Senior Security Engineer – Detection & Response

Posted 3 days ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Senior Security Engineer building EvenUp’s detection and response program for legal technology serving personal injury lawyers and victims. Designing SIEM, telemetry, detections, and incident-response operations.

Responsibilities

  • Build and implement the detection platform, including SIEM evaluation, log ingestion and routing pipelines, and hot-search versus long-term archive decisions
  • Develop and tune high-signal detection content across cloud, identity, endpoint, SaaS, and application telemetry
  • Build business-logic detections using product audit events
  • Partner with Engineering and DevOps to define application and infrastructure logging requirements and security telemetry contracts
  • Build and maintain incident-response playbooks and runbooks
  • Coordinate response during security events
  • Run the annual tabletop exercise and lead post-incident reviews
  • Detect sensitive data exposure, including PHI, across applications, endpoints, and SaaS
  • Define requirements for managed detection partners, own escalation procedures, and manage 24/7 coverage quality

Requirements

  • 5+ years in security operations, detection engineering, or incident response
  • Experience building a detection and response capability at a startup or high-growth technology company
  • Hands-on experience implementing or significantly maturing a SIEM, including custom log sources and detection content
  • Strong detection engineering skills using Python, SQL, or a rules DSL
  • Experience managing detections in version control and measuring detection quality
  • Real incident response experience, including leading investigations, writing playbooks, and running retrospectives
  • Experience with cloud-native telemetry across AWS, GCP, or Azure control planes, identity providers, endpoints, and SaaS audit logs
  • Strong programming or automation skills; Python preferred
  • Comfort building integrations and response automation
  • Experience partnering with software engineers to instrument applications for security visibility is a strong plus
  • Familiarity with securing or monitoring AI/LLM-powered systems is a strong plus
  • Experience working with MDR/MSSP providers
  • Relevant security certifications such as GIAC/GCIA/GCIH or CISSP are a plus
  • Ability to work in person at least three days per week from the Toronto office

Benefits

  • Choice of medical, dental, and vision insurance plans for you and your family
  • Additional insurance coverage options for life, accident, or critical illness
  • Flexible paid time off
  • Sick leave
  • Short-term and long-term disability
  • 10 US observed holidays and Canadian statutory holidays by province
  • Home office stipend
  • 401(k) for US-based employees
  • RRSP for Canada-based employees
  • Paid parental leave
  • Local in-person meet-up program
  • Equity

Job type

Full Time

Experience level

Senior

Salary

CA$150,000 - CA$190,000 per year

Degree requirement

No Education Requirement

Tech skills

AWSAzureCloudGoogle Cloud PlatformPythonSQL

Location requirements

HybridTorontoCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.