Senior Manager, Information Security, CSIRT
$136,000–$163,200 year
On-siteToronto, Ontario, Canada
Job Summary
Lead the CSIRT function coordinating response to significant cyber security incidents, including triage, scoping, containment, eradication, recovery, and post-incident improvement. Serve as the senior technical and operational escalation point during high-severity incidents, supporting executive-ready updates and decisive response actions. Partner with CSOC, Detection Engineering, and threat intelligence teams to convert incident observations into higher-fidelity detections and strengthen containment strategies. Oversee technical investigations across endpoint, cloud, identity, and network environments, ensuring rigorous forensic analysis and reproducible root cause determination. Drive development of response playbooks, automation, and orchestration to improve response speed and consistency. Establish operational metrics for CSIRT effectiveness and translate outcomes into risk-based insights for leadership decision-making.
Required Qualifications
- Prior people leadership experience in incident response, security operations, threat investigation, digital forensics, or a related cybersecurity function
- 8+ years of experience in cybersecurity, with deep experience leading or performing cyber incident response in complex enterprise environments
- Strong understanding of the incident response lifecycle, including triage, scoping, containment, eradication, recovery, root cause analysis, and post-incident improvement
- Hands-on or leadership experience with SIEM, SOAR, EDR/XDR, identity, cloud security, network telemetry, case management, and investigative tooling
- Working knowledge of digital forensics, malware analysis, threat hunting, threat intelligence, and adversary tactics, techniques, and procedures
- Experience partnering with legal, privacy, fraud, insider threat, technology operations, and business stakeholders during sensitive or high-impact cyber events
- Ability to communicate complex technical issues clearly to senior leaders and translate response actions into risk-based business outcomes
Desired Qualifications
- Experience operating within a Fusion-style, cross-domain security model integrating intelligence, detection, response, and exposure management
- Experience leading response to ransomware, credential compromise, cloud/SaaS compromise, third-party compromise, data exposure, or insider-related cyber investigations
- Experience developing response automation, playbooks, tabletop exercises, purple-team learnings, or incident-driven detection improvement processes
- Relevant certifications such as GCIH, GCFA, GCIA, GNFA, CISSP, CISM, or cloud security certifications
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.