Incident Response Lead
1 week ago
**About us**:
Coalition is the world's first Active Insurance provider designed to help prevent digital risk before it strikes. Founded in 2017, Coalition combines broad insurance coverage with a digital risk assessment and continuous security monitoring to help organizations protect themselves in today's hyper-connected world.
Opportunities to make an impact with bold thinking are real - and happening daily.
**About the role**:
**Responsibilities**:
- Drive incident response engagements to guide our customers through forensic investigations, contain security incidents, and provide guidance on longer term remediation recommendations.
- Coordinate and guide incident response assistance from team members and vendors
- Investigate customer data breaches and malicious activity leveraging forensics tools; analyze Windows, Linux, and Mac OS X systems to identify Indicators of Compromise (IOCs); examine firewall, web, database, and other log sources to identify evidence of malicious activity.
- Lead proactive cybersecurity advisory and consulting engagements such as:
- Tabletop Exercises: lead and facilitate tabletop exercises designed to simulate real-world cyber incidents, helping clients enhance their incident response preparedness and resilience.
- Assessments: conduct comprehensive cybersecurity assessments to evaluate clients' security postures, identify vulnerabilities, and provide actionable recommendations for improvement.
- Documentation Reviews: evaluate and refine clients' incident response plans, policies, and procedures to ensure they align with industry best practices and regulatory requirements.
- Strategic Guidance and Client Engagement:
- Advisory Role: Provide strategic guidance to clients on enhancing their security architectures, cloud security strategies, and compliance frameworks such as NIST, HIPAA, and PCI.
- Long-Term Remediation: Beyond immediate incident containment, collaborate with clients to develop and implement longer-term remediation strategies to strengthen their security postures.
- Process Enhancement: Contribute to the refinement and improvement of internal processes, methodologies, and service offerings based on your consulting insights and industry expertise.
- Provide case reporting as required across internal and external audiences with the appropriate technical level of detail for threat researchers and/or business customers.
- Evaluate customer security programs, technologies, controls, and business environments; recommend and develop enhancements.
- Provide recommendations on solutions to help customers navigate information security risk.
- Track emerging security practices and contribute to building internal processes, and our various products.
- Stay abreast of the current regulatory environment, industry trends and related implications.
**Skills and Qualifications**:
- Minimum of 5+ years of incident response or digital forensics experience.
- Demonstrated practiced knowledge of the lifecycle of network threats, attacks, attack vectors, and methods of exploitation with a knowledge of intrusion set tactics, techniques, and procedures.
- Consultative Approach: Ability to effectively communicate complex technical concepts to non-technical stakeholders and provide actionable recommendations.
- Analytical Skills: Proficiency in analyzing security programs, technologies, and environments to identify gaps and recommend enhancements.
- Regulatory Knowledge: Familiarity with regulatory requirements and frameworks (e.g., NIST, HIPAA, PCI) is essential for advising clients on compliance issues.
- Project Management: Experience managing multiple projects simultaneously, from initial scoping through to final deliverables, ensuring high-quality results and client satisfaction.
- Experience with Velociraptor, Axiom, FTK, SIFT, Volatility, ELK, WireShark, Plaso, Skadi or other open source forensic/log analysis/network assessment tools.
- Experience with EDR tools like CrowdStrike Falcon, Carbon Black, Sentinel One, etc.
- Knowledge of industry standard frameworks - NIST, HIPAA, PCI.
- Self-motivated; entrepreneurial spirit; comfortable working in a, dynamic environment.
- Strong interactive communication skills (verbal & written).
- Aptitude to learn technical concepts/terms, and aptitude to guide multiple tasks/projects simultaneously.
- Experience deploying tools to AWS and familiarity using Cloud based platform for assessment.
**Bonus Points**:
- Security policy, governance, privacy or regulatory experience (e.g., NIST, ISO, HIPAA, PCI).
- Securing cloud based platforms (Microsoft Azure, Amazon AWS, etc.).
