Senior Security Engineer building EvenUp’s detection and response program for legal technology serving personal injury lawyers and victims. Designing SIEM, telemetry, detections, and incident-response operations.
Responsibilities
Build and implement the detection platform, including SIEM evaluation, log ingestion and routing pipelines, and hot-search versus long-term archive decisions
Develop and tune high-signal detection content across cloud, identity, endpoint, SaaS, and application telemetry
Build business-logic detections using product audit events
Partner with Engineering and DevOps to define application and infrastructure logging requirements and security telemetry contracts
Build and maintain incident-response playbooks and runbooks
Coordinate response during security events
Run the annual tabletop exercise and lead post-incident reviews
Detect sensitive data exposure, including PHI, across applications, endpoints, and SaaS
Define requirements for managed detection partners, own escalation procedures, and manage 24/7 coverage quality
Requirements
5+ years in security operations, detection engineering, or incident response
Experience building a detection and response capability at a startup or high-growth technology company
Hands-on experience implementing or significantly maturing a SIEM, including custom log sources and detection content
Strong detection engineering skills using Python, SQL, or a rules DSL
Experience managing detections in version control and measuring detection quality
Real incident response experience, including leading investigations, writing playbooks, and running retrospectives
Experience with cloud-native telemetry across AWS, GCP, or Azure control planes, identity providers, endpoints, and SaaS audit logs
Strong programming or automation skills; Python preferred
Comfort building integrations and response automation
Experience partnering with software engineers to instrument applications for security visibility is a strong plus
Familiarity with securing or monitoring AI/LLM-powered systems is a strong plus
Experience working with MDR/MSSP providers
Relevant security certifications such as GIAC/GCIA/GCIH or CISSP are a plus
Ability to work in person at least three days per week from the Toronto office
Benefits
Choice of medical, dental, and vision insurance plans for you and your family
Additional insurance coverage options for life, accident, or critical illness
Flexible paid time off
Sick leave
Short-term and long-term disability
10 US observed holidays and Canadian statutory holidays by province
Information Security Specialist strengthening technology controls, security governance, and risk management at TD, a major North American bank. Advising partners, assessing controls, supporting audits, and responding to incidents.
Buildings, development and security Analyst supporting fire prevention, facility safety, and building management at Desjardins. Analyzing risks, developing safety plans, and implementing physical security systems.
BMO banking associate providing bilingual credit and lending sales and service remotely in Quebec. Handling customer contacts, credit decisions, compliance, and suspicious - activity reporting.
Principal Information Security Engineer defining scalable security strategy, architecture, automation, cloud, identity, and AI controls. Helping Arctic Wolf protect organizations worldwide and end cyber risk.
Consultant cybersécurité hybride à Montréal chez I - TRACING, pure - player indépendant en sécurité informatique. Conception, déploiement et support de solutions IAM, réseau, systèmes et applications.
Desjardins property technician supporting fire prevention, building safety, management, and build - out projects. Providing technical support, process coordination, user training, and operational guidance.