{"id":788853,"url":"https://alion.io/job/financeit-senior-security-operations-analyst-detection-response","title":"Senior Security Operations Analyst, Detection & Response","company":{"id":673810,"name":"Financeit","domain":"financeit.io","url":"https://alion.io/company/financeit","size_band":null,"is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workable","truth_index":{"grade":"A","score":85,"open_postings":5,"ghost_share":0,"stale_share":0.6,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-02T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Toronto, Canada"],"countries":["CA"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":89000,"max_usd":205000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":50},"experience_years_min":null,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Kubernetes","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"OWASP Top 10","optional":false},{"name":"Python","optional":false},{"name":"Rest API","optional":false},{"name":"SIEM","optional":false}],"status":"live","first_seen_at":"2026-09-09T00:00:00Z","employer_posted_date":"2026-09-09","last_verified_at":"2026-10-02T09:41:32Z","board_verified":true,"closed_at":null,"days_open":24,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":24},"description":"Who we are:\nFinanceit is a point-of-sale financing provider serving some of the largest home improvement and retail organizations in Canada. Our platform helps businesses close more sales by offering customers affordable monthly payment options for their next big home improvement, vehicle or retail purchase.\nWe are small enough that you can make an impact within the company and large enough to make an impact in the market. Financeit is a company where collaboration, inclusivity, fairness, and respect aren’t just ideas that get talked about, but are part of who we are. If such a workplace intrigues you, we hope you’ll join us.\nAbout the role:\nReporting to the Vice President of Information Technology as the first hire on our Security Operations Centre (SOC) team, you will be responsible for threat detection, investigation and incident response across endpoint, cloud, identity and production environments across the Financeit business.\nIn partnership with our cybersecurity team, you will handle escalated and complex investigations, build and maintain SOC detection content, and service as the main point of contact for confirmed security incidents. As this is a new team you will help establish the investigation standards, runbooks and working practices for the SOC team.\nWith a focus on automation and AI tooling, you’ll help build and tune automated detection and response workflows, apply judgement to the output they produce, and develop detection coverage for AI-related threats. This is a hands-on and technical role with a growing team!\nWhat you'll be doing:\nLead complex investigations, cloud/host forensics, and containment for high-severity incidents across endpoint, cloud, and SaaS environments; participate in an on-call rotation.\nWrite, test, tune, and manage detection rules and response playbooks as code across EDR, cloud, and log analytics platforms, mapping coverage to MITRE ATT&CK.\nConduct hypothesis-driven threat hunts and translate financial-sector threat intel and purple team findings into durable detections.\nDocument attacker activity for executive briefings and regulatory reports, driving post-incident corrective actions with IT and engineering partners.\nDocument and maintain investigation runbooks, operational data and case detail behind SOC metrics and reporting, and evidence of audit, assurance, and client security \nPartner with cybersecurity function to align detection and response priorities with the organizations risk picture \nBuild and maintain automated response and enrichment playbooks within approved guardrails and evaluate new security tooling and automation \nSupervise AI triage and investigation agents day to day, develop detection and investigation capability for AI-related threats, and tune agent configuration with results and analyst feedback \nAs you are supporting cybersecurity, evening and weekend hours may be required\nWho you are:\nYou enjoy evaluating AI/automated triage outputs with healthy skepticism to override or validate machine conclusions\nYou can write clear technical reports and translate complex security incidents for executive and non-technical stakeholders\nYou’re a team player and can participate in an on-call rotation for critical security incidents\nRequirements\nBachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related technical discipline, or equivalent practical experience\n5+ years of experience in cybersecurity, including a minimum of 3 years in a security operations, incident response or detection engineering role\nExperience in financial services or regulated environments is strongly preferred\nCertifications in GCIH, GCFA, GCDA, GNFA, CompTIA CySA+, vendor endpoint detection credentials, and cloud security certifications, and CISSP are strong assets \nFamiliarity with Kubernetes, OWASP Top 10 for LLMs, prompt injection risks, and MITRE ATLAS\nProven lead on complex investigations, root cause analysis, and containment across Endpoint (EDR), Identity, and Cloud (AWS) environments\nHands-on experience authoring detections as code (version control), building SIEM/SOAR playbooks, mapping to MITRE ATT&CK, and executing threat hunts\nStrong query and scripting skills (Python preferred), with experience working directly with REST APIs\nBenefits\nWinner of Canada’s Most Admired Corporate Cultures, twice. We offer more than just the basics, take advantage of:\nAn award-winning culture with a collaborative & inclusive team.\nCompetitive pay and performance-based bonus:\nAnnual Base Salary: $110,000 - $125,000\nAnnual Bonus: 20%\nCommitted to flexible work arrangements, offering hybrid workplace options.\nComprehensive medical, dental and vision coverage + Lifestyle Account.\nRRSP Matching and Parental Leave Top UP Program.\nIn office massage, meditation & workout sessions.\nVirtual events such as Lunch & Learns, company parties, fun team activities and charity initiatives.\nCareer learning and development programs.\nNext Steps:\nIf what you just read excites you, we’d like to hear from you! Please submit your application and we’ll contact you if you are selected to move forward in the process.\nFinanceit is an equal opportunity employer. We celebrate diverse backgrounds and perspectives because we know they make our team stronger and our product better. We hire based on talent, potential, and culture add - no matter your background, identity, or life experience, you are welcome here.\nWe may use AI to support our hiring process. While these tools assist our team, applications are ultimately reviewed and assessed by our recruiters. If you require accommodation at any stage of the recruitment process, please let our People Success team know. Please note that this posting is for an existing vacancy, and all employment offers are contingent upon a successful background and credit check, among other verifications.","description_format":"text","description_chars":5860,"description_truncated":false,"requirements":{"experience_years_min":null,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":["Flexible schedule","Parental leave"],"hiring_locations":[{"name":"Canada","iso":"CA","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Financial Software & Embedded Finance","Incident Response","Buy Now, Pay Later"],"lifecycle":[{"event":"open","at":"2026-09-12T02:41:57Z"}],"liveness":{"score":48,"band":"ok","label":"Likely open","p_open":1,"p_active":0.644,"p_room":0.75,"age_days":23,"expected_fill_days":24,"reasons":["conf:11","win:late"],"computed_at":"2026-10-02T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/financeit-senior-security-operations-analyst-detection-response","json_url":"https://alion.io/job/financeit-senior-security-operations-analyst-detection-response.json","meta":{"generated_at":"2026-10-03T04:02:25Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4072,"day_limit":5000,"remaining_today":928,"minute_limit":60,"resets_at":"2026-10-04T00:00:00Z"}}}