428,943open jobs
14,661companies
61,923added this week
Browse all
Salary
$108k – $228k per year (Estimated)
Location
Remote/Hybrid (Canada)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Jobgether is a Belgian recruitment platform built entirely around remote and flexible work, aggregating openings from thousands of employers that allow work from outside an office. Its matching engine ranks roles against a candidate's skills, seniority and stated preferences on location and flexibility, rather than leaving people to filter a keyword search, and it verifies how genuinely remote each posting is. The company also runs an AI screening layer that shortlists applicants for employers, and publishes research and guidance on distributed work practices alongside the job marketplace itself.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Engineer - Security Operations and Incident Response based in Canada.

This role is central to strengthening and continuously evolving a global Security Operations and Incident Response program.

You will help protect enterprise environments by identifying, investigating, containing, and eradicating sophisticated cybersecurity threats.

The position combines deep technical investigations with detection engineering, threat intelligence, automation, and incident response.

You will work across hybrid cloud environments while improving security processes, technologies, and operational resilience.

Your expertise will help close visibility gaps, strengthen detection capabilities, and reduce risk across the organization.

You will also contribute to playbooks, threat models, documentation, and continuous optimization of SOC tooling and workflows.

This is an opportunity to make a direct impact on enterprise security while working with advanced cybersecurity technologies and frameworks.

Accountabilities:

    • Conduct expert-level investigations into complex security incidents, including digital forensics involving memory, network traffic, and malware analysis.
    • Develop, author, and continuously refine incident response playbooks and operational guidelines to ensure effective responses to evolving threats.
    • Develop and maintain threat models, incorporating penetration testing findings into detection strategies and security improvements.
    • Design, implement, and optimize sophisticated detection rules and automated remediation workflows to identify and respond to adversarial behavior.
    • Leverage threat intelligence and the MITRE ATT&CK framework to identify visibility gaps and proactively mitigate emerging cybersecurity risks.
    • Maintain comprehensive documentation covering detection strategies, active investigations, incident timelines, and response activities.
    • Partner with SIEM teams to continuously tune detection rules, improving detection fidelity while minimizing false positives and alert fatigue.
    • Review and optimize threat intelligence capabilities, including brand protection and dark web monitoring systems.
    • Develop scripts and queries using technologies such as Python, XQL, PowerShell, and Bash to support security investigations and operational efficiency.
    • Implement and maintain automation and orchestration capabilities through SOAR tools and related technologies.
    • Support incident response leadership as a backup resource for incident response activities and operational priorities.
    • Contribute to the continuous improvement of security operations processes, technologies, and overall incident response maturity.
    • Requirements:

      • Bachelor's degree and at least 5 years of relevant professional experience in incident response and Security Operations Center (SOC) tooling.
      • In-depth knowledge of SIEM and SOAR platforms, with experience in technologies such as Microsoft Sentinel, Palo Alto Cortex XSIAM, and Cortex XSOAR.
      • Strong understanding of incident response processes within hybrid cloud environments, including GCP and Azure.
      • Experience serving as an incident commander during security incidents and leading coordinated response efforts.
      • Proven ability to conduct root cause analysis and drive continuous optimization of SOC tools, processes, and detection capabilities.
      • Strong scripting and query-building skills using Python, PowerShell, Bash, and/or XQL.
      • Understanding of cybersecurity frameworks and regulatory requirements, including MITRE ATT&CK, NIST, and ISO.
      • Experience with threat intelligence, detection engineering, security automation, and incident response processes.
      • Strong analytical and problem-solving skills, with the ability to investigate complex security events and develop practical solutions.
      • Ability to prioritize effectively, manage multiple concurrent priorities, and work independently as well as collaboratively.
      • Excellent written and verbal communication skills, including the ability to translate sophisticated technical security concepts into clear, concise business-focused explanations.
      • Benefits:

        • Remote or hybrid work options.
        • Opportunity to work on the ongoing transformation of a global Security Operations and Incident Response program.
        • Exposure to advanced cybersecurity technologies, including SIEM, SOAR, threat intelligence, security automation, and cloud security platforms.
        • Opportunity to work with modern security frameworks and methodologies such as MITRE ATT&CK, NIST, and ISO.
        • High-impact role focused on strengthening enterprise resilience and protecting against evolving cybersecurity threats.
        • Opportunity to contribute to continuous process improvement and the advancement of security operations capabilities.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
428,943 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$21k – $55k per year (Estimated) • In office • Full-Time • Bengaluru
Python
JavaScript
PowerShell
AI/ML
AI Agents
LLM
RAG
LLM Guardrails
Agentic Workflows
DevOps
Terraform
GCP
CloudFormation
Azure
CI/CD
AWS
Docker
Kubernetes
Cybersecurity
OWASP Top 10
Threat Modeling
Apply
$27k – $64k per year (Estimated) • In office • 6+ years exp • Bengaluru
Python
Go
Java
Kotlin
TypeScript
Python
FastAPI
Databases
PostgreSQL
Redis
Apache Kafka
AI/ML
Airflow
Fine-tuning
Embeddings
NLP
RAG
Semantic Search
Semantic Search
Knowledge Graph
DevOps
GCP
OpenTelemetry
Prometheus
Azure
CI/CD
AWS
Kubernetes
Grafana
Vector
Honeycomb
Apply
$89k – $198k per year (Estimated) • Remote • Full-Time • 6+ years exp
JavaScript
C++
Node JS
Apply
$68k – $152k per year (Estimated) • Remote • Full-Time • 6+ years exp
JavaScript
C++
Node JS
Apply
$23k – $45k per year (Estimated) • Remote • Full-Time • Moscow
Python
SQL
Databases
PostgreSQL
Greenplum
AI/ML
Airflow
DevOps
Git
Analytics
ETL/ELT
Apply
$89k – $198k per year (Estimated) • Remote • Full-Time • 6+ years exp
JavaScript
C++
Node JS
Apply
$68k – $152k per year (Estimated) • Remote • Full-Time • 6+ years exp
JavaScript
C++
Node JS
Apply
$58k – $127k per year (Estimated) • Remote • Full-Time • 6+ years exp
JavaScript
C++
Node JS
Apply
$46k – $103k per year (Estimated) • Remote • Full-Time • 6+ years exp
JavaScript
C++
Node JS
Apply
$92k – $180k per year (Estimated) • Equity • Remote • Full-Time • 5+ years exp • Bachelor's Degree
Apply
See all jobs
This is one of many
428,943 more open roles from verified company boards, updated every day.