Talent.com
Manager, Digital Forensics Incident Response/ Responsable des enquêtes numériques et de la réponse aux incidents
Manager, Digital Forensics Incident Response/ Responsable des enquêtes numériques et de la réponse aux incidentsSITA • Montreal, CA
Manager, Digital Forensics Incident Response/ Responsable des enquêtes numériques et de la réponse aux incidents

Manager, Digital Forensics Incident Response/ Responsable des enquêtes numériques et de la réponse aux incidents

SITA • Montreal, CA
30+ days ago
Job type
  • Full-time
Job description

Overview

WELCOME TO SITA

At , we keep airports moving, airlines flying smoothly, and borders open. Our technology and communication innovations power the success of the global air travel industry.

Youll find us in 95% of international airports, working closely with over 2,500 transportation and government clients. Each partnership brings unique challenges, and we thrive on delivering fresh solutions and cutting-edge tech to keep operations running like clockwork. We dont just move the world forward, were proud to be recognized as a Great Place to Work® by our employees and certified in most of our growing locations. Here, we feel empowered, supported, and inspired to grow.

Are you ready to love your job? The adventure begins right here, with you, at SITA.

PURPOSE

As the Digital Forensics & Incident Response Lead, you will take full ownership of high-severity investigationsrapidly detecting, containing, and neutralizing threatswhile driving digital forensics and proactive threat hunting initiatives. You will act as Incident Commander and serve as the primary technical escalation point for complex cases.

You will join SITAs STORM (Security Threat & Operational Risk Management) organization, collaborating closely with SOC, CTI, Cloud/Platform, Product, and customer-facing teams to enhance detection and response capabilities across SITA, our clients, and the broader air-transport ecosystem.

ABOUT THE ROLE & TEAM

As the Digital Forensics & Incident Response Lead, you will take full ownership of high-severity investigationsrapidly detecting, containing, and neutralizing threatswhile driving digital forensics and proactive threat hunting initiatives. You will act as Incident Commander and serve as the primary technical escalation point for complex cases.

You will join SITAs STORM (Security Threat & Operational Risk Management) organization, collaborating closely with SOC, CTI, Cloud/Platform, Product, and customer-facing teams to enhance detection and response capabilities across SITA, our clients, and the broader air-transport ecosystem.

WHAT YOU WILL DO

Incident Response & Coordination

  • Lead high/critical incident response: containment, eradication, recovery, and post-incident hardening.
  • Act as Incident Commander, coordinating SOC, CTI, IT, cloud, product, and business teams.
  • Produce reports, executive readouts, and track lessons learned.
  • Update playbooks, detections, and response patterns based on evolving threats.

Digital Forensics & Evidence Handling

  • Perform forensically sound acquisition and analysis across endpoints, servers, cloud, network, and SaaS.
  • Maintain chain-of-custody and document to industry standards.
  • Reconstruct attacker activity and map to MITRE ATT&CK.

Threat Hunting & Detection Engineering

  • Conduct hypothesis-driven hunts across EDR, SIEM, cloud, and network telemetry.
  • Convert findings into high-fidelity detections, analytics, and SOAR automations.
  • Validate and tune rules to reduce false positives and improve coverage.

Triage, Monitoring & QA

  • Oversee L1/L2 triage quality, severity calibration, and playbook execution.
  • Refine thresholds, use cases, runbooks, dashboards, and KPIs.

Tooling, Automation & Telemetry

  • Develop scripts and tools to accelerate evidence collection and response.
  • Partner with platform owners to improve logging, telemetry, and retention at scale.

Qualifications

ABOUT YOUR SKILLS

  • Proven experience leading incident response and digital forensics in hybrid environments.
  • Hands-on with EDR (CrowdStrike), SIEM (Splunk, Sentinel, Elastic), and SOAR.
  • Scripting for DFIR/automation (Python/PowerShell); familiarity with KQL.
  • Deep knowledge of attacker tradecraft and MITRE ATT&CK.
  • Excellent communication skills to brief executives and guide teams.

Nice-to-Have:

  • Certifications: GCFA, GNFA, GCIH, GREM, OSCP, CISSP.
  • Cloud DFIR (Azure/AWS/GCP) and identity-centric investigations (Entra ID/Okta).
  • Exposure to OT/airport systems in air-transport environments.

