Cybersecurity Threat Hunter
14 hours ago
Cybersecurity Threat Hunter & Intelligence Specialist
Contract | Full-time | Onsite (Toronto)
Position Summary
This role is focused on proactive threat hunting and strategic threat intelligence within a complex enterprise environment. The Threat Hunter & Intelligence Specialist will hypothesize and execute advanced hunts across diverse telemetry sources, operationalize threat intelligence into high-fidelity detections, and lead investigations into sophisticated security findings.
The successful candidate will research emerging threats, adversary tactics, techniques, and procedures (TTPs), and active campaigns, translating intelligence into actionable insights that strengthen detection engineering, incident response, and overall security posture. This role emphasizes continuous improvement, executive-ready reporting, and close collaboration with Security Operations, Incident Response, Vulnerability Management, and external security partners.
Key Responsibilities
- Plan and execute hypothesis-driven and IOC/TTP-based threat hunts across endpoint, network, cloud, identity, and application telemetry.
- Correlate signals from SIEM, UEBA, EDR, and other security platforms with threat intelligence and environmental context to uncover malicious activity, lateral movement, and stealth persistence.
- Operationalize threat intelligence (IOCs, adversary tradecraft, ATT&CK techniques) into hunt queries, detections, and enrichment workflows.
- Lead investigations arising from hunt findings and intelligence reports, including scoping, containment, eradication, and recovery in partnership with incident response teams.
- Develop, tune, and maintain high-fidelity detections and analytics (e.g., KQL, LEQL, Sigma, YARA) to convert hunt insights into durable monitoring with low false-positive rates.
- Maintain hunting methodologies, playbooks, success metrics, and documentation; capture lessons learned and root-cause analysis.
- Measure and report on hunt effectiveness, including detections created, gaps remediated, dwell time reduction, and control efficacy, for technical and executive audiences.
- Participate in purple-team activities to validate detections, emulate adversary behavior, and prioritize defensive improvements.
- Research emerging threats, tooling, campaigns, and cloud/identity attack paths; communicate relevant intelligence to stakeholders.
- Collaborate with third-party vendors and partners to coordinate hunts, exchange indicators, and validate security tooling effectiveness.
- Support policy development, standards, and evidence collection related to security monitoring and incident response compliance requirements.
Knowledge Transfer & Collaboration
- Mentor SOC analysts and junior team members on threat hunting, intelligence analysis, and investigation techniques.
- Provide technical guidance to platform owners and product teams on telemetry quality, logging, and coverage needed for effective detection and hunting.
Qualifications & Experience
- Minimum
5 years of experience in cybersecurity
, with at least
2 years focused on threat hunting, advanced detection engineering, or equivalent roles
. - Minimum
6 years of experience in information technology or related disciplines
. - Proven track record of leading complex investigations and translating hunt outcomes into sustainable detections and process improvements.
- Experience with scripting languages such as
Python, PowerShell, or Bash
for automation, parsing, or custom tooling. - Community contributions or research (e.g., Sigma rules, KQL queries, ATT&CK mappings, blogs, conference talks) are an asset.
Technical Skillset
- Deep understanding of attacker TTPs, including credential access, defense evasion, living-off-the-land techniques, and cloud/identity attack paths.
- Strong knowledge of cloud environments (particularly
Azure
) and the telemetry required to detect threats in cloud-native and SaaS platforms. - Proficiency in detection engineering languages and frameworks such as
KQL, LEQL, Sigma, YARA
, and common security data models. - Solid grasp of threat intelligence methodologies, kill-chain analysis,
MITRE ATT&CK mapping
, and requirements-driven intelligence collection. - Hands-on experience with security operations tooling, including
SIEM, EDR, UEBA, NDR, and SOAR
platforms. - Working knowledge of system administration and hardening principles across
Windows, macOS, and Linux
, including logging and audit policies. - Familiarity with privacy and regulatory frameworks (e.g.,
NIST, ISO 27001
) as they relate to monitoring and incident response.
Certifications (Assets)
- Industry-recognized certifications such as
GCTI, GCFA, GCIH, OSCP
, or similar.
