Talent.com
CGI
Incident Response LeadCGI • Edmonton
Incident Response Lead

Incident Response Lead

CGI • Edmonton
17 days ago
Job type
  • Full-time
Job description

Position Description:

This role can be located in any CGI office in Canada.

The Incident Response Lead is part of CGI's Global Security Operations Center (GSOC), which provides 24/7 security monitoring, threat detection, and incident response capabilities across the organisation.

As a senior member of GSOC, the Incident Response Lead is responsible for leading the technical response to complex cybersecurity incidents, coordinating investigations, and driving containment, eradication, and recovery activities. Acting as the technical authority during major incidents, the role provides Incident leadership in GSOC while ensuring investigations are conducted using industry best practices and forensically sound methodologies.

The Incident Response Lead works closely with Security Monitoring, Detection Engineering, Threat Intelligence, Security Engineering, IT Operations, and business stakeholders to minimise organisational risk, improve incident response capabilities, and strengthen CGI's overall cyber resilience.

This role requires extensive experience in cyber incident response, digital forensics, threat actor tactics, techniques and procedures (TTPs), malware analysis, enterprise infrastructure, and cloud technologies. The successful candidate will combine deep technical expertise with strong leadership, communication, and decision making skills to manage high impact incidents in a fast paced global environment.

Your future duties and responsibilities:

Key Responsibilities

. Lead the technical response to cybersecurity incidents, coordinating containment, eradication, recovery, and post incident activities.
. Conduct advanced investigations across endpoints, networks, cloud environments, identity platforms, and enterprise applications to determine root cause, attack scope, and business impact.
. Perform and oversee digital forensic investigations using industry standard and forensically sound methodologies, maintaining appropriate evidence handling and chain of custody.
. Develop and continuously improve incident response plans, playbooks, procedures, and operational standards.
. Conduct malware analysis, including static and dynamic analysis, and perform basic reverse engineering where required.
. Collaborate with Threat Intelligence, Detection Engineering, Security Monitoring, and Security Engineering teams to improve detection capabilities and operational readiness.
. Provide technical guidance and mentorship across GSOC, supporting junior partners professional development.
. Produce high quality technical reports, executive summaries, and lessons learned following security incidents.
. Identify opportunities to automate investigation workflows and improve the efficiency of incident response operations.
. Participate in an on call rotation providing 24/7 incident response support for high priority cybersecurity incidents.

Required qualifications to be successful in this role:

The candidate should have expertise and strong experience including:

. Minimum of 7 years' experience in working in a similar cybersecurity role or associated discipline.
. Demonstrable experience leading complex cyber incident response engagements within enterprise environments.
. Strong knowledge of incident response frameworks, methodologies, and lifecycle management.
. Extensive understanding of threat actor tactics, techniques and procedures (TTPs) and the MITRE ATT&CK framework. . Advanced knowledge of Windows, Linux, Active Directory, Microsoft , Azure, networking, and enterprise security architecture.
. Experience conducting host, network, cloud, and identity investigations.
. Experience using enterprise security technologies, including SIEM, EDR/XDR, NDR, and forensic investigation tools.
. Experience performing digital forensic investigations and evidence preservation using forensically sound practices.
. Experience analysing malware using static and dynamic analysis techniques.
. Strong understanding of common attack techniques, persistence mechanisms, privilege escalation, lateral movement, and data exfiltration.
. Ability to lead technical teams during high pressure incidents while making effective risk based decisions.
. Excellent communication skills with the ability to explain complex technical concepts to both technical and executive audiences. . Knowledge of insider threat investigations and user behaviour analytics.
. Experience collaborating with legal, privacy, HR, or regulatory bodies during cyber investigations.
. Experience with cloud security investigations across Microsoft Azure, Microsoft , AWS, or Google Cloud Platform.

Qualifications & Certifications

. Bachelor's degree in Cyber Security, Computer Science, Information Technology, or a related discipline, or equivalent practical experience.
. Relevant industry certifications are desirable, including one or more of:
. GIAC Certified Incident Handler (GCIH)
. GIAC Certified Forensic Analyst (GCFA)
. GIAC Reverse Engineering Malware (GREM) . GCFE or GCIA . CISSP . CISM


CGI is providing a reasonable estimate of the pay range for this role. The determination of this range includes factors such as skill set level, geographic market, experience and training, and licenses and certifications. Compensation decisions depend on the facts and circumstances of each case. A reasonable estimate of the current range is $,–$, This role is an existing vacancy.


#LI-AB19

Skills:

  • Cloud Security Audit
  • Collaboration
  • Cybersec. Incident Remediation
  • English
  • Incident Management
  • Leadership
  • Linux
  • Threat Risk Assessment
Create a job alert for this search

Incident Response Lead • Edmonton

Similar jobs

Information Technology Private Tutoring Jobs Beaumont (Alberta)

SuperprofBeaumont (Alberta), Canada
CA$20.00 hourly
Full-time +1

Superprof is Canada's #1 tutoring platform, and we're actively recruiting passionate tutors! Whether you're a student, a professional, or simply someone who loves teaching, join the largest communi... Show more

 • Promoted

Senior Incident Response Consultant at CrowdStrike

CrowdStrikeEdmonton, Division No. 11, CA
Full-time

Join CrowdStrike as a Senior Incident Response Consultant and play a critical role in modern cybersecurity.This position allows you to shape responses to sophisticated cyber threats.We are looking ... Show more

