Senior SOC analyst leading threat detection, investigations, and incident response for Financeit, a Canadian point-of-sale financing provider. Building its new SOC’s automation, AI-threat coverage, and operational standards.
Responsibilities
Lead complex investigations, cloud/host forensics, and containment for high-severity incidents across endpoint, cloud, and SaaS environments
Participate in an on-call rotation
Write, test, tune, and manage detection rules and response playbooks as code across EDR, cloud, and log analytics platforms
Map detection coverage to MITRE ATT&CK
Conduct hypothesis-driven threat hunts
Translate financial-sector threat intelligence and purple team findings into durable detections
Document attacker activity for executive briefings and regulatory reports
Drive post-incident corrective actions with IT and engineering partners
Document and maintain investigation runbooks, operational data, SOC case details, metrics, reporting, and audit, assurance, and client-security evidence
Partner with the cybersecurity function to align detection and response priorities with the organization’s risk picture
Build and maintain automated response and enrichment playbooks within approved guardrails
Evaluate new security tooling and automation
Supervise AI triage and investigation agents
Develop detection and investigation capabilities for AI-related threats
Tune agent configuration using results and analyst feedback
Report to the Vice President of Information Technology
Help establish investigation standards, runbooks, and working practices for the new SOC team
Requirements
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related technical discipline, or equivalent practical experience
5+ years of experience in cybersecurity, including a minimum of 3 years in a security operations, incident response or detection engineering role
Experience in financial services or regulated environments is strongly preferred
Certifications in GCIH, GCFA, GCDA, GNFA, CompTIA CySA+, vendor endpoint detection credentials, cloud security certifications, and CISSP are strong assets
Familiarity with Kubernetes, OWASP Top 10 for LLMs, prompt injection risks, and MITRE ATLAS
Proven lead on complex investigations, root cause analysis, and containment across Endpoint (EDR), Identity, and Cloud (AWS) environments
Hands-on experience authoring detections as code using version control
Experience building SIEM/SOAR playbooks
Experience mapping to MITRE ATT&CK
Experience executing threat hunts
Strong query and scripting skills, with Python preferred
Experience working directly with REST APIs
Ability to participate in an on-call rotation for critical security incidents
Evening and weekend availability may be required
Successful background and credit check, among other verifications, required for employment
Benefits
An award-winning culture with a collaborative & inclusive team.
Performance-based bonus: Annual Bonus: 20%
Hybrid workplace options
Comprehensive medical, dental and vision coverage
Lifestyle Account
RRSP Matching
Parental Leave Top UP Program
In office massage, meditation & workout sessions
Virtual events such as Lunch & Learns, company parties, fun team activities and charity initiatives
Security Operations Engineer securing Tailscale’s software for safe device and network connections. Managing endpoints, identity access, platforms, automation, and data loss prevention.
Security Operations Engineer securing Tailscale’s networking platform through device, identity, access, and vulnerability management. Supporting distributed teams and automating security operations across core business systems.
Incident Response Security Engineer strengthening detection, automation, and incident management for ClickHouse’s real - time analytics cloud platform. Handling security events across products and services.
Lead cybersecurity strategy, governance, and operations at Alberta Innovates. Oversee risk management, incident response, and team leadership in a hybrid role based in Edmonton.
Security operations manager defending Forward Financing’s fintech infrastructure and AI systems. Leading incident response, detection engineering, cybersecurity risk assessments, and AI security team development.
Security Training & Operations Team Lead at OLG overseeing security operations and developing training programs for personnel across various locations. Requires strong leadership in managing safety and compliance protocols.