Cybersecurity Threat Hunter
2 weeks ago
Cybersecurity Threat Hunter & Intelligence Specialist
Contract | Full-time | Onsite (Toronto)
Position Summary
This role is focused on proactive threat hunting and strategic threat intelligence within a complex enterprise environment. The Threat Hunter & Intelligence Specialist will hypothesize and execute advanced hunts across diverse telemetry sources, operationalize threat intelligence into high-fidelity detections, and lead investigations into sophisticated security findings.
The successful candidate will research emerging threats, adversary tactics, techniques, and procedures (TTPs), and active campaigns, translating intelligence into actionable insights that strengthen detection engineering, incident response, and overall security posture. This role emphasizes continuous improvement, executive-ready reporting, and close collaboration with Security Operations, Incident Response, Vulnerability Management, and external security partners.
Key Responsibilities
- Plan and execute hypothesis-driven and IOC/TTP-based threat hunts across endpoint, network, cloud, identity, and application telemetry.
- Correlate signals from SIEM, UEBA, EDR, and other security platforms with threat intelligence and environmental context to uncover malicious activity, lateral movement, and stealth persistence.
- Operationalize threat intelligence (IOCs, adversary tradecraft, ATT&CK techniques) into hunt queries, detections, and enrichment workflows.
- Lead investigations arising from hunt findings and intelligence reports, including scoping, containment, eradication, and recovery in partnership with incident response teams.
- Develop, tune, and maintain high-fidelity detections and analytics (e.g., KQL, LEQL, Sigma, YARA) to convert hunt insights into durable monitoring with low false-positive rates.
- Maintain hunting methodologies, playbooks, success metrics, and documentation; capture lessons learned and root-cause analysis.
- Measure and report on hunt effectiveness, including detections created, gaps remediated, dwell time reduction, and control efficacy, for technical and executive audiences.
- Participate in purple-team activities to validate detections, emulate adversary behavior, and prioritize defensive improvements.
- Research emerging threats, tooling, campaigns, and cloud/identity attack paths; communicate relevant intelligence to stakeholders.
- Collaborate with third-party vendors and partners to coordinate hunts, exchange indicators, and validate security tooling effectiveness.
- Support policy development, standards, and evidence collection related to security monitoring and incident response compliance requirements.
Knowledge Transfer & Collaboration
- Mentor SOC analysts and junior team members on threat hunting, intelligence analysis, and investigation techniques.
- Provide technical guidance to platform owners and product teams on telemetry quality, logging, and coverage needed for effective detection and hunting.
Qualifications & Experience
- Minimum
5 years of experience in cybersecurity
, with at least
2 years focused on threat hunting, advanced detection engineering, or equivalent roles
. - Minimum
6 years of experience in information technology or related disciplines
. - Proven track record of leading complex investigations and translating hunt outcomes into sustainable detections and process improvements.
- Experience with scripting languages such as
Python, PowerShell, or Bash
for automation, parsing, or custom tooling. - Community contributions or research (e.g., Sigma rules, KQL queries, ATT&CK mappings, blogs, conference talks) are an asset.
Technical Skillset
- Deep understanding of attacker TTPs, including credential access, defense evasion, living-off-the-land techniques, and cloud/identity attack paths.
- Strong knowledge of cloud environments (particularly
Azure
) and the telemetry required to detect threats in cloud-native and SaaS platforms. - Proficiency in detection engineering languages and frameworks such as
KQL, LEQL, Sigma, YARA
, and common security data models. - Solid grasp of threat intelligence methodologies, kill-chain analysis,
MITRE ATT&CK mapping
, and requirements-driven intelligence collection. - Hands-on experience with security operations tooling, including
SIEM, EDR, UEBA, NDR, and SOAR
platforms. - Working knowledge of system administration and hardening principles across
Windows, macOS, and Linux
, including logging and audit policies. - Familiarity with privacy and regulatory frameworks (e.g.,
NIST, ISO 27001
) as they relate to monitoring and incident response.
Certifications (Assets)
- Industry-recognized certifications such as
GCTI, GCFA, GCIH, OSCP
, or similar.
