Senior Cybersecurity Specialist - Incident Response

location_onToronto, Ontario, CanadapaymentsCA$90,000 – CA$120,000/yrschedule22 hours ago
homeWork style:Remote
trending_upExperience level:Senior
badgeEmployment:Full-time
historyMinimum experience:5+ years
Apply Nowopen_in_new

Job description

What’s in it for you as an employee of QFG?

Health & wellbeing resources and programs

Paid vacation, personal, and sick days for work-life balance

Competitive compensation and benefits packages

Work-life balance

Career growth and development opportunities

Opportunities to contribute to community causes

Work with diverse team members in an inclusive and collaborative environment

This job posting is for an existing vacancy.

We’re looking for our next Senior Cybersecurity Specialist, Incident Response. Could It Be You?

The Senior Cybersecurity Specialist, Incident Response is a critical contributor to delivering sustainable and measurable results in identifying and responding to cyber threats - safeguarding our company's infrastructure and data. You will be primarily involved in supporting the alert development cycle, triaging and investigating alerts, managing the full incident response lifecycle (investigation, containment, eradication, and recovery) and collecting and tracking metrics for reporting. The Senior Cybersecurity Specialist, Incident Response works alongside internal customers and our vendor support teams to ensure we are utilizing our security tools in accordance with corporate policies and growing business needs. You will work closely with Cybersecurity and IT teams to align priorities and execute plans for new initiatives, as well as contribute to process improvements and build documentation for new tools.

Need more details? Keep reading…

In this role, responsibilities include but are not limited to:

Mentoring and providing technical guidance to junior SOC analysts.

Monitoring, analyzing and reporting possible cybersecurity attacks.

Investigating and performing analysis of threat indicators.

Gathering Indicators of compromise and any relevant data to use with threat hunting activities.

Leveraging security tools (Elastic, CrowdStrike and more) for analysis to identify malicious activities.

Analyzing identified malicious activity to determine Tactics, Techniques and Procedures.

Conducting research, analysis and correlate gathered data from various resources to determine the impact of the incident.

Executing containment and eradication actions following established playbooks.

Participating in on-call and hands-on scheduled shift rotations, including outside of business hours.

Coordinating Security Incident Response and investigation with other internal teams and 3rd party providers.

Documenting incident timelines, evidence, and actions taken for post-incident review.

Performing post-incident reviews and producing lessons-learned reports.

Maintaining and improving incident response playbooks and runbooks.

Participating in tabletop exercises and IR simulations.

Providing proactive security investigations and searches on corporate environments to detect malicious activities.

Maintaining up-to-date understanding of security threats, countermeasures, security tools, cloud security and SaaS technologies.

Maintaining technical proficiency through training, keeping up with industry best practices, and security frameworks.

Communicating investigation findings and risk posture to technical and non-technical stakeholders.

Owning and reporting on SOC operational metrics (MTTD, MTTR, alert fidelity).

So are YOU our next Senior Cybersecurity Specialist, Incident Response? You are if you have…

5+ years of relevant experience in performing Cybersecurity Incident Response and Threat Hunting activities in a complex incident management or Security Operations Center environment

Hands-on experience in the creation and fine-tuning of detection rules

Practical experience integrating security tools via APIs for automation, and familiarity with Security Orchestration, Automation, and Response (SOAR) concepts

Deep experience with complex investigations and incident response using EDR tools such as CrowdStrike Falcon and SIEM tools such as Elastic Security (KQL, ESQL, Timeline analysis)

Experience with forensic triage (disk, memory, network) and multiple operating systems (Mac, Linux, Windows)

Solid experience with building SOC processes, playbooks, SIEM correlation rules, and incident reports

Proven experience in incident management and communication under pressure

Knowledge of programming languages such as Python, JavaScript and others

Knowledge of NIST Cybersecurity Framework, MITRE ATT&CK

Knowledge of security products and device monitoring tools including Firewalls, IDS/IPS, Phishing and e-mail security, content filtering, DDoS, WAF, etc.

Additional kudos if you…

Hold GCIH, GCED, CCFR, HTB CDSA, GCFA, CHFI or similar relevant certifications

Additional Information…

Operating hours for this role are 3 pm to 11 pm, Monday to Friday with on-call rotations schedule, including weekends

Compensation Information:

Base salary range: $90,000 - $120,000

The final compensation package will be commensurate with the successful candidate's experience, skills, and geographic location (Canada). It includes a comprehensive benefits plan and a competitive incentive (bonus) program for Full-Time Permanent roles.

Sounds like you? Click below to apply!

#LI-NP1

#LI-Remote

Skills mentioned


Financial Services, FINTECH, Wealth Management
Toronto, Ontario, Canada

Questrade Inc. is a Canadian financial services firm that has been operating since 1999. Founded by Edward Kholodenko, who also serves as the President and CEO, the company's mission is to assist Canadians in achieving financial independence by providing them with leading investment tools and resources. Questrade has established itself as Canada's largest discount broker and a significant player in the country's financial services industry. The company is a registered investment dealer, a member of the Canadian Investment Regulatory Organization (CIRO), and a member of the Canadian Investor Protection Fund (CIPF). Questrade Financial Group Inc. is the parent company of Questrade, Inc. and Questrade Wealth Management Inc. Questrade offers a diverse range of financial products and services tailored to meet the evolving needs of investors. These include self-directed investing, allowing clients to manage their own portfolios by trading stocks, ETFs, options, and other securities. For those who prefer a hands-off approach, Questwealth Portfolios provide professionally managed, low-cost investment portfolios. The company also facilitates Forex and CFD trading, precious metals trading, and provides access to various account types such as Tax-Free Savings Accounts (TFSAs) and Registered Retirement Savings Plans (RRSPs), often with no annual account fees. Questrade is recognized for leveraging technology to lower fees and provide a viable alternative to traditional financial investment options, thereby enabling Canadians to 'Keep More of their Money'. The firm has consistently expanded its offerings, including being the first Canadian broker to offer the First Home Savings Account (FHSA). With a commitment to customer service and innovation, Questrade has garnered numerous accolades, including being named one of Canada's Best Managed Companies for over a decade and one of Greater Toronto's Top Employers. The company reports having over $50 billion in assets under administration.

Apply for this job

Use the application link supplied with this listing to apply to Questrade Financial Group. Check the destination before entering personal information.

Apply Nowopen_in_new