Talent.com
ISA Cybersecurity
Cybersecurity Incident Response CommanderISA Cybersecurity • Toronto, Ontario, Canada
Cybersecurity Incident Response Commander

Cybersecurity Incident Response Commander

ISA Cybersecurity • Toronto, Ontario, Canada
17 days ago
Salary
CA$135,000.00 yearly
Job type
  • Full-time
Job description

About the Role:

The Cybersecurity Incident Response (IR) Commander is the technical and operational authority for ISA Cybersecuritys Digital Forensics & Incident Response (DFIR) function and holds expert-level command of the Security Incident Response (SIR) service during client engagements. The role is structured as a Subject Matter Expert and Incident Commander rather than a line-management position: technical authority judgment under pressure and external-grade SME presence are the primary contributions.

The IR Commander leads the Response side of ISAs Protect-Detect-Respond operating model through influence process and playbook ownership and direct command on every Emergency and IR Retainer engagement. People-leadership behaviors including coaching analysts championing career pathways and modelling composure under stress are valued and expected to grow over time but formal direct reports are not a requirement of the role at hire. Development and ongoing evolution of the Incident Response program is subject to the final authority of the Senior Director DFIR Services who provides strategic direction and ultimate accountability for the programs scope structure and priorities.

This role reports to the Senior Director DFIR Services. The successful candidate will have extensive experience in personally commanding and leading ransomware business email compromise data exfiltration and complex multi-vector engagements and will be recognized externally as a subject-matter expert in incident response and digital forensics.

About Us:

We are proud to be recognized as a top employer for multiple years in a row we currently hold the distinctions of Canadas Top Small and Medium Employers 2025 Greater Torontos Top Employers 2025 and are Certified Great Place to Work 2026-2027.

ISA Cybersecurityis a proudly Canadiancyberand AIservices and solutions by over 500 clients from SMB to global enterprise we empower organizations to safeguard their most critical assetsand adopt AI ourhighly customizableCyber 360and AI 360offerings we deliver a comprehensive range of governance assuranceengineeringprotection detectionand response services for the public and private sectors. Backed by over three decadesof operational experienceand a vast network ofhighly specialized andcertified experts weleveragecutting-edgetechnologies and AI to ensure that clients achieve their privacysecurity and businessgoals.

We operate in a remote-first environment. Office presence is typically less than 20% of the time varying by role and work requirements. Our office space located at Bloor and Islington is a collaborative space designed for in-person meetings and drop-ins. We enjoy hosting in-person quarterly townhalls and social events throughout the year to encourage teambuilding and collaboration.



Responsibilities:

  • Serve as Incident Commander for all IR Retainer engagements and Emergency IRs delivered by ISA Cybersecurity.
  • Lead digital forensic investigations across endpoint server network mobile and cloud sources.
  • Ensure chain-of-custody discipline suitable for legal proceedings.
  • Develop manage and continuously refine DFIR processes procedures playbooks and runbooks (DFIR policy authorship is out of scope and sits with other functions).
  • Conduct regular reviews and updates to DFIR people processes and technologies to ensure alignment with organizational objectives and the evolving threat landscape.
  • Present incident and digital evidence reports to key stakeholders including law enforcement legal counsel and clients; Lead post-incident reporting and client walk-throughs and translate lessons learned into process playbook tooling and training improvements.
  • Educate internal and external stakeholders on incident identification and response best practices.
  • Support presales activities including proposals Statements of Work (SOWs) and RFP responses.
  • Own the technical quality of the DFIR practice in alignment with the Security Incident Response (SIR) service card.
  • Integrate threat intelligence into incident analysis and feed TTPs back into detection content and hunting hypotheses.
  • Identify define track and report on DFIR metrics; run continuous-improvement cycles against them to drive service-quality and operational outcomes.
  • Lead and manage the IR readiness program including IR Plan engagements Tabletop Exercises (TTX) and Playbook development and/or validation.
  • Serve as a senior client-facing voice during engagements and a trusted advisor between them; brief executives boards regulators legal counsel and law enforcement as required.
  • Represent ISA externally as a recognized DFIR subject matter expert publications speaking engagements industry forums IR community participation etc.
  • Collaborate closely with SOC leadership analysts and Service Owners to ensure incident response remains tightly integrated with detection capabilities and aligned to the broader evolution of ISAs service portfolio.
  • Coach DFIR analysts and Incident Managers through technical authority case-based pairing and matrix influence; participate in hiring panels and rotation planning.



