The posting
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Incident Response Analyst, MDR based in Canada.
This is a senior cybersecurity role focused on protecting organizations during complex, high-impact security incidents. You will lead advanced incident response engagements involving sophisticated adversaries, multi-vector attacks, and cross-environment compromise. The role combines deep technical investigation with strategic leadership, customer communication, and containment decision-making. You will operate across responder, advisor, and commander responsibilities depending on the complexity and severity of each engagement. You will collaborate closely with SOC, threat intelligence, and detection engineering teams to strengthen visibility and response capabilities. The position also provides opportunities to mentor security professionals and improve incident response playbooks, tooling, and workflows. This is a remote role suited to an experienced cybersecurity professional who thrives in high-pressure, time-sensitive environments.
Accountabilities
- Lead complex incident investigations involving advanced adversaries, multi-vector intrusions, and compromise across multiple environments.
- Serve as the primary Incident Advisor or designated Commander for high-severity and critical security engagements.
- Direct investigative, forensic, and containment activities across multiple analysts and response teams.
- Establish investigation strategies, priorities, and containment approaches based on business risk, technical findings, and incident impact.
- Validate, correlate, and synthesize technical findings into clear and actionable recommendations for customers and internal stakeholders.
- Provide technical leadership, mentorship, and oversight to incident response and security operations analysts.
- Collaborate with SOC, Threat Intelligence, and Detection Engineering teams to validate detections, identify visibility gaps, and improve defensive capabilities.
- Lead or contribute to post-incident reviews and translate lessons learned into improvements to playbooks, tools, processes, and response workflows.
- Maintain accurate records of time and activities to support operational visibility, resource planning, and capacity management.
- Communicate effectively with customer stakeholders, including senior and executive-level audiences, throughout critical incidents.
- At least 5 years of professional experience in incident response, managed detection and response, cybersecurity investigations, or a closely related field, including leadership of complex incidents.
- Advanced expertise in endpoint and network forensics, log analysis, and adversary tactics, techniques, and procedures.
- Strong understanding of enterprise network architecture, IT infrastructure, and security environments.
- Proven ability to lead investigations, validate technical findings, assess risk, and develop effective containment strategies.
- Experience translating complex technical findings into concise, actionable guidance for customers and senior stakeholders.
- Demonstrated ability to mentor analysts and provide technical leadership within incident response or security operations teams.
- Strong decision-making, analytical, and problem-solving skills, with the ability to operate effectively under pressure and within time-sensitive situations.
- Strong customer-facing communication and presentation skills, including the ability to brief executive audiences during security incidents.
- Willingness to participate in an occasional weekend and holiday rotation.
- Advanced incident response or digital forensics certifications such as GCFA, GCED, GCIH, OSCP, or equivalent are an asset.
- Experience serving as an Incident Advisor or Commander during critical engagements is an asset.
- Cybersecurity publications, presentations, community contributions, or other recognized industry involvement are considered an advantage.
- Experience influencing detection strategies, security tooling, or cybersecurity service design is an asset.
- Base salary ranging from $131,000 to $219,000 CAD per year.
- Additional compensation opportunities, including bonus eligibility.
- Comprehensive employee benefits package.
- Remote-first working model, with remote work as the primary option for most positions.
- Employee-led diversity and inclusion networks supporting community, education, and advocacy.
- Paid volunteer days and opportunities to participate in charitable and fundraising initiatives.
- Employee sustainability initiatives supporting environmental responsibility.
- Global fitness and trivia activities.
- Global wellbeing days and monthly wellbeing webinars and training.
- Inclusive work environment with accommodations available throughout the recruitment and selection process.
- Opportunity to work on advanced cybersecurity investigations and collaborate with specialists across incident response, threat intelligence, SOC, and detection engineering.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1



