Senior Incident Response Consultant 2
Summary
A senior DFIR consultant leads cybersecurity incident response engagements end to end — investigating ransomware, business email compromise, and network breaches, directing forensic analysts, briefing customers and executives, and producing MITRE ATT&CK-mapped reports. Core toolkit spans cloud forensics (AWS, Azure, GCP), SIEM platforms, and scripting.
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Incident Response Consultant 2 based in Canada.
This senior cybersecurity role sits at the forefront of complex digital forensics and incident response engagements, helping organizations contain and recover from sophisticated cyberattacks. You will lead high-impact investigations involving ransomware, network breaches, business email compromise, insider threats, and web applications. As an incident lead, you will direct technical teams, prioritize investigations, communicate findings to customers, and coordinate response activities with key stakeholders. You will combine forensic expertise, threat intelligence, and structured incident response methodologies to identify attacker activity and root causes. The role also involves translating complex technical findings into clear executive-level reporting and actionable remediation guidance. Working across multiple incidents and time zones, you will play a critical role in strengthening customer resilience against evolving cyber threats.
Accountabilities:
As a Senior Incident Response Consultant, you will lead customer engagements from initial assessment through investigation, containment, remediation guidance, and final reporting. You will act as a trusted technical advisor while coordinating analysts, customers, legal counsel, and other stakeholders throughout high-pressure incidents.
- Lead customer kickoff calls, assess the situation, and identify immediate actions required to contain threats.
- Act as a trusted advisor by providing customers with practical incident response and remediation guidance.
- Lead daily customer update calls and communicate forensic findings clearly and confidently.
- Provide concise written updates to customers between scheduled calls.
- Direct forensic investigations, establish priorities, and delegate investigative tasks to analysts.
- Manage multiple incident response engagements concurrently while maintaining quality and responsiveness.
- Review findings and determine attacker tactics, techniques, and procedures (TTPs), contributing relevant intelligence to threat intelligence platforms.
- Ensure appropriate actions are completed by both internal teams and customers to effectively neutralize threats.
- Conduct root cause analysis to determine how incidents originated and assess potential data exfiltration where sufficient evidence is available.
- Produce clear, timely executive-summary reports containing incident timelines mapped to the MITRE ATT&CK framework and actionable remediation recommendations.
- Coordinate with legal counsel, cyber insurance carriers, and other external stakeholders when required.
- Provide daily handover notes across time zones and during transitions between incident leads.
- Contribute to basic and moderately complex projects that improve and expand the incident response service.
- Mentor junior analysts, share knowledge, and contribute to the continuous development of the wider incident response team.
- 10+ years of experience leading incident response investigations involving ransomware, network breaches, malicious insiders, web applications, and database services.
- Proven experience leading business email compromise (BEC) investigations.
- Strong digital forensic analysis experience across cloud environments such as AWS, Microsoft Azure, and GCP.
- Proven ability to successfully neutralize and support remediation of ransomware threats.
- Excellent understanding of incident response processes, methodologies, and best practices.
- Strong understanding of cyber risks and the