Talent.com
Apex Systems
AI-focused Incident Response ContractorApex Systems • Toronto, ON
AI-focused Incident Response Contractor

AI-focused Incident Response Contractor

Apex Systems • Toronto, ON
16 days ago
Job type
  • Full-time
  • Quick Apply
Job description

Job#: 3043808

Job Description:

Job Description:

Role Title: AI-focused Incident Response Contractor

Line of Business: Technology and Operations

Ideal Start date: Mid-August

Contract duration: 6 months

Working hours: 830am-5pm ET, flexibility possible if located in another time zone

Office location: Downtown

Hybrid work requirements: 2x/week in office, but open to remote workers as well

Role Mandate:

The contractor will support the Incident Response organization’s AI initiatives through the development, evaluation, and operationalization of AI-assisted and agentic cybersecurity workflows. This includes building and testing workflows that use large language models, agent orchestration, retrieval-augmented generation, tool calling, structured outputs, and human-in-the-loop review to improve investigation efficiency, automate repeatable analyst activities, and enhance security operations. The role requires a strong cybersecurity background, preferably in Incident Response, threat detection, investigations, or security operations, combined with practical hands-on experience or strong working knowledge of AI workflow development, agent frameworks, automation, and emerging AI technologies.

Team Structure:

Standalone role on a current team of 5, with independent work but a high collaborative component across the IR team.

Role Responsibilities:

·Design, prototype, and evaluate agentic AI workflows that support Incident Response use cases such as alert triage, investigation planning, evidence summarization, enrichment orchestration, disposition recommendation, and reviewer routing.

·Build AI-enabled workflow prototypes using frameworks and patterns such as LangGraph, LangChain, Semantic Kernel, AutoGen, CrewAI, OpenAI Assistants/Agents SDKs, GitHub Copilot SDK, or similar agent development frameworks.

·Develop structured agent workflows involving tool calling, retrieval-augmented generation, multi-step reasoning, state management, memory handling, guardrails, human approval checkpoints, and deterministic workflow routing.

·Create and maintain evaluation approaches for AI-assisted security workflows, including prompt/version testing, historical backtesting, golden datasets, adjudication comparison, hallucination/error analysis, confidence calibration, precision/recall measurement, and regression testing.

·Support the design of AI workflow observability and auditability, including logging of inputs, outputs, prompts, model selections, token usage, cost attribution, tool calls, intermediate reasoning artifacts where appropriate, reviewer decisions, and final dispositions.

·Help translate AI security workflow prototypes into operationally defensible capabilities by documenting system behavior, workflow assumptions, known failure modes, guardrails, escalation criteria, fallback procedures, and human-in-the-loop controls.

·Work with technology partners to assess integration patterns between AI workflows and security platforms such as SIEM, SOAR, EDR, case management, threat intelligence, enrichment APIs, ticketing systems, and internal knowledge repositories.

·Must Have Skills:

·Strong cybersecurity background, ideally 7+ years in Incident Response, threat detection, investigations, digital forensics, security operations, threat intelligence, or adjacent cyber operations roles.

·Practical experience with security operations workflows, including alert triage, event enrichment, escalation decisioning, evidence collection, investigation documentation, case management, and incident response reporting.

·Hands-on experience designing, building, testing, or evaluating AI-assisted workflows, agentic workflows, LLM-based applications, automation pipelines, or analyst productivity tooling.

·Practical familiarity with agentic AI concepts such as tool calling, workflow orchestration, multi-step task execution, stateful agents, retrieval-augmented generation, prompt engineering, structured outputs, human-in-the-loop review, and guardrail design.

·Experience with one or more AI/agent development frameworks or SDKs such as LangGraph, LangChain, Semantic Kernel, AutoGen, CrewAI, OpenAI Assistants/Agents SDKs, GitHub Copilot SDK, Azure AI Foundry, or comparable technologies.

·Ability to develop or contribute to scripts, workflow components, prompt templates, structured schemas, evaluation harnesses, or lightweight applications using languages or tools such as Python, PowerShell, SQL, JSON/YAML, REST APIs, notebooks, or Git-based development workflows.

·Experience working with structured security data such as logs, alerts, detection outputs, case records, enrichment results, investigation notes, evidence artifacts, and historical analyst decisions to support AI-assisted analysis and backtesting.

·Familiarity with security operations tooling such as SIEM, EDR, SOAR, case management, threat intelligence platforms, enrichment APIs, data lakes, or internal security knowledge repositories.

·Understanding of AI workflow evaluation concepts, including ground-truth comparison, false positive/false negative review, confidence scoring, agreement rate, miss-rate analysis, prompt/version comparison, regression testing, and workflow reliability measurement.

·Strong analytical and problem-solving skills, with the ability to challenge AI-generated outputs, identify unsupported conclusions, validate findings against source evidence, and balance speed with investigative rigor.

·Strong written communication skills, including the ability to produce clear workflow documentation, technical notes, structured analysis, evaluation findings, governance documentation, and defensible summaries for operational and leadership audiences.

·Ability to collaborate with Incident Response leadership, analysts, domain SMEs, technology partners, and governance stakeholders to convert operational needs into practical, controlled, and measurable AI-enabled workflows.

Nice to Have Skills:

•Professional security certification such as CISSP, GCIH, GCFA, GCFE, GCFR, or equivalent

•Relevant postsecondary

EEO Employer

Apex Systems is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law. Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact our Employee Services Department at or 844-463-6178.


Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing® in Talent Satisfaction in the United States and Great Place to Work® in the United Kingdom and Mexico.

Everforth Apex Benefits Overview: In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA.