WHAT WE OFFER

Were all about diversity. We operate in 200 countries and speak 60 different languages and cultures. Were really proud of our inclusive environment. Our offices are comfortable and fun places to work, and we make sure you get to work from home too. Find out what it's like to join our team and take a step closer to your best life ever.

Flex Week: Work from home up to 2 days/week (depending on your teams needs)

Flex Day: Make your workday suit your life and plans. (Depending on the stakeholders and BISO Directors needs)

Flex Location: Take up to 30 days a year to work from any location in the world.

Employee Wellbeing: Weve got you covered with our Employee Assistance Program (EAP), for you and your dependents 24/7, 365 days/year. We also offer Champion Health a personalized platform that supports a range of wellbeing needs.

Professional Development: Level up your skills with our training platforms, including LinkedIn Learning!

Competitive Benefits: Competitive benefits that make sense with both your local market and employment status.

SITA is an Equal Opportunity Employer. We value a diverse workforce. In support of our Employment Equity Program, we encourage women, aboriginal people, members of visible minorities, and/or persons with disabilities to apply and self-identify in the application process.

Create a job alert for this search

Manager, Digital Forensics Incident Response/ Responsable des enquêtes numériques et de la réponse aux incidents • Montreal, CA

Similar jobs
Security Operations Lead — Incident Response & DFIR

Security Operations Lead — Incident Response & DFIR

Ubisoft Entertainment • Montreal
Full-time
A leading game development studio in Montreal seeks a Security Team Lead to oversee its Security Operations Center and Digital Forensics team.The role requires strong leadership to drive incident r...Show more
Last updated: 10 days ago • Promoted
Incident/Change Management Specialist

Incident/Change Management Specialist

Talan Group • Montreal
Full-time
Talan est un groupe international de conseil et d’expertises technologiques qui accélère la transformation de ses clients par les leviers de l'innovation, la technologie et la data.Depuis plus de 2...Show more
Last updated: 30+ days ago • Promoted
Analyste Itsm – Optimisation Des Services Et Incidents

Analyste Itsm – Optimisation Des Services Et Incidents

Dollarama • Mount Royal, Canada
Full-time
Une entreprise canadienne recherche un Analyste en gestion des services informatiques pour superviser et améliorer les processus de gestion des services.Le candidat idéal aura au moins 3 ans d'expé...Show more
Last updated: 30+ days ago • Promoted
Responsable Conformité Cybersécurité & Gouvernance Cloud

Responsable Conformité Cybersécurité & Gouvernance Cloud

un emploi de Team lead RO chez Vooban • Montreal
Full-time
Une entreprise technologique de pointe à Montréal recherche un Team Lead en conformité cybersécurité.Vous serez responsable de gérer le programme de conformité ISO 27001 et d'évaluer les risques.Le...Show more
Last updated: 7 days ago • Promoted
Leader SecOps – Cybersécurité Opérationnelle

Leader SecOps – Cybersécurité Opérationnelle

Réseau de transport de Longueuil • Longueuil, Montérégie, Canada
Full-time
Une organisation de transport public à Longueuil recherche un chef technique en cybersécurité opérationnelle.La mission inclut la supervision de l’implantation et l’amélioration des solutions techn...Show more
Last updated: 18 days ago • Promoted
MONTREAL [Hybrid] - Incident & Problem Manager

MONTREAL [Hybrid] - Incident & Problem Manager

QUANTEAM (RAINBOW PARTNERS Group) • Montreal
Full-time
As the founding entity of RAINBOW PARTNERS, QUANTEAM is a consulting firm specializing in the fields of Banking, Finance, and Financial Services.Guided by our core values of closeness, teamwork, di...Show more
Last updated: 30+ days ago • Promoted
Information Technology Audit Manager (Bilingual FR/EN)

Information Technology Audit Manager (Bilingual FR/EN)

PwC Canada • Montreal
Full-time
A career in our External Audit Third Party Trust Services practice, within Risk Assurance, will enable you to assist clients in optimising control activities, organisational strategy, and policies ...Show more
Last updated: 30+ days ago • Promoted
Spécialiste Cybersécurité — Gouvernance, Incidents & BC-DR