-
Director II, Cybersecurity: Cyber Defense
2 weeks ago
Toronto, Ontario, Canada Elevance Health Full timeAnticipated End Date: Position Title:Director II, Cybersecurity: Cyber Defense & Security AnalyticsJob Description:Director II, Cybersecurity: Cyber Defense & Security Analytics Location: This role requires the associate to be in-office 3 days per week, fostering collaboration and connectivity, while providing flexibility to support productivity and...
-
Cybersecurity Risk Advisor
5 days ago
Toronto, Ontario, Canada Apex Systems Full timeCybersecurity Risk AdvisorIndustry:Financial ServicesLocation:Toronto.Hybrid:1 day in office per weekDuration of Contract/Perm:6 month rolling contractHours/week: 37.5Start date:January 2026Job OverviewAs the Cyber Security Risk Advisor, you'll work in a growing area of the bank that manages operational risk, regulatory supervision, standardized testing,...
-
Cybersecurity Roles – FinTech Sector
1 week ago
Toronto, Ontario, Canada Domnic Lewis Pvt. Ltd Full timeCybersecurity Roles - FinTech Sector | Domnic Lewis InternationalDomnic Lewis International is hiring Cybersecurity Professionals for multiple leading companies in the FinTech industry. We are seeking experienced candidates (typically 4-6+ years, but all strong profiles are encouraged to apply) who can help build secure, compliant, and resilient financial...
-
Cybersecurity Analyst
2 weeks ago
Toronto, Ontario, Canada Hitachi Full timeAbout UsA career at Hitachi Rail will help create a legacy. With operations in every corner of the world, our work goes to the cutting-edge of digital transformation and technology. From the multi-cultural strength of our global organisation to the sustainable and innovative ways we work to bring people together, there's something for everyone to get stuck...
-
Manager, Cybersecurity
2 weeks ago
Toronto, Ontario, Canada RBC Full timeJob DescriptionWhat is the opportunity? City National Bank (CNB) is a subsidiary of RBC and headquartered in Los Angeles, California. It is the 30th largest bank in the United States and offers a full complement of banking, trust and investment services through 75 offices across the US. In this role, you will be an RBC employee based out of RBC Internal...
-
Summer Intern 2026
6 days ago
Toronto, Ontario, Canada Mackenzie Financial Corporation Full time $49,000 - $51,000Job DescriptionDivision: IGM-TECHLocation:TorontoIGM Financial Inc. is a leading wealth and asset management company in Canada, managing approximately $271 billion in assets. It offers financial planning and investment services to over two million Canadians through IG Wealth Management and Mackenzie Investments.Mackenzie Investments, founded in 1967, is a...
-
Senior Cybersecurity Analyst
2 weeks ago
Toronto, Ontario, Canada Infrastructure Ontario Full time $87,900 - $118,900Infrastructure Ontario (IO), an Ontario crown corporation, provides a wide range of services to support the Ontario government's initiative to modernize and maximize the value of public infrastructure and realty. IO has been recognized domestically and internationally for the way it does business and the success it has had with its major projects, real...
-
Senior Cybersecurity Analyst
5 days ago
Toronto, Ontario, Canada Infrastructure Ontario Full timeInfrastructure Ontario (IO), an Ontario crown corporation, provides a wide range of services to support the Ontario government's initiative to modernize and maximize the value of public infrastructure and realty. IO has been recognized domestically and internationally for the way it does business and the success it has had with its major projects, real...
-
Toronto, Ontario, Canada NielsenIQ Full timeCompany DescriptionOur Cybersecurity architecture team works diligently to protect NielsenIQ's data center and cloud components from cyber-attacks. We're driving a global security strategy through technology leader partnership, continuously evolving our security systems designs, analyzing industry frameworks and standards to drive more meaningful security...
-
Senior Cybersecurity Engineer- Offensive
2 weeks ago
Toronto, Ontario, Canada CAAT Pension Plan Full timeAt CAAT, we're passionate about what we do. And it showsHere, you'll find a cultural spark in everything we do – from the way we partner with members and employers, to the way we work, collaborate, and grow. It doesn't just feel different at CAAT. Itisdifferent. We're one of the fastest-growing pensions in the country for a reason. We challenge the status...