Qualifications:

  • 10 years of progressive experience in cybersecurity with at least 7 years in incident response and digital forensics roles.
  • Demonstrated experience as Incident Commander on multiple high-severity engagements (e.g. ransomware BEC APT intrusion large-scale data breach).
  • Expert-level knowledge of the incident response lifecycle containment and eradication strategies and digital forensic methodologies.
  • Hands-on expertise across host network memory mobile and cloud forensics including chain-of-custody discipline suitable for legal proceedings.
  • Proficient working with Windows Linux and MacOS
  • Experience with multi-cloud forensics (AWS Azure GCP Microsoft 365 Google Workspace) and SaaS-platform investigations.
  • Experience with OSINT (Open-Source Intelligence) including gathering and correlating publicly available information to support threat actor attribution infrastructure mapping and exposure analysis and translating findings into actionable intelligence for client engagements.
  • Working knowledge of multiple security control families such as EDR SIEM SOAR NDR identity email security DLP and their use during response.
  • Deep familiarity with MITRE ATT&CK and current ransomware/APT TTPs.
  • Working knowledge of NIST SP 800-61 ISO 27035 ISO 27001:2022 NIST CSF SOC 2 and CSA CCM.
  • Demonstrated ability to identify define track and report on operational and service-quality metrics and to run continuous-improvement cycles against them.
  • Excellent leadership-by-influence executive communication and stakeholder management skills; must be able to communicate clearly under pressure and to non-technical audiences.
  • Trusted advisor presence; ability to brief client executives and boards on cyber risk governance and resilience between as well as during incidents.
  • Bachelors degree in computer science Information Security or related field or equivalent professional experience.
  • CISSP (required).
  • Willingness to participate in 24x7 on-call rotation for IR Retainers and Emergency IRs.
  • Ability to obtain Government of Canada security clearance.
  • Strong English language skills written and verbal.

Nice to Have

  • People leadership experience including coaching mentoring performance feedback hiring panels even where the role has not formally carried direct reports.
  • Experience leading or contributing to MSSP service delivery including contractual SLAs RACI models 24x7 operations and onboarding/transition workflows.
  • Recognized externally as a subject matter expert through published research conference talks MITRE ATT&CK contributions media commentary or industry awards.
  • Experience supporting law enforcement engagements (RCMP NC3 CCCS/CCIRC FBI Cyber) Anton Piller orders expert witness testimony or regulatory investigations.
  • Experience with dark web monitoring and social-media threat monitoring.
  • Multilingual capability is an asset.

Certifications

  • Required: CISSP
  • Strongly preferred: GCIH GCFA GCIA GX-FA GSE
  • Preferred: OSCP CISM CCSP EnCE CHFI ECIH
  • Cloud (any of): AWS Security Specialty Azure Security Engineer Google Professional Cloud Security Engineer


Why Join Us

At ISA Cybersecurity we lead with our Why. Our Why is to make people feel safe. This not only applies to the result of services that we provide to our clients but how people feel when interacting with us. Whether youre an employee of ISA or a client we want you to feel safe and supported. Each one of our team members is expected to uphold this leadership quality and embrace it through consistent demonstration of our core values of Explore Persevere Adapt and Uplift.

We are proud to offer a variety of employee friendly programs that enable our team to perform at their best.