- Experience with system hardening procedures for Windows, Linux, Unix is helpful.Knowledge and/or experience with Nmap, Nessus, Nexpose, Qualys, Burp, Kali, Metasploit, Meterpreter, or other offensive tools is helpful.
- Knowledge of scripting for development of security tools and industry frameworks is helpful.
- SCADA/Control systems network experience is a plus.
*
-
Senior Incident Response
15 hours ago
Toronto, Canada Publicis Groupe ANZ Full timeA leading global communications group in Toronto is seeking a Senior Associate, Information Security - Forensics to lead cyber security incident investigations. The ideal candidate will have extensive experience in analyzing incidents, using forensics tools, and communicating effectively with senior executives. This role requires a proactive approach to...
-
Senior Incident Response
5 minutes ago
Toronto, Canada Publicis Groupe ANZ Full timeA leading global communications group in Toronto is seeking a Senior Associate, Information Security - Forensics to lead cyber security incident investigations. The ideal candidate will have extensive experience in analyzing incidents, using forensics tools, and communicating effectively with senior executives. This role requires a proactive approach to...
-
Senior Incident Response
15 hours ago
Toronto, Canada Publicis Groupe Holdings B.V Full timeA leading communications firm in Toronto needs a Senior Associate, Information Security - Forensics to lead cyber security incident responses. The role requires expertise in forensic analysis, cloud environments, and strong communication skills. Candidates should have over 4 years in an analytical role, particularly in incident response. The compensation...
-
Incident Response
3 weeks ago
Toronto, Canada Celestica Inc. Full timeA technology solutions leader in Toronto seeks an experienced Information Security Manager specializing in incident response and threat hunting. The role involves strategic assessments, managing security incidents, and leading cybersecurity initiatives. Applicants should have over 10 years of experience in cybersecurity, excellent communication skills, and...
-
Incident Response
3 weeks ago
Toronto, Canada Celestica Inc. Full timeA technology solutions leader in Toronto seeks an experienced Information Security Manager specializing in incident response and threat hunting. The role involves strategic assessments, managing security incidents, and leading cybersecurity initiatives. Applicants should have over 10 years of experience in cybersecurity, excellent communication skills, and...
-
Incident Response
3 weeks ago
Toronto, Canada Celestica Inc. Full timeA technology solutions leader in Toronto seeks an experienced Information Security Manager specializing in incident response and threat hunting. The role involves strategic assessments, managing security incidents, and leading cybersecurity initiatives. Applicants should have over 10 years of experience in cybersecurity, excellent communication skills, and...
-
Incident Response Analyst
14 hours ago
Toronto, Canada Alignerr Full timeAbout The Job At Alignerr, we partner with the world’s leading AI research teams and labs to build and train cutting-edge AI models. We’re developing and testing AI systems designed to interpret security events, correlate alerts, and support digital investigations across modern environments. You will work with realistic incident data to ensure AI-driven...
-
Incident Response Analyst
2 minutes ago
Toronto, Canada Alignerr Full timeAbout The Job At Alignerr, we partner with the world’s leading AI research teams and labs to build and train cutting-edge AI models. We’re developing and testing AI systems designed to interpret security events, correlate alerts, and support digital investigations across modern environments. You will work with realistic incident data to ensure AI-driven...
-
Senior Incident Response
7 hours ago
Toronto, Canada Publicisgroupe Full timeA global communications leader located in Toronto seeks a Senior Associate in Information Security - Forensics. The successful candidate will lead cyber security incident investigations, analyze systems using forensic tools, and collaborate with senior management. Ideal candidates will have significant experience with EDR tools and cloud environments, as...
-
Senior Incident Response
5 minutes ago
Toronto, Canada Publicisgroupe Full timeA global communications leader located in Toronto seeks a Senior Associate in Information Security - Forensics. The successful candidate will lead cyber security incident investigations, analyze systems using forensic tools, and collaborate with senior management. Ideal candidates will have significant experience with EDR tools and cloud environments, as...