Senior Security Engineer, Detection and Response
Quick Summary
5+ years of hands-on experience in security operations, with a strong focus on incident response and detection engineering. Additional experience in threat hunting, cyber threat intelligence,
Join a Security Operations and Response team focused on strengthening enterprise security through advanced detection and incident response capabilities.
You will lead complex security investigations across North American time zones and serve as a senior technical responder during critical incidents.
The role combines detection engineering, threat hunting, incident response, and security automation in a cloud-native environment.
You will help shape next-generation security operations by developing AI-driven tools and automated response workflows.
Your work will directly improve threat visibility, reduce response times, and strengthen the organization’s overall security posture.
You will also mentor junior engineers and collaborate closely with security, infrastructure, and engineering stakeholders.
This is a fully remote opportunity available to professionals located in Ontario or British Columbia.
-
Act as the lead security responder for North American time zones, triaging and investigating complex alerts and supporting the Cybersecurity Incident Response Team.
-
Participate in a 24x7x365 on-call rotation, providing senior-level expertise and escalation support during security events and incidents.
-
Engineer, maintain, and continuously optimize detection logic across multiple security data sources using threat modeling and current threat intelligence.
-
Design and maintain detection coverage maps to identify capabilities, visibility gaps, and areas requiring additional monitoring.
-
Develop and track security KPIs with leadership, including detection effectiveness, false-positive rates, and mean time to detect, respond, and recover.
-
Create and maintain incident response runbooks, standard operating procedures, and technical documentation to promote consistent response practices.
-
Build automation workflows and orchestration playbooks that improve detection engineering, threat hunting, and incident response efficiency.
-
Develop and leverage AI-driven tools to accelerate security investigations and strengthen Security Operations and Incident Response capabilities.
-
Conduct proactive, hypothesis-driven threat hunts across corporate and production environments.
-
Support the logging and monitoring infrastructure required for effective threat detection and investigation.
-
Mentor junior team members in security operations, detection engineering, and incident response methodologies.
Requirements
~2 min read-
5+ years of hands-on experience in security operations, with a strong focus on incident response and detection engineering.
-
Additional experience in threat hunting, cyber threat intelligence, and digital forensics is highly valued.
-
Strong investigative instincts and intellectual curiosity, with the ability to analyze anomalies, follow evidence trails, and reconstruct complex security incidents from fragmented data.
-
Solid technical expertise across enterprise security technologies, including EDR, NDR, CSPM, EASM, SIEM, SOAR, and cloud security platforms such as AWS GuardDuty.
-
Strong knowledge of threat intelligence frameworks, particularly MITRE ATT&CK, and experience applying them to assess detection capabilities and coverage gaps.
-
Demonstrated ability to develop threat detection use cases based on telemetry analysis, environment baselining, actionable threat intelligence, and incident response findings.
-
Experience identifying detection and visibility gaps across infrastructure and collaborating with stakeholders to improve logging and detection content.
-
Strong understanding of AWS cloud services and containerization technologies.
-
Industry certifications in incident response or related disciplines, such as GCIH, GCFA, GIME, OSIR, or GEIR, are strongly preferred.
-
Programming experience with Python, JavaScript, or Go is an asset.
-
Familiarity with infrastructure-as-code tools such as Terraform is an asset.
-
Experience with forensic tools such as KAPE, EnCase, FTK, or Volatility is a plus.
-
Experience with Detection-as-Code technologies such as Sigma or YARA is a plus.
-
Experience conducting Purple Team exercises, validating vulnerabilities or reported bugs, and working with observability or SRE tools and processes is beneficial.
What We Offer
~1 min readLocation & Eligibility
Listing Details
- Posted
- October 7, 2026
- First seen
- October 7, 2026
- Last seen
- October 7, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 68%
- Scored at
- October 7, 2026
Signal breakdown
4 other jobs at
View all →Similar Security Engineer jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.