Skip to content

Open nowPosted 25 days ago

Senior Security Operations Analyst, Detection & Response

Workable (global search)108,016 open roles

Where
Toronto, ON, Canada
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security Operations Analyst, Detection & ResponseWorkable (global search) · Toronto, ON, Canada
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Workable (global search)'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.9% of postings close within 7 days. Measured by our own scanner across the market. Workable (global search) postings stay open a median of 7 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.6%3 days
  3. 7.9%7 days
  4. 14.9%14 days
  5. 34.0%30 days
This job: posted 25 days ago

Workable (global search) median: 7 days open

The posting

Who we are:

Financeit is a point-of-sale financing provider serving some of the largest home improvement and retail organizations in Canada. Our platform helps businesses close more sales by offering customers affordable monthly payment options for their next big home improvement, vehicle or retail purchase.

We are small enough that you can make an impact within the company and large enough to make an impact in the market. Financeit is a company where collaboration, inclusivity, fairness, and respect aren’t just ideas that get talked about, but are part of who we are. If such a workplace intrigues you, we hope you’ll join us.

About the role:

Reporting to the Vice President of Information Technology as the first hire on our Security Operations Centre (SOC) team, you will be responsible for threat detection, investigation and incident response across endpoint, cloud, identity and production environments across the Financeit business.

In partnership with our cybersecurity team, you will handle escalated and complex investigations, build and maintain SOC detection content, and service as the main point of contact for confirmed security incidents. As this is a new team you will help establish the investigation standards, runbooks and working practices for the SOC team.

With a focus on automation and AI tooling, you’ll help build and tune automated detection and response workflows, apply judgement to the output they produce, and develop detection coverage for AI-related threats. This is a hands-on and technical role with a growing team!

What you'll be doing:

  • Lead complex investigations, cloud/host forensics, and containment for high-severity incidents across endpoint, cloud, and SaaS environments; participate in an on-call rotation.
  • Write, test, tune, and manage detection rules and response playbooks as code across EDR, cloud, and log analytics platforms, mapping coverage to MITRE ATT&CK.
  • Conduct hypothesis-driven threat hunts and translate financial-sector threat intel and purple team findings into durable detections.
  • Document attacker activity for executive briefings and regulatory reports, driving post-incident corrective actions with IT and engineering partners.
  • Document and maintain investigation runbooks, operational data and case detail behind SOC metrics and reporting, and evidence of audit, assurance, and client security
  • Partner with cybersecurity function to align detection and response priorities with the organizations risk picture
  • Build and maintain automated response and enrichment playbooks within approved guardrails and evaluate new security tooling and automation
  • Supervise AI triage and investigation agents day to day, develop detection and investigation capability for AI-related threats, and tune agent configuration with results and analyst feedback
  • As you are supporting cybersecurity, evening and weekend hours may be required

Who you are:

  • You enjoy evaluating AI/automated triage outputs with healthy skepticism to override or validate machine conclusions
  • You can write clear technical reports and translate complex security incidents for executive and non-technical stakeholders
  • You’re a team player and can participate in an on-call rotation for critical security incidents

Requirements

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related technical discipline, or equivalent practical experience
  • 5+ years of experience in cybersecurity, including a minimum of 3 years in a security operations, incident response or detection engineering role
  • Experience in financial services or regulated environments is strongly preferred
  • Certifications in GCIH, GCFA, GCDA, GNFA, CompTIA CySA+, vendor endpoint detection credentials, and cloud security certifications, and CISSP are strong assets
  • Familiarity with Kubernetes, OWASP Top 10 for LLMs, prompt injection risks, and MITRE ATLAS
  • Proven lead on complex investigations, root cause analysis, and containment across Endpoint (EDR), Identity, and Cloud (AWS) environments
  • Hands-on experience authoring detections as code (version control), building SIEM/SOAR playbooks, mapping to MITRE ATT&CK, and executing threat hunts
  • Strong query and scripting skills (Python preferred), with experience working directly with REST APIs

Benefits

Winner of Canada’s Most Admired Corporate Cultures, twice. We offer more than just the basics, take advantage of:

  • An award-winning culture with a collaborative & inclusive team.
  • Competitive pay and performance-based bonus:
  • Annual Base Salary: $110,000 - $125,000
  • Annual Bonus: 20%
  • Committed to flexible work arrangements, offering hybrid workplace options.
  • Comprehensive medical, dental and vision coverage + Lifestyle Account.
  • RRSP Matching and Parental Leave Top UP Program.
  • In office massage, meditation & workout sessions.
  • Virtual events such as Lunch & Learns, company parties, fun team activities and charity initiatives.
  • Career learning and development programs.

Next Steps:

If what you just read excites you, we’d like to hear from you! Please submit your application and we’ll contact you if you are selected to move forward in the process.

Financeit is an equal opportunity employer. We celebrate diverse backgrounds and perspectives because we know they make our team stronger and our product better. We hire based on talent, potential, and culture add - no matter your background, identity, or life experience, you are welcome here.

We may use AI to support our hiring process. While these tools assist our team, applications are ultimately reviewed and assessed by our recruiters. If you require accommodation at any stage of the recruitment process, please let our People Success team know. Please note that this posting is for an existing vacancy, and all employment offers are contingent upon a successful background and credit check, among other verifications.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Workable (global search)'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Workable (global search)'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Workable (global search)'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.