Highlights of our programs and policies include:

  • Flexible sick and personal days for all employees
  • Generous health plan with enhanced mental health resources and programs
  • Professional development opportunities and education reimbursement up to $2000 annually for all employees
  • Maternity and parental leave top-up
  • Employee referral bonus of $2000
  • Competitive salaries complemented with RRSP matching and bonus programs
  • Distance remote working policy
  • LinkedIn Learning access for all team members

We also place great value on celebrating the contributions of all employees through the following service recognition programs:

  • Service anniversary recognition and generous five-year milestone service awards
  • Presidents Club recognizing special achievement awards: Team Member of the Year for Sales CIOC and Cyber Services the Rich Uhrich Founders Award that is nominated on by all employees and four Presidents Awards (Risk Taker Lost Without You Money Maker and On the Rise)
  • Spot rewards providing opportunities for instant peer recognition

Information-sharing and team-building initiatives include:

  • Annual kick-off meeting to communicate our strategic priorities
  • Quarterly town hall meetings
  • Regular team get togethers and client events
  • Scheduled employee feedback surveys and goal setting focus groups

Thank you for your interest in joining ISA Cybersecurity. Our team looks forward to reviewing your application. We will be reaching out to you directly if your experience matches our needs.

Vacancy Status:This posting is for an existing vacancy.
Salary Range: $135000-$157500- $180000

AI Disclosure:ISA Cybersecurity does not currently use artificial intelligence tools as part of our recruitment process.



Accessibility:

ISA Cybersecurity is committed to providing accommodations for applicants with disabilities. If you require specific accommodation because of a disability or medical need please inform ISAs Human Resources team () so arrangements can be made for appropriate accommodation to be in place during the recruitment process.


Required Experience:

Senior IC


Employment Type : Full-Time
Experience: years
Vacancy: 1
Monthly Salary Salary: 135000 - 180000
Create a job alert for this search

Cybersecurity Incident Response Commander • Toronto, Ontario, Canada

Similar jobs

Associate Principal, Cybersecurity & Incident Response

Charles River AssociatesToronto, ON, CA
Full-time

A consulting firm specializing in forensic services seeks an Associate Principal in Cybersecurity & Incident Response.The role involves leading security investigations, performing digital forensics... Show more

 • Promoted

Cybersecurity - Cyber Managed Services (Industrials & Energy) - Senior Manager

EYtoronto, on, Canada
Full-time

EY is recognized by leading industry analysts as best‑in‑class in cybersecurity and managed security services.As part of our continued growth, EY Canada is seeking a Senior Manager to join our Mana... Show more

 • Promoted

Senior Incident Response Lead - Hybrid (Vancouver) - C$135,000 - C$145,000 A Year

B2B SaaS providerToronto County, Canada
Full-time

Lead incident response for a B2B SaaS provider, focusing on advanced investigations, improving detection, and mentoring junior staff in a hybrid Vancouver role. Show more

 • Promoted

Incident and Release Management Lead Role

Fidelity Internationaltoronto, on, Canada
Full-time

Fidelity Clearing Canada is looking for an Incident and Release Management Lead to streamline incident processes and oversee critical application updates.This role is essential for ensuring effecti... Show more

 • Promoted

Jsoc - Principal Cybersecurity - Incident Response - $114,143 - $142,679 A Year

Questrade Financial GroupNorth York, Canada
Full-time

Lead cybersecurity incident response and threat hunting activities, mentor the SOC team, investigate threats, manage incident lifecycles, and improve response strategies using security tools and fr... Show more

 • Promoted

Manager, IT Governance, Risk and Compliance

Pet Valumarkham, on, Canada
Full-time +1

Manager, IT Governance, Risk and ComplianceApplyremote type: Hybridlocations: 0001 – Markham Officetime type: Full timeposted on: Posted Todayjob requisition id: R25751Hybrid: Markham, On... Show more