Spécialiste Cybersécurité — Gouvernance, Incidents & BC-DR

Budge Studios • Montreal
Full-time
Une entreprise de jeux vidéo à Montréal recherche un spécialiste en cybersécurité pour assurer la sécurité de son infrastructure.Ce rôle implique la supervision des vulnérabilités, la gestion des i...Show more
Last updated: 3 days ago • Promoted
Forensic &Disputes Senior Associate (FR/EN) – Hybrid

Forensic &Disputes Senior Associate (FR/EN) – Hybrid

PwC - Global • Montreal
Full-time
A leading consulting firm based in Montreal is seeking a Senior Associate in Forensic & Dispute services.The role involves helping clients investigate vulnerabilities, providing analytical support ...Show more
Last updated: 4 days ago • Promoted
Leader Sénior – Prévention et Détection de la Fraude

Leader Sénior – Prévention et Détection de la Fraude

Cogeco Inc. • Montreal
Full-time
Une entreprise de télécommunications recherche un conseiller principal pour diriger les initiatives de prévention et de détection de la fraude.Situé à Montréal, ce poste nécessite des compétences e...Show more
Last updated: 5 days ago • Promoted
Fire Cause Forensic Engineer – Investigation Specialist

Fire Cause Forensic Engineer – Investigation Specialist

Intact • Laval, Canada
Full-time
Une entreprise de prestations d'assurance recherche un ingénieur en recherche de cause incendie à Laval.Le candidat jouera un rôle crucial dans l'investigation et la gestion des réclamations incend...Show more
Last updated: 30+ days ago • Promoted
Directeur Audit Informatique – Leadership en Sécurité IT

Directeur Audit Informatique – Leadership en Sécurité IT

Mallette • Montreal
Full-time
Une société de services comptables de premier plan à Montréal recherche un directeur ou une directrice en audit informatique.Vous jouerez un rôle clé dans la communication d'informations techniques...Show more
Last updated: 27 days ago • Promoted
Responsable Incidents Cyber – Leadership & Remédiations

Responsable Incidents Cyber – Leadership & Remédiations

Delan • Montréal, Canada
Full-time
Une entreprise de sécurité informatique à Montréal recherche un Responsable Gestion des Incidents de Cybersécurité.Vous serez en charge des opérations de réponse aux incidents, de la gestion et du ...Show more
Last updated: 30+ days ago • Promoted
It Operations & Incident Lead

It Operations & Incident Lead

Alteo • Montréal, Canada
Full-time
Une entreprise de gestion des opérations recherche un Responsable Opérations et Incidents pour rejoindre son équipe à Montréal.Votre rôle inclura la définition et mise en œuvre de procédures, le su...Show more
Last updated: 9 days ago • Promoted
Analyste ITSM – Amélioration Continue & Incidents

Analyste ITSM – Amélioration Continue & Incidents

Kinessor • Montreal
Full-time
Une entreprise de services informatiques cherche un Analyste en gestion des services informatiques à Montréal pour chapeauter les processus ITSM, améliorer continuellement les opérations et gérer l...Show more
Last updated: 30+ days ago • Promoted
Analyste Réseaux & Sécurité N3 – Incidents & Infra Hybride

Analyste Réseaux & Sécurité N3 – Incidents & Infra Hybride

ALFACONSEIL.CA • Montreal-Ouest
Full-time
Une entreprise de services en TI recherche un(e) analyste sénior en réseautique pour jouer un rôle clé dans la gestion des infrastructures et de la sécurité IT.Le candidat idéal possède une expérie...Show more
Last updated: 30+ days ago • Promoted
Strategic Leader, Workplace Investigations

Strategic Leader, Workplace Investigations

Bombardier • Dorval, Quebec, Canada
Full-time
A leading aerospace company seeks a Manager of Workplace Investigations in Dorval, Quebec.The successful candidate will lead a team, establish investigation methods, and prepare comprehensive repor...Show more
Last updated: 12 days ago • Promoted
Analyste Sécurité - Incidents & Stratégie Cloud Télétravail

Analyste Sécurité - Incidents & Stratégie Cloud Télétravail

Reelcruit • Candiac, Montérégie, Canada
Remote
Full-time
Une entreprise de services de TI recherche un Analyste sécurité pour gérer tous les aspects de la sécurité informatique.Le candidat idéal devra avoir entre 3 et 5 ans d'expérience dans ce domaine, ...Show more
Last updated: 22 days ago • Promoted