Senior Security Operations Analyst, Detection & Response

Posted 3 days ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Senior SOC analyst leading threat detection, investigations, and incident response for Financeit, a Canadian point-of-sale financing provider. Building its new SOC’s automation, AI-threat coverage, and operational standards.

Responsibilities

  • Lead complex investigations, cloud/host forensics, and containment for high-severity incidents across endpoint, cloud, and SaaS environments
  • Participate in an on-call rotation
  • Write, test, tune, and manage detection rules and response playbooks as code across EDR, cloud, and log analytics platforms
  • Map detection coverage to MITRE ATT&CK
  • Conduct hypothesis-driven threat hunts
  • Translate financial-sector threat intelligence and purple team findings into durable detections
  • Document attacker activity for executive briefings and regulatory reports
  • Drive post-incident corrective actions with IT and engineering partners
  • Document and maintain investigation runbooks, operational data, SOC case details, metrics, reporting, and audit, assurance, and client-security evidence
  • Partner with the cybersecurity function to align detection and response priorities with the organization’s risk picture
  • Build and maintain automated response and enrichment playbooks within approved guardrails
  • Evaluate new security tooling and automation
  • Supervise AI triage and investigation agents
  • Develop detection and investigation capabilities for AI-related threats
  • Tune agent configuration using results and analyst feedback
  • Report to the Vice President of Information Technology
  • Help establish investigation standards, runbooks, and working practices for the new SOC team

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related technical discipline, or equivalent practical experience
  • 5+ years of experience in cybersecurity, including a minimum of 3 years in a security operations, incident response or detection engineering role
  • Experience in financial services or regulated environments is strongly preferred
  • Certifications in GCIH, GCFA, GCDA, GNFA, CompTIA CySA+, vendor endpoint detection credentials, cloud security certifications, and CISSP are strong assets
  • Familiarity with Kubernetes, OWASP Top 10 for LLMs, prompt injection risks, and MITRE ATLAS
  • Proven lead on complex investigations, root cause analysis, and containment across Endpoint (EDR), Identity, and Cloud (AWS) environments
  • Hands-on experience authoring detections as code using version control
  • Experience building SIEM/SOAR playbooks
  • Experience mapping to MITRE ATT&CK
  • Experience executing threat hunts
  • Strong query and scripting skills, with Python preferred
  • Experience working directly with REST APIs
  • Ability to participate in an on-call rotation for critical security incidents
  • Evening and weekend availability may be required
  • Successful background and credit check, among other verifications, required for employment

Benefits

  • An award-winning culture with a collaborative & inclusive team.
  • Performance-based bonus: Annual Bonus: 20%
  • Hybrid workplace options
  • Comprehensive medical, dental and vision coverage
  • Lifestyle Account
  • RRSP Matching
  • Parental Leave Top UP Program
  • In office massage, meditation & workout sessions
  • Virtual events such as Lunch & Learns, company parties, fun team activities and charity initiatives
  • Career learning and development programs

Job type

Full Time

Experience level

Senior

Salary

CA$110,000 - CA$125,000 per year

Degree requirement

Bachelor's Degree

Tech skills

AWSCloudCyber SecurityKubernetesPython

Location requirements

HybridTorontoCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.