 • Promoted

Enterprise Security Specialist

Cprvisionwhitchurch stouffville, on, Canada
Full-time

Enterprise Security Specialist.Location: Stouffville, ON • Department: R&D • Reports to: Chief Technology Officer (CTO) • Salary: $120,000 - $135,000 • Openings: 1.Lead the development, implementat... Show more

 • Promoted

Senior OT Cybersecurity Leader

BBA Consultantstoronto, on, Canada
Full-time

We’re seeking a Senior OT Cybersecurity Leader with strong strategic and technical skills to support the growth of our expertise and our industrial control systems (ICS) cybersecurity team.You’ll m... Show more

 • Promoted

Incident Management, Lead

Interac Corp.Toronto, ON, CA
Full-time

Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.At Interac, we design and deliver products and solutions that give Canadians control over their money ... Show more

 • Promoted

Incident Coordinator

ScotiabankToronto, ON, CA
Full-time

Select how often (in days) to receive an alert:.Join a purpose driven winning team, committed to results, in an inclusive and high‑performing culture.The Incident Coordinator will lead, and coordin... Show more

 • Promoted

Manager, Security Incident Response

TechAlliance of Southwestern Ontario, London Economic Development CorporationToronto, ON, CA
Full-time

Security Incident Response Manager.This role is critical to protecting our business, data, and clients by ensuring rapid, effective, and efficient responses to cybersecurity incidents and threats.T... Show more

 • Promoted

Forensics Expert in Fire and Explosion Analysis

Aviva Canadamarkham, york region, Canada
Full-time

Drive deep investigations in fires and explosions as a Forensic Engineering Expert.Utilize your expertise to assess failures, analyze evidence, and support claims professionals with precise conclus... Show more

 • Promoted

Manager, Incident Response

ScotiabankToronto, ON, CA
Full-time

Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.Contributes to the overall success of the Corporate Security / Physical Security globally ensur... Show more

 • Promoted

Cybersecurity Incident Response Commander

ISA Cybersecurity IncToronto, ON, CA
Full-time

The Cybersecurity Incident Response (IR) Commander is the technical and operational authority for ISA Cybersecurity's Digital Forensics & Incident Response (DFIR) function and holds expert-level co... Show more

 • Promoted

Threat Hunting & Incident Response Manager

Insight GlobalToronto, ON, CA
Full-time

A leading cybersecurity consultancy is looking for a Cybersecurity Manager with extensive experience in incident response and digital forensics.This role involves a mixture of technical work and ma... Show more

 • Promoted

Manager of Platform Security

Paymentusrichmond hill, york region, Canada
Full-time

The Manager of Platform Security is responsible for leading a team of security engineers focused on the security of the Paymentus SaaS platform, including web applications, RESTful APIs, cloud-nati... Show more

 • Promoted

Senior Radiation Risk Management Expert

Arcadismarkham, on, Canada
Full-time

Elevate your career as a Senior Nuclear Practice Leader at Arcadis, leading innovative radiological projects and mentoring professionals in the Radiation Risk Management sector.Arcadis seeks a Seni... Show more

 • Promoted

Cyber Incident Response Manager Position

PwC CanadaToronto, ON, CA
Full-time

Lead incident response efforts as a Cyber Incident Response Manager.Use your analytical skills and comprehensive knowledge to address sophisticated cyber threats and protect information assets.This... Show more

 • Promoted

Cybersecurity Incident Manager

PwC South AfricaToronto, ON, CA
Full-time

At PwC, our people in cybersecurity focus on protecting organisations from cyber threats through advanced technologies and strategies.They work to identify vulnerabilities, develop secure systems, ... Show more

 • Promoted

Hybrid Digital Security Specialist: Incident Response

IAMGOLD CorporationToronto, ON, CA
Full-time

A leading Canadian mining company is seeking a Digital Security Specialist to bolster its cybersecurity operations.This role involves coordinating incident responses, managing vulnerabilities, and ... Show more