CareerPlanSign in

Senior Security Operations Analyst, Detection & Response

Toronto, Ontario, Canada💼 Full-time💰 $110,000–$125,000🗓 2026-09-09 → 2026-09-25

Core

Lead threat detection, investigation, and incident response across endpoint, cloud, and identity environments, while building automated detection workflows and supervising AI triage agents.

Role type

Senior Security Operations Analyst (Detection & Response)

Builds

Automated detection and response playbooks, SOC detection content, and AI-related threat coverage

Domain

Cybersecurity, Financial Services

Deliverable

production ML models | product features | dashboards & analysis

Required skills

Complex incident investigation, cloud/host forensics, detection rules as code, threat hunting, scripting (Python), REST API integration, AI triage supervision

Preferred skills

Financial services experience, GCIH/GCFA/GCDA/GNFA/CISSP certifications, Kubernetes, OWASP Top 10 for LLMs, MITRE ATT&CK/ATLAS

Technologies

EDR, SIEM, SOAR, AWS, Python, Kubernetes

Responsibilities

Lead complex investigations and containment for high-severity incidents; write, test, and tune detection rules and response playbooks; conduct hypothesis-driven threat hunts; document attacker activity for executive briefings; maintain investigation runbooks and SOC metrics; partner with cybersecurity to align priorities; supervise AI triage agents and tune configurations

Seniority

Senior, hands-on IC

Sourced via workable · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.