24/7 coverage quality
Requirements
5+ years in security operations, detection engineering, or incident response
Experience building a detection and response capability at a startup or high-growth technology company
Hands-on experience implementing or significantly maturing a SIEM, including custom log sources and detection content
Strong detection engineering skills using Python, SQL, or a rules DSL
Experience managing detections in version control and measuring detection quality
Real incident response experience, including leading investigations, writing playbooks, and running retrospectives
Experience with cloud-native telemetry across AWS, GCP, or Azure control planes, identity providers, endpoints, and SaaS audit logs
Strong programming or automation skills; Python preferred
Comfort building integrations and response automation
Experience partnering with software engineers to instrument applications for security visibility is a strong plus
Familiarity with securing or monitoring AI/LLM-powered systems is a strong plus
Experience working with MDR/MSSP providers
Relevant security certifications such as GIAC/GCIA/GCIH or CISSP are a plus
Ability to work in person at least three days per week from the Toronto office
Benefits
Choice of medical, dental, and vision insurance plans for you and your family
Additional insurance coverage options for life, accident, or critical illness
Flexible paid time off
Sick leave
Short-term and long-term disability
10 US observed holidays and Canadian statutory holidays by province
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.
Senior security advisor simulating cyber threats and strengthening defenses for Desjardins, North America's largest cooperative financial group. Leading complex initiatives, methodologies and cybersecurity risk mitigation.
SA&A Lead securing Azure applications and Microsoft platforms for PLATO, Canada’s Indigenous - owned software testing company. Leading authorization, control testing, evidence collection, and risk remediation.