Location: Toronto, ON, Hybrid (3x week)
Language: Strong written and spoken English communication skills
Background Check Requirement: Canadian criminal credit check, Canadian ID cross-check, public safety verification, 5-year employment verification, education verification, credit check, and social media check
About the Opportunity
Join a leading organization in the financial technology sector as a SOC Analyst, Tier III, where you’ll play a critical role in protecting the systems and digital infrastructure that support millions of transactions. Reporting to the Leader, Security Incident Management, you’ll take ownership of complex cybersecurity incidents and help strengthen enterprise-wide resilience.
You’ll work closely with technology, risk, legal, compliance, and business teams, serving as a senior escalation point when sophisticated threats emerge. This is an opportunity to combine deep technical expertise with leadership, collaboration, and continuous improvement in a highly connected environment.
What’s In It for You
You’ll join an innovative, inclusive workplace that values collaboration, professional growth, and employee well-being.
Your Responsibilities
• You’ll lead complex cybersecurity incident investigations, including containment, eradication, recovery, root cause analysis, and post-incident reporting.
• You’ll conduct digital forensic investigations across endpoints, servers, networks, cloud environments, and enterprise infrastructure.
• You’ll lead proactive threat hunting and leverage threat intelligence to identify emerging risks and strengthen defensive strategies.
• You’ll enhance monitoring and detection capabilities through log source onboarding, detection use case development, analytics, and rule tuning.
• You’ll develop incident response playbooks, remediation plans, and lessons learned to improve organizational resilience.
• You’ll provide expert cybersecurity guidance and coordinate response efforts across technical teams, business stakeholders, and external partners.
Skills and Qualifications
• Extensive cybersecurity experience spanning incident response, digital forensics, threat hunting, and cyber threat intelligence.
• Advanced expertise in malware analysis, memory, host and network forensics, incident reconstruction, and Windows, Linux, macOS, cloud, and on-premises environments.
• Strong experience with SIEM platforms including Sentinel, Splunk, LogRhythm, or QRadar, and EDR technologies including Defender for Endpoint, Cortex, or CrowdStrike.
• Strong knowledge of IDS/IPS, vulnerability management, TCP/IP, networking, operating systems, application security, and infrastructure security controls.
• Proven ability to lead incidents of varying severity, manage competing priorities, and communicate complex findings to technical and non-technical audiences.
• GIAC, GCFA, GCIH, CISSP, CISA, or equivalent certifications are assets, as is experience with ISO-certified environments and ITIL practices.
• Willingness to participate in an after-hours on-call rotation.
Note from the Hiring Manager
“We’re looking for someone who can bring deep technical expertise to complex investigations while staying calm and collaborative when the stakes are high. You’ll have the opportunity to influence how we detect, respond to, and learn from emerging threats.”
Why Partner with Altis
If you’ve never worked with a staffing agency before, we make it easy. We work with top employers across Canada who have great jobs to fill, each vetted and verified by our team. When you apply for a job with Altis, we get to know you as a candidate and learn what your strengths are. Then, if you’re a solid match, we handle all the logistics, advocating for you as a candidate for the role, providing access to coaching and connecting you directly with the hiring manager. And rest assured, all our services are free of cost for candidates.