-
Director of Cybersecurity
1 day ago
Toronto, Ontario, Canada SGGG Fund Services Inc. Full timeReq #90SGGG Fund Services Inc., 121 King Street West, Toronto, Ontario, CanadaJob DescriptionPosted Tuesday, December 16, 2025, 5:00 AMPosition SummaryUnder the direction of the Chief Technology Officer (CTO), the Director of Cybersecurity is responsible for executing the organization's cybersecurity strategy and managing operational risk controls. The...
-
Microsoft Cybersecurity Speciaist
1 day ago
Toronto, Ontario, Canada Enterprise 1 Advisory Services Full timeJob SummaryA valued TELUS client is seeking a seasoned Microsoft Security Engineer to maintain, optimize, and secure their live enterprise environment. This role requires a strong foundation in cybersecurity threat mitigation, optimization and management on desktop and cloud.You'll work closely with the internal IT team and be responsible for the day-to-day...
-
Data Analyst – Cybersecurity/Python
2 days ago
Toronto, Ontario, Canada BeachHead Full timeAre you passionate about leveraging data to strengthen cybersecurity defenses? Apply NowWorking with one of our top financial clients, this role calls for a Data Analyst – Cybersecurity/Python and demands a proactive professional capable of supporting incident analytics, developing threat detection use cases, and automating manual processes. The ideal...
-
Cybersecurity Analyst
1 day ago
Toronto, Ontario, Canada Porter Airlines Inc. Full timeJob SummaryWe are seeking someone who is passionate about making a big impact in our cybersecurity operations. In this position, you will help drive important initiatives like identity and access management, threat detection, vulnerability response, and integrating security tools. You will manage user access across cloud and SaaS platforms, respond to...
-
Cybersecurity Analyst
1 day ago
Toronto, Ontario, Canada Porter Airlines Inc. Full timeJob SummaryWe are seeking someone who is passionate about making a big impact in our cybersecurity operations. In this position, you will help drive important initiatives like identity and access management, threat detection, vulnerability response, and integrating security tools. You will manage user access across cloud and SaaS platforms, respond to...
-
Manager, Cybersecurity Operations
23 hours ago
Toronto, Ontario, Canada University Pension Plan Ontario Full timeOUR COMPANY BACKGROUND & CULTUREUPP is the first pension plan of its kind in Ontario's university sector, proudly serving over 41,000 members across six universities and fourteen sector organizations. Our purpose is to bring greater retirement peace of mind to the university sector by investing with integrity and serving members with care. As a sector-wide...
-
Toronto, Ontario, Canada Elevance Health Full timeAnticipated End Date: Position Title:Director II, Cybersecurity: Cyber Defense & Security AnalyticsJob Description:Director II, Cybersecurity: Cyber Defense & Security Analytics Location: This role requires the associate to be in-office 3 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and...
-
IT and Cybersecurity Manager
1 day ago
Toronto, Ontario, Canada Essence Coaching Group Full timeIT and Cybersecurity Manager Location: Lindsay, Ontario, Canada (On-site / Hybrid) Employment Type: Full-time About the Role We are seeking an experienced IT & Cybersecurity Manager to lead and strengthen IT infrastructure, cloud environments, and cybersecurity operations within a fast-growing, technically complex organization. This role is responsible for...
-
Intern, Cybersecurity
1 day ago
Toronto, Ontario, Canada Investment Management Corporation of Ontario Full timeAt IMCO, our talent is among the best IMCO offers a uniquely stimulating and rewarding environment where you can help build and drive organizational transformation, all while seeking to challenge yourself, learn, and grow your career.Our culture is built on collaboration and passion, with a shared commitment to delivering lasting value to the clients we...
-
Threat Detection and Response Analyst
1 day ago
Toronto, Ontario, Canada Wavelo Full timeWavelo is a SaaS business on a mission to make telecoms a breeze.We provide flexible software that modernizes how communication service providers (CSPs) do business, helping them drive more value, focus on customer experience, and scale their operations faster.As part of Tucows (NASDAQ:TCX, TSX:TC)—one of the world's largest Internet services...