Skip to content

Open nowPosted 24 hours ago

Principal Cybersecurity Specialist, Incident Response

Questrade Financial Group81 open roles

Where
North American Centre, 5700 Yonge St, North York, ON M2N 5M9, Canada
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowPrincipal Cybersecurity Specialist, Incident ResponseQuestrade Financial Group · North American Centre, 5700 Yonge St, North York, ON M2N 5M9, Canada
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Questrade Financial Group's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.3% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.9%1 day
  2. 4.0%3 days
  3. 8.3%7 days
  4. 15.3%14 days
  5. 34.2%30 days
This job: posted 24 hours ago

The posting

What’s in it for you as an employee of QFG?

Health & wellbeing resources and programs 

Paid vacation, personal, and sick days for work-life balance

Competitive compensation and benefits packages

Work-life balance in a hybrid environment with at least 3 days in office

Career growth and development opportunities

Opportunities to contribute to community causes

Work with diverse team members in an inclusive and collaborative environment

  This job posting is for an existing vacancy.    We’re looking for our next Principal Cybersecurity Specialist, Incident Response. Could It Be You? The Principal Cybersecurity Specialist, Incident Response is a critical contributor to delivering sustainable and measurable results in identifying and responding to cyber threats - safeguarding our company's infrastructure and data. You will be primarily involved in leading the alert development cycle, triaging and investigating alerts, managing the full incident response lifecycle (investigation, containment, eradication, and recovery) and collecting and tracking metrics for reporting. The Principal Cybersecurity Specialist, Incident Response works alongside internal customers and our vendor support teams to ensure we are utilizing our security tools in accordance with corporate policies and growing business needs. You will work closely with Cybersecurity and IT teams to align priorities and execute plans for new initiatives, as well as drive process improvements and establish documentation for new tools.   Need more details? Keep reading… In this role, responsibilities include but are not limited to:

Mentoring and elevating the technical capabilities of the SOC team.

Monitoring, analyzing and reporting possible cybersecurity attacks.

Investigating and performing analysis of threat indicators.

Gathering Indicators of compromise and any relevant data to use with threat hunting activities.

Leveraging security tools (Elastic, CrowdStrike and more) for analysis to identify malicious activities.

Analyzing identified malicious activity to determine Tactics, Techniques and Procedures.

Conducting research, analysis and correlating gathered data from various resources to determine the impact of the incident.

Leading containment and eradication efforts, making critical decisions during high-severity incidents.

Participating in on-call and hands-on scheduled shift rotations, including outside of business hours.

Leading Security Incident Response and serving as the escalation point for complex investigations across internal teams and third party providers.

Documenting incident timelines, evidence, and actions taken for post-incident review.

Leading post-incident reviews and driving continuous improvement from lessons learned.

Defining and continuously improving the SOC's incident response playbooks, runbooks, and detection strategy.

Designing and leading tabletop exercises and IR simulations.

Coordinating and running proactive investigations and threat hunts across corporate environments and detecting malicious activities.

Maintaining up-to-date understanding of security threats, countermeasures, security tools, cloud security and SaaS technologies.

Setting the standard for technical proficiency; evaluating and recommending tools, techniques, and methodologies for the team.

Presenting investigation, incident response findings and strategic recommendations to senior leadership and executive stakeholders.

Defining, owning, and reporting on SOC operational metrics (MTTD, MTTR, alert fidelity) and using data to drive strategic improvements.

  So are YOU our next Principal Cybersecurity Specialist, Incident Response? You are if you have…

8+ years of relevant experience in performing and leading Cybersecurity Incident Response and Threat Hunting activities in a complex incident management or Security Operations Center environment

Extensive experience designing, implementing and optimizing detection rules and detection-as-code frameworks

Demonstrated expertise integrating security tools via APIs for automation, and hands-on experience implementing Security Orchestration, Automation, and Response (SOAR) workflows

Deep expertise leading complex, multi-vector investigations and incident response using EDR tools such as CrowdStrike Falcon and SIEM tools such as Elastic Security (KQL, ESQL, Timeline analysis)

Advanced experience with forensic triage (disk, memory, network) and multiple operating systems (Mac, Linux, Windows)

Proven track record of designing and maturing SOC processes, playbooks, detection strategies, SIEM correlation rules, and incident reports

Proven ability to lead incident management for high-severity incidents, with excellent communication under pressure

Proficiency in programming languages such as Python, JavaScript and others for security automation and tooling development

Deep understanding of NIST Cybersecurity Framework, MITRE ATT&CK, and ability to apply them to detection engineering and threat modeling

Comprehensive understanding of security products and device monitoring tools including Firewalls, IDS/IPS, Phishing and e-mail security, content filtering, DDoS, WAF, and more

Demonstrated experience mentoring and developing technical skills across a security team

Strong ability to translate technical findings into strategic recommendations for leadership

Experience with cloud-native security monitoring (GCP, AWS, Azure)

  Additional kudos if you…

Hold GCIH, GCED, CCFR, HTB CDSA, GCFA, CHFI, GREM, OSCP, CISSP or similar relevant certifications

  Additional Information…

Operating hours for this role are standard office hours, Monday to Friday with on-call scheduled rotations, including weekends and evenings

  Compensation Information:

Base salary range: $120,000 - $140,000

The final compensation package will be commensurate with the successful candidate's experience, skills, and geographic location (Canada). It includes a comprehensive benefits plan and a competitive incentive (bonus) program for Full-Time Permanent roles.

  Sounds like you? Click below to apply! #LI-NP1 #LI-Hybrid

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Questrade Financial Group's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Questrade Financial Group's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Questrade Financial Group's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.