 • Promoted

Customer Experience Team Lead

BIS Safety SoftwareSherwood Park, AB, CA
Full-time

SaaS company on a mission to change how organizations manage safety, learning, and compliance.This team is the heart of the client experience at BIS, and we want a leader who takes that seriously.T... Show more

 • Promoted

Global Therapist: Integrated Critical Incident Response (ICIR)

Spring HealthEdmonton, Division No. 11, CA
Full-time

Global Therapist: Integrated Critical Incident Response (ICIR).Location: Brandon, Manitoba, Canada.Our mission: to eliminate every barrier to mental health.At Spring Health, we’re on a mission to r... Show more

 • Promoted

Survey Taker: Earn up to $25 per survey (Remote)

Earn HausBeaumont, AB, CA
Remote
Full-time +1

Looking for people to participate in taking online surveys for Fortune 500 brands.All you need to do is complete online surveys by sharing your opinion.You will help influence brand decisions on se... Show more

 • Promoted

Innovative Loss Prevention Coordinator Focused on Retail Safety

High Tide Inc.Edmonton, Division No. 11, CA
Full-time

Enhance retail asset protection as a proactive Loss Prevention Coordinator.Engage your investigative skills to safeguard against theft and ensure compliance throughout multiple locations.You will b... Show more

 • Promoted

Remote Cloud Security Architect: DevSecOps & Risk Leader

Intuitive.aiEdmonton, Division No. 11, CA
Remote
Full-time

A leading cybersecurity solutions company is seeking a Cybersecurity Specialist (GCP) to enhance their Cybersecurity Program.The role involves developing comprehensive security strategies in cloud ... Show more

 • Promoted

Governance, Risk & Compliance Consultant

MalleumEdmonton, Division No. 11, CA
Full-time

Governance, Risk & Compliance Consultant.Governance, Risk & Compliance Consultant.We are a premier cybersecurity consultancy, blending advanced offensive and defensive strategies to safeguard our c... Show more

 • Promoted

Full-Cycle DFIR Specialist (Contract)

New Value SolutionsEdmonton, Division No. 11, CA
Full-time

A cybersecurity solutions provider is seeking a highly skilled Senior DFIR Specialist to lead complex investigations and incident response activities.The ideal candidate will have over 5 years of e... Show more

 • Promoted

Public Safety & Fire Prevention Specialist

Kativik Regional GovernmentEdmonton, Division No. 11, CA
Full-time

A regional government organization in Nunavik is seeking a Public Safety & Fire Prevention Technician to develop and deliver fire prevention programs.The role involves working closely with municipa... Show more

 • Promoted

Senior Threat Detection & Response Engineer

1PasswordEdmonton, Division No. 11, CA
Full-time

A leading cybersecurity company in Canada seeks a Senior Security Engineer to enhance threat detection and response capabilities.You will design systems for threat detection, lead incident response... Show more

 • Promoted

Store Loss Prevention Lead, Wem

Canadian TireEdmonton, Canada
Full-time

What you'll doAs a Store Loss Prevention Lead at SportChek, your positive attitude will help customers and employees of the store.You will ensure customer and Loss Prevention awareness lives wi... Show more

 • Promoted

Earn Cash From Taking Surveys Online

Earn HausBeaumont, AB, CA
Full-time +1

Looking for people to participate in taking online surveys for Fortune 500 brands.All you need to do is complete online surveys by sharing your opinion.You will help influence brand decisions on se... Show more

 • Promoted

Lead Client Services

The Salvation Army in CanadaEdmonton, Division No. 11, CA
Full-time

For more than 130 years, The Salvation Army has served people in need in communities across Canada and Bermuda.Building on our roots as a world‑wide Christian church, each year we help more than 2 ... Show more

 • Promoted

Remote Director Workplace Investigations Role

Veritas SolutionsEdmonton, Alberta, Canada
Remote
Full-time

Join Veritas Solutions as a Remote Director of Workplace Investigations, immersing yourself in a flexible role that emphasizes quality investigation practices and leadership across Canada.This seni... Show more

 • Promoted

Senior iGaming Compliance Investigator

AGLCEdmonton
Full-time +1

A provincial regulatory agency in Canada is seeking an iGaming Investigator to lead investigations and ensure compliance within Alberta's growing iGaming market.The ideal candidate should have at l... Show more

 • Promoted

Licensed Heavy Duty Mechanic

Clean HarborsEdmonton, AB, CAN
Full-time +1

Licensed/Journeyman Heavy Duty Mechanic.This individual will assist in the maintenance and repair of heavy handling units including, but not limited to tractors, trailers, and loaders.Permanent (fu... Show more

 • Promoted

Contract IMT Specialist: Disaster Response Cadre

Hagerty Consulting IncEdmonton, Division No. 11, CA
Full-time

A leading emergency management consulting firm in Canada is seeking Incident Management Team (IMT) Members for its Response Cadre.You will support state and local agencies during disaster missions ... Show more

 • Promoted

Remote Operations Training Lead

CGS (Computer Generated Solutions)Edmonton, Division No. 11, Canada
Remote
Full-time

A leading training solutions provider is seeking an experienced Operations Training Manager to oversee the planning and delivery of a plasma collection training program.The ideal candidate should h... Show more

 • Promoted

Senior DevOps Engineer with Expertise in Cloud and Incident Management

RipplingEdmonton, Division No. 11, CA
Full-time

Advance your career as a Senior DevOps Engineer, focusing on optimizing corporate IT through security and automation.This role emphasizes autonomy within cloud-native environments while significant... Show more