Create a job alert for this search

AI-focused Incident Response Contractor • Toronto, ON

Similar jobs

Cyber Incident Response Manager Position

PwC CanadaToronto
Full-time

Lead incident response efforts as a Cyber Incident Response Manager.Use your analytical skills and comprehensive knowledge to address sophisticated cyber threats and protect information assets.This... Show more

 • Promoted

Senior Digital Forensics & Incident Response Consultant (ID#5314)

New Value SolutionsToronto, Ontario, Canada
Full-time

We are seeking a highly skilled.This a contract opportunity on an as needed basis.This role is responsible for delivering end-to-end incident response, including forensic analysis, containment, era... Show more

 • Promoted

Consulting Associate/Cybersecurity & Incident Response (Forensic Services Practice)

Charles River AssociatesToronto, Canada
Full-time

About Charles River AssociatesCRA is a leading global consulting firm that provides independent economic and financial analysis behind litigation matters, guides businesses through critical strateg... Show more

 • Promoted

Agentic Incident Management Founder, Manufacturing

Forum VenturesToronto, ON, CA
Full-time

Factory floors generate thousands of alerts every day.At $260,000 an hour in unplanned downtime, operators can't afford to guess which one matters.Manufacturing operations run on a fragmented stack... Show more

 • Promoted

Senior Incident Response & Forensics Lead - $130,000 - $180,000 A Year

Publicis Groupe Holdings B.VNorth York, Canada
Full-time

Lead cyber security incident responses, requiring forensic analysis and strong communication skills. Show more

 • Promoted

Incident Management, Lead

Interac Corp.Toronto, ON, CA
Full-time

Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.At Interac, we design and deliver products and solutions that give Canadians control over their money ... Show more

 • Promoted

Senior Incident Response & Forensics Lead - $130,000 - $180,000 A Year

Publicis Groupe ANZToronto County, Canada
Full-time

Lead cyber security incident investigations, analyze incidents, and use forensics tools, in Toronto. Show more

 • Promoted

Fraud Prevention AI Strategy Lead

DefinityToronto
Full-time

Take the lead as a Fraud Prevention AI Strategy Lead, specializing in advanced AI applications to counter fraud.Collaborate with a talented team to shape innovative fraud detection solutions in the... Show more

 • Promoted

Consulting Associate/Cybersecurity & Incident Response (Forensic Services practice)

Charles River Associatestoronto, on, Canada
Full-time

About Charles River Associates.CRA is a leading global consulting firm that provides independent economic and financial analysis behind litigation matters, guides businesses through critical strate... Show more

 • Promoted

Manager, Incident Response

ScotiabankToronto, ON, CA
Full-time

Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.Contributes to the overall success of the Corporate Security / Physical Security globally ensur... Show more

 • Promoted

Security Analyst: Incident Response, Audits & Policy

Onico SolutionsRichmond Hill, York Region, CA
Full-time

A leading security solutions provider is seeking a Security Analyst to oversee and enhance information security across IT infrastructure.This role involves identifying security threats, responding ... Show more

 • Promoted

Manager, Security Incident Response

TechAlliance of Southwestern Ontario, London Economic Development CorporationToronto, ON, CA
Full-time

Security Incident Response Manager.This role is critical to protecting our business, data, and clients by ensuring rapid, effective, and efficient responses to cybersecurity incidents and threats.T... Show more

 • Promoted

Senior Associate/Cybersecurity & Incident Response (Forensic Services practice)

Charles River AssociatesToronto, Ontario, Canada
Full-time

About Charles River Associates.CRA is a leading global consulting firm that provides independent economic and financial analysis behind litigation matters, guides businesses through critical strate... Show more

 • Promoted

Incident Response Associate — Toronto or Ottawa

IBMToronto
Full-time

A leading IT services provider is seeking an Associate for their X-Force Incident Response team in Toronto or Ottawa.Candidates will engage in global cyber incident response, utilizing advanced ski... Show more

 • Promoted

Ai Platform Sre: Reliability & Incident Response - $94,300 - $141,500 A Year

Global Financial Services FirmEast York, Canada
Full-time

Seeking an AI Platform SRE in Mississauga to ensure stability and performance of AI and DevOps platforms, coordinate daily activities, and resolve incidents with engineering teams.Requires 5-8 year... Show more

 • Promoted

Incident Analyst

DexianToronto, ON, CA
Full-time

Type: 1-year contract, contract-to-potential full-time.Location : Toronto, ON (Hybrid 2 days/ week).Lead remediation of incidents impacting Capital Markets.Act as a stakeholder in Major Incidents.D... Show more

 • Promoted

Senior Incident Response Lead - Hybrid (Vancouver) - C$135,000 - C$145,000 A Year

B2B SaaS providerEast York, Canada
Full-time

Lead incident response for a B2B SaaS provider, focusing on advanced investigations, improving detection, and mentoring junior staff in a hybrid Vancouver role. Show more

 • Promoted

Incident and Release Management Lead Role

Fidelity InternationalToronto, ON, CA
Full-time

Fidelity Clearing Canada is looking for an Incident and Release Management Lead to streamline incident processes and oversee critical application updates.This role is essential for ensuring effecti... Show more

 • Promoted

Experienced Solutions Engineer for Robust Incident Management

RootlyToronto, ON, CA
Full-time

Drive impactful incident management solutions as a Solutions Engineer.Utilize your technical skills and passion for customer success to guide implementations across diverse platforms.In this positi... Show more

 • Promoted

Incident Coordinator

ScotiabankToronto
Full-time

Select how often (in days) to receive an alert:.Join a purpose driven winning team, committed to results, in an inclusive and high‑performing culture.The Incident Coordinator will lead, and coordin... Show more