Overview
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer, Detection and Response b
Full job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer, Detection and Response based in Canada. Join a Security Operations and Response team focused on strengthening enterprise security through advanced detection and incident response capabilities. You will lead complex security investigations across North American time zones and serve as a senior technical responder during critical incidents. The role combines detection engineering, threat hunting, incident response, and security automation in a cloud-native environment. You will help shape next-generation security operations by developing AI-driven tools and automated response workflows. Your work will directly improve threat visibility, reduce response times, and strengthen the organization’s overall security posture. You will also mentor junior engineers and collaborate closely with security, infrastructure, and engineering stakeholders. This is a fully remote opportunity available to professionals located in Ontario or British Columbia.
Act as the lead security responder for North American time zones, triaging and investigating complex alerts and supporting the Cybersecurity Incident Response Team. Participate in a 24x7x365 on-call rotation, providing senior-level expertise and escalation support during security events and incidents. Engineer, maintain, and continuously optimize detection logic across multiple security data sources using threat modeling and current threat intelligence. Design and maintain detection coverage maps to identify capabilities, visibility gaps, and areas requiring additional monitoring. Develop and track security KPIs with leadership, including detection effectiveness, false-positive rates, and mean time to detect, respond, and recover. Create and maintain incident response runbooks, standard operating procedures, and technical documentation to promote consistent response practices. Build automation workflows and orchestration playbooks that improve detection engineering, threat hunting, and incident response efficiency. Develop and leverage AI-driven tools to accelerate security investigations and strengthen Security Operations and Incident Response capabilities. Conduct proactive, hypothesis-driven threat hunts across corporate and production environments. Support the logging and monitoring infrastructure required for effective threat detection and investigation. Mentor junior team members in security operations, detection engineering, and incident response methodologies. Requirements: 5+ years of hands-on experience in security operations, with a strong focus on incident response and detection engineering. Additional experience in threat hunting, cyber threat intelligence, and digital forensics is highly valued. Strong investigative instincts and intellectual curiosity, with the ability to analyze anomalies, follow evidence trails, and reconstruct complex security incidents from fragmented data. Solid technical expertise across enterprise security technologies, including EDR, NDR, CSPM, EASM, SIEM, SOAR, and cloud security platforms such as AWS GuardDuty. Strong knowledge of threat intelligence frameworks, particularly MITRE ATT&CK, and experience applying them to assess detection capabilities and coverage gaps. Demonstrated ability to develop threat detection use cases based on telemetry analysis, environment baselining, actionable threat intelligence, and incident response findings. Experience identifying detection and visibility gaps across infrastructure and collaborating with stakeholders to improve logging and detection content. Strong understanding of AWS cloud services and containerization technologies. Industry certifications in incident response or related disciplines, such as GCIH, GCFA, GIME, OSIR, or GEIR, are strongly preferred. Programming experience with Python, JavaScript, or Go is an asset. Familiarity with infrastructure-as-code tools such as Terraform is an asset. Experience with forensic tools such as KAPE, EnCase, FTK, or Volatility is a plus. Experience with Detection-as-Code technologies such as Sigma or YARA is a plus. Experience conducting Purple Team exercises, validating vulnerabilities or reported bugs, and working with observability or SRE tools and processes is beneficial. Benefits: Competitive base salary of CAD 136,800–171,000 , depending on location, skills, and experience. Annual bonus opportunities based on individual and organizational performance. Multiple health insurance options. Flexible vacation time plus additional floating holidays. Retirement savings program with company contributions. Equity in a publicly traded company. Monthly stipend to support remote work. Annual professional development stipend. Family-forming benefits. Generous parental leave with base salary top-up. Fully remote work within Ontario or British Columbia, Canada .
Tips for this job
Practical JobOpportunity guidance. These tips do not replace official rules or create new eligibility requirements.
- Tailor the CV and application to the responsibilities and required skills stated on the official employer page.
- Use concrete evidence of relevant work, projects and measurable results rather than generic claims.
- Confirm location, work authorization, remote restrictions and sponsorship terms before applying.
- Apply through the original employer or official recruitment destination shown on this page.
JobOpportunity.info helps you discover and organize source listings. Confirm eligibility, dates, salary/funding and application instructions on the original source before submitting anything.
Apply through JobOpportunity →Browse current JobOpportunity listings from jobgether (lever) →