Senior Cyber Security Specialist - Cyber Incident Management
$96,727–$138,142 year
HybridStellarton, Nova Scotia, Canada or Calgary, Alberta, Canada
Job Summary
Lead the Cyber Incident Management team by conducting alert triage, investigations, and containment while mentoring specialists on complex troubleshooting. Execute thorough incident response during major security events, coordinating strategies and guiding the team through the full lifecycle. Optimize security use cases using SIEM, EDR, and other tools to reduce false positives and enhance detection efficacy. Develop and refine incident response playbooks, SOPs, and documentation for lessons learned, while defining monthly metrics to measure operational effectiveness. Collaborate closely with internal IT teams and the Managed Security Service Provider on escalation and prevention strategies. This role requires 5+ years of experience, advanced certifications like GCIH, and the ability to work nights and weekends. Based in Stellarton, Mississauga, Calgary, or Burnaby, with a salary range of $96,727–$138,142.
Required Qualifications
- An undergraduate degree or diploma in computer science, information security, or a related technical discipline.
- 5+ years of progressive industry experience working in Cybersecurity operations, with a significant focus on Incident Response and Security Operations (SecOps) leadership or senior roles.
- Demonstrated expertise in leading and conducting complex security investigations and incident response efforts across various security domains (e.g., network, endpoint, cloud, applications).
- Strong understanding of network and system security concepts, including TCP/IP, operating systems (Windows, Linux), common attack vectors, and defensive strategies.
- Proficiency in using a variety of security tools and technologies, including but not limited to: SIEM, EDR, IDS/IPS, Firewalls, Email security gateways, Proxy, etc.
- Excellent analytical and problem-solving skills with a methodical approach to complex investigations.
- Strong attention to detail and the ability to work effectively and make sound decisions under pressure during critical incidents.
- Ability to work outside of regular business hours, including nights and weekends, to respond to security incidents.
- Excellent written and verbal communication skills, with the ability to articulate highly technical information clearly and concisely to diverse audiences, including senior management and non-technical stakeholders.
- Strong interpersonal skills, with a proven ability to build rapport, influence, and collaborate effectively with diverse teams, external partners, and vendors.
- Advanced industry certification(s) such as GCIH, GCFA, ECIH, OSIR, BTL2, or equivalent.
- Please note: Successful candidates will be required to provide documentation to prove their legal ability to work in the position during the onboarding process.
Desired Qualifications
- Proven experience working directly in or closely with Managed Security Service Providers (MSSPs) at a senior or lead level.
- Knowledge and experience working in a complex retail technology environment is highly desired.
- Demonstrated experience in developing and implementing Digital Forensics and Incident Response (DFIR) programs, including handling complex and large-scale incidents such as Business Email Compromise (BEC), Ransomware, or advanced persistent threats.
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.