isacybersecurity
Cybersecurity Incident Response Commander
Toronto, Ontario
No sponsorshipDetected 15 hours ago
AWSGCPAzureLinuxCybersecuritySIEMSOARIncident ResponseComplianceAccessibilityStakeholder ManagementHRResearchLeadershipCommunicationMentoringCISSP
About the role
- The role is structured as a Subject Matter Expert and Incident Commander rather than a line-management position: technical authority, judgment under pressure, and external-grade SME presence are the primary contributions.
- People-leadership behaviors including coaching analysts, championing career pathways, and modelling composure under stress are valued and expected to grow over time, but formal direct reports are not a requirement of the role at hire.
- Development and ongoing evolution of the Incident Response program is subject to the final authority of the Senior Director, DFIR Services who provides strategic direction and ultimate accountability for the program's scope, structure, and priorities.
Responsibilities
- Lead digital forensic investigations across endpoint, server, network, mobile, and cloud sources.
- Develop, manage, and continuously refine DFIR processes, procedures, playbooks, and runbooks (DFIR policy authorship is out of scope and sits with other functions).
- Lead post-incident reporting and client walk-throughs and translate lessons learned into process, playbook, tooling, and training improvements.
- Support presales activities including proposals, Statements of Work (SOWs), and RFP responses.
- Own the technical quality of the DFIR practice in alignment with the Security Incident Response (SIR) service card.
- run continuous-improvement cycles against them to drive service-quality and operational outcomes.
- Lead and manage the IR readiness program including IR Plan engagements, Tabletop Exercises (TTX), and Playbook development and/or validation.
- Present incident and digital evidence reports to key stakeholders including law enforcement, legal counsel, and clients; Lead post-incident reporting and client walk-throughs and translate lessons learned into process, playbook, tooling, and training improvements.
- Identify, define, track, and report on DFIR metrics; run continuous-improvement cycles against them to drive service-quality and operational outcomes.
- Collaborate closely with SOC leadership, analysts, and Service Owners to ensure incident response remains tightly integrated with detection capabilities and aligned to the broader evolution of ISA's service portfolio.
Requirements
- 10+ years of progressive experience in cybersecurity, with at least 7 years in incident response and digital forensics roles.
- Expert-level knowledge of the incident response lifecycle, containment and eradication strategies, and digital forensic methodologies.
- Hands-on expertise across host, network, memory, mobile, and cloud forensics, including chain-of-custody discipline suitable for legal proceedings.
- Experience with multi-cloud forensics (AWS, Azure, GCP, Microsoft 365, Google Workspace) and SaaS-platform investigations.
- Working knowledge of multiple security control families such as EDR, SIEM, SOAR, NDR, identity, email security, DLP, and their use during response.
- Working knowledge of NIST SP 800-61, ISO 27035, ISO 27001:2022, NIST CSF, SOC 2, and CSA CCM.
- Demonstrated ability to identify, define, track, and report on operational and service-quality metrics, and to run continuous-improvement cycles against them.
- must be able to communicate clearly under pressure and to non-technical audiences.
- ability to brief client executives and boards on cyber risk, governance, and resilience between as well as during incidents.
- Bachelor's degree in computer science, Information Security, or related field, or equivalent professional experience.
- Demonstrated experience as Incident Commander on multiple high-severity engagements (e.g., ransomware, BEC, APT intrusion, large-scale data breach).
- Proficient working with Windows, Linux, and MacOS
- Experience with OSINT (Open-Source Intelligence), including gathering and correlating publicly available information to support threat actor attribution, infrastructure mapping, and exposure analysis, and translating findings into actionable intelligence for client engagements.
- Deep familiarity with MITRE ATT&CK and current ransomware/APT TTPs.
- Excellent leadership-by-influence, executive communication, and stakeholder management skills
- Trusted advisor presence
Nice to have
- People leadership experience including coaching, mentoring, performance feedback, hiring panels, even where the role has not formally carried direct reports.
- Experience leading or contributing to MSSP service delivery including contractual SLAs, RACI models, 24x7 operations, and onboarding/transition workflows.
- Recognized externally as a subject matter expert through published research, conference talks, MITRE ATT&CK contributions, media commentary, or industry awards.
- Experience supporting law enforcement engagements (RCMP NC3, CCCS/CCIRC, FBI Cyber), Anton Piller orders, expert witness testimony, or regulatory investigations.
- Experience with dark web monitoring and social-media threat monitoring.
- Multilingual capability is an asset.
- Strongly preferred: GCIH, GCFA, GCIA, GX-FA, GSE
- Preferred: OSCP, CISM, CCSP, EnCE, CHFI, ECIH
Compensation
- $135,000-$157,500- $180,000
Benefits
- Flexible sick and personal days for all employees
- Generous health plan with enhanced mental health resources and programs
- Professional development opportunities and education reimbursement up to $2,000 annually for all employees
Company info
- We are proud to be recognized as a top employer for multiple years in a row, we currently hold the distinctions of Canada's Top Small and Medium Employers 2025, Greater Toronto's Top Employers 2025 and are Certified Great Place to Work 2026-2027.
- ISA Cybersecurity is a proudly Canadian cyber and AI services and solutions provider. Trusted by over 500 clients from SMB to global enterprise, we empower organizations to safeguard their most critical assets and adopt AI securely. Through our highly customizable Cyber 360 and AI 360 offerings, we deliver a comprehensive range of governance, assurance, engineering protection, detection, and response services for the public and private sectors. Backed by over three decades of operational experience and a vast network of highly specialized and certified experts, we leverage cutting-edge technologies and AI to ensure that clients achieve their privacy, security, and business goals.
- We operate in a remote-first environment. Office presence is typically less than 20% of the time, varying by role and work requirements. Our office space, located at Bloor and Islington, is a collaborative space designed for in-person meetings and drop-ins. We enjoy hosting in-person quarterly townhalls and social events throughout the year to encourage teambuilding and collaboration.
- ISA Cybersecurity is a proudly Canadian cyber and AI services and solutions provider.
- Trusted by over 500 clients from SMB to global enterprise, we empower organizations to safeguard their most critical assets and adopt AI securely.
- Through our highly customizable Cyber 360 and AI 360 offerings, we deliver a comprehensive range of governance, assurance, engineering protection, detection, and response services for the public and private sectors.
- Backed by over three decades of operational experience and a vast network of highly specialized and certified experts, we leverage cutting-edge technologies and AI to ensure that clients achieve their privacy, security, and business goals.
- We operate in a remote-first environment.
- Office presence is typically less than 20% of the time, varying by role and work requirements.
- Our office space, located at Bloor and Islington, is a collaborative space designed for in-person meetings and drop-ins.
- We enjoy hosting in-person quarterly townhalls and social events throughout the year to encourage teambuilding and collaboration.
Visa & Work Authorization
- Ability to obtain Government of Canada security clearance
Apply directly at isacybersecurity →Create a free account for alerts like thisView isacybersecurity immigration profile
This listing is sourced directly from isacybersecurity's careers page and normalized into a canonical job model.