Talent.com
CGI
Incident Response LeadCGI • Calgary
Incident Response Lead

Incident Response Lead

CGI • Calgary
23 days ago
Job type
  • Full-time
Job description

Position Description:

This role can be located in any CGI office in Canada.

The Incident Response Lead is part of CGI's Global Security Operations Center (GSOC), which provides 24/7 security monitoring, threat detection, and incident response capabilities across the organisation.

As a senior member of GSOC, the Incident Response Lead is responsible for leading the technical response to complex cybersecurity incidents, coordinating investigations, and driving containment, eradication, and recovery activities. Acting as the technical authority during major incidents, the role provides Incident leadership in GSOC while ensuring investigations are conducted using industry best practices and forensically sound methodologies.

The Incident Response Lead works closely with Security Monitoring, Detection Engineering, Threat Intelligence, Security Engineering, IT Operations, and business stakeholders to minimise organisational risk, improve incident response capabilities, and strengthen CGI's overall cyber resilience.

This role requires extensive experience in cyber incident response, digital forensics, threat actor tactics, techniques and procedures (TTPs), malware analysis, enterprise infrastructure, and cloud technologies. The successful candidate will combine deep technical expertise with strong leadership, communication, and decision making skills to manage high impact incidents in a fast paced global environment.

Your future duties and responsibilities:

Key Responsibilities

. Lead the technical response to cybersecurity incidents, coordinating containment, eradication, recovery, and post incident activities.
. Conduct advanced investigations across endpoints, networks, cloud environments, identity platforms, and enterprise applications to determine root cause, attack scope, and business impact.
. Perform and oversee digital forensic investigations using industry standard and forensically sound methodologies, maintaining appropriate evidence handling and chain of custody.
. Develop and continuously improve incident response plans, playbooks, procedures, and operational standards.
. Conduct malware analysis, including static and dynamic analysis, and perform basic reverse engineering where required.
. Collaborate with Threat Intelligence, Detection Engineering, Security Monitoring, and Security Engineering teams to improve detection capabilities and operational readiness.
. Provide technical guidance and mentorship across GSOC, supporting junior partners professional development.
. Produce high quality technical reports, executive summaries, and lessons learned following security incidents.
. Identify opportunities to automate investigation workflows and improve the efficiency of incident response operations.
. Participate in an on call rotation providing 24/7 incident response support for high priority cybersecurity incidents.

Required qualifications to be successful in this role:

The candidate should have expertise and strong experience including:

. Minimum of 7 years' experience in working in a similar cybersecurity role or associated discipline.
. Demonstrable experience leading complex cyber incident response engagements within enterprise environments.
. Strong knowledge of incident response frameworks, methodologies, and lifecycle management.
. Extensive understanding of threat actor tactics, techniques and procedures (TTPs) and the MITRE ATT&CK framework. . Advanced knowledge of Windows, Linux, Active Directory, Microsoft , Azure, networking, and enterprise security architecture.
. Experience conducting host, network, cloud, and identity investigations.
. Experience using enterprise security technologies, including SIEM, EDR/XDR, NDR, and forensic investigation tools.
. Experience performing digital forensic investigations and evidence preservation using forensically sound practices.
. Experience analysing malware using static and dynamic analysis techniques.
. Strong understanding of common attack techniques, persistence mechanisms, privilege escalation, lateral movement, and data exfiltration.
. Ability to lead technical teams during high pressure incidents while making effective risk based decisions.
. Excellent communication skills with the ability to explain complex technical concepts to both technical and executive audiences. . Knowledge of insider threat investigations and user behaviour analytics.
. Experience collaborating with legal, privacy, HR, or regulatory bodies during cyber investigations.
. Experience with cloud security investigations across Microsoft Azure, Microsoft , AWS, or Google Cloud Platform.

Qualifications & Certifications

. Bachelor's degree in Cyber Security, Computer Science, Information Technology, or a related discipline, or equivalent practical experience.
. Relevant industry certifications are desirable, including one or more of:
. GIAC Certified Incident Handler (GCIH)
. GIAC Certified Forensic Analyst (GCFA)
. GIAC Reverse Engineering Malware (GREM) . GCFE or GCIA . CISSP . CISM


CGI is providing a reasonable estimate of the pay range for this role. The determination of this range includes factors such as skill set level, geographic market, experience and training, and licenses and certifications. Compensation decisions depend on the facts and circumstances of each case. A reasonable estimate of the current range is $,–$, This role is an existing vacancy.


#LI-AB19

Skills:

  • Cloud Security Audit
  • Collaboration
  • Cybersec. Incident Remediation
  • English
  • Incident Management
  • Leadership
  • Linux
  • Threat Risk Assessment
Create a job alert for this search

Incident Response Lead • Calgary

Similar jobs

Incident Response Principal Consultant

CrowdStrikeCalgary, Canada
Full-time

As a global leader in cybersecurity, CrowdStrike protects the people, processes and technologies that drive modern organizations.Since 2011, our mission hasn't changed — we’re here to stop brea... Show more

 • Promoted

IAM Test Lead

NES FircroftCalgary, AB, Canada
Full-time

Job Title:<br/><br/>IAM Test Lead.Location:<br/><br/>Calgary, AB.Length:<br/><br/>4 Months (with potential extension).Rotation:<br/><br/>Monday - Fri... Show more

 • Promoted

Raytheon Integrated Product Team Lead Role

Prattwhitneycalgary, ab, Canada
Full-time

Join Raytheon Canada as an Infrastructure Integrated Product Team Lead, delivering advanced training solutions for the Canadian Army.This leadership role involves ensuring high-quality performance ... Show more

 • Promoted

Contract IMT Specialist: Disaster Response Cadre

Hagerty Consulting IncCalgary, AB, CA
Full-time

A leading emergency management consulting firm in Canada is seeking Incident Management Team (IMT) Members for its Response Cadre.You will support state and local agencies during disaster missions ... Show more

 • Promoted

Remote Monitoring and Evaluation Advisor (E-Volunteer) - Spanish Required

Cuso InternationalHigh River, Alberta
Remote
Permanent

Online placement (E-Volunteer).Please submit a Spanish Resume and Statement of Interest.Open to Canadian Citizens and Permanent Residents of Canada only.As a Monitoring and EvaluationAdvisor, you w... Show more

 • Promoted

Emergency Response Client Manager Role

H2Safety ServicesCalgary, AB, CA
Full-time

Client Relationship Manager focused on emergency response management.Spearhead client engagement and ensure effective delivery of emergency plans.As a Client Relationship Manager, you will provide ... Show more

 • Promoted

Global Incident Management Analyst Role

Nutrien (Canada) Holdings ULCCalgary, AB, CA
Full-time

Join Nutrien as a Service Assurance Analyst, specializing in Incident Management in a fast-paced, global environment.Ensure service stability while leading Major Incident responses proactively.As p... Show more

 • Promoted

Insolvency Counselling Manager

BDO CanadaCalgary, AB, CA
Full-time

Putting people first, every day.BDO is a firm built on a foundation of positive relationships with our people and our clients.Each day, our professionals provide exceptional service, helping client... Show more

 • Promoted

Lead Incident Management Advisor Role

PVH (Tommy Hilfiger/Calvin Klein)Calgary, AB, Canada
Full-time

Elevate incident management practices within a leading organization as a Senior Advisor.This pivotal role emphasizes high-risk investigations and enhances organizational learning across functions.T... Show more

 • Promoted

Global Therapist: Integrated Critical Incident Response (ICIR)

Spring HealthCalgary, AB, CA
Full-time

Global Therapist: Integrated Critical Incident Response (ICIR).Location: Brandon, Manitoba, Canada.Our mission: to eliminate every barrier to mental health.At Spring Health, we’re on a mission to r... Show more

 • Promoted

Part-Time Focus Group Participant - No Experience Required

ApexFocusGroupAirdrie, AB, CA
Full-time +1

Now accepting applicants for Focus Group studies.Earn up to $850 per week part-time working from home.Must register to see if you qualify.No call center representative agent experience needed.Call ... Show more

 • Promoted

Impact Data & Policy Insights Lead

Venture for CanadaCalgary, AB, CA
Full-time

A non-profit organization in Canada is seeking a Manager for Impact, Data and Policy Insights.The role encompasses managing data systems, ensuring data quality, and translating complex data into co... Show more

 • Promoted

Remote Cloud Security Architect: DevSecOps & Risk Leader

Intuitive.aiCalgary, AB, CA
Remote
Full-time

A leading cybersecurity solutions company is seeking a Cybersecurity Specialist (GCP) to enhance their Cybersecurity Program.The role involves developing comprehensive security strategies in cloud ... Show more

 • Promoted

Remote Referral Partnerships Lead

Micro1Okotoks, Alberta, CA
CA$30.00 hourly
Remote
Full-time

AI data lab for training frontier models and evaluating AI agents.Experts contribute their diverse subject matter knowledge across domains such as finance, healthcare, STEM engineering, and more.AI... Show more

 • Promoted

Senior DevOps Engineer with Expertise in Cloud and Incident Management

RipplingCalgary, AB, CA
Full-time

Advance your career as a Senior DevOps Engineer, focusing on optimizing corporate IT through security and automation.This role emphasizes autonomy within cloud-native environments while significant... Show more

 • Promoted

Public Safety & Fire Prevention Specialist

Kativik Regional GovernmentCalgary, AB, CA
Full-time

A regional government organization in Nunavik is seeking a Public Safety & Fire Prevention Technician to develop and deliver fire prevention programs.The role involves working closely with municipa... Show more

 • Promoted

Service Assurance Analyst, Incident

NutrienCalgary
Full-time

Nutrien is a leading provider of crop inputs and services, dedicated to feeding the future.This position reports to the Supervisor, Service Assurance – Incident.This position is part of the Global ... Show more

 • Promoted

Fire and Explosion Forensic Engineering Role

IntactCalgary, AB, CA
Full-time

Pursue an exciting opportunity with Intact as a Forensic Engineer specializing in fire and explosion cases.Based in Calgary or Edmonton, you’ll lead investigations to ascertain loss causes and enha... Show more

 • Promoted

Senior Threat Detection & Response Engineer

1PasswordCalgary, AB, CA
Full-time

A leading cybersecurity company in Canada seeks a Senior Security Engineer to enhance threat detection and response capabilities.You will design systems for threat detection, lead incident response... Show more

 • Promoted

Senior Offensive Security Consultant - Red Team

TELUSCalgary, AB, CA
Full-time

Get notified about new Senior Security Consultant jobs in.Senior Security Consultant Jobs in United States.Information System Security Manager (Remote).Senior Security/Cybersecurity Consultant.Sr M... Show more