Remote job
Senior Security Engineer, Detection and Response
Job details
About this role
Role overview A senior-level security engineering position on a Security Operations and Response team, focused on leading incident response for North American operations and shaping modern detection and response practices. The role blends hands-on investigation, detection engineering, and threat hunting with mentoring, while leveraging AI-driven automation within a next-generation agentic SOAR platform.
Responsibilities - Serve as the lead technical responder during security events in North American timezones, triaging complex alerts and acting as a core member of the cybersecurity incident response team. - Participate in a 24x7 on-call rotation, providing senior escalation support for incidents and investigations. - Engineer, maintain, and continuously tune detection logic across multiple data sources, using threat modeling to keep coverage current with the evolving attack landscape. - Design detection coverage maps that document capabilities, identify blind spots, and inform logging and monitoring improvements. - Build and maintain incident response runbooks, SOPs, and KPIs such as detection effectiveness, false positive rates, and mean time to detect, respond, and recover. - Develop automation workflows, orchestration playbooks, and AI-driven tooling that accelerate detection engineering, threat hunting, and response. - Conduct proactive, hypothesis-driven threat hunts across corporate and production environments. - Mentor junior team members on detection engineering, operations, and incident response methodologies.
Requirements - 5+ years of hands-on security operations experience with emphasis on incident response and detection engineering. - Strong working knowledge of enterprise security tools such as EDR, NDR, CSPM, EASM, SIEM, SOAR, and cloud security platforms. - Solid understanding of AWS cloud services and containerization technologies. - Proficiency applying threat intelligence frameworks such as MITRE ATT&CK to assess coverage and gaps. - Demonstrated ability to design new detection use cases from telemetry analysis, baselining, threat intel, and incident findings. - Investigative mindset, intellectual curiosity, and commitment to staying current with emerging threats and adversary tactics. - Industry certifications such as GCIH, GCFA, GIME, OSIR, or GEIR are strongly preferred.
Nice to have - Experience with programming languages such as Python, JavaScript, or Go. - Familiarity with infrastructure-as-code tools such as Terraform. - Background in threat hunting, cyber threat intelligence, or digital forensics.
Benefits and work setup - Remote-first work model within the candidate's Canadian province of residence (Ontario or British Columbia). - Competitive base salary calibrated to working location, with annual performance bonuses and equity in a publicly traded company. - Multiple health insurance options, flexible vacation with floating holidays, and a retirement savings program with company contribution. - Monthly remote work stipend, annual development stipend, and family-forming benefits with generous parental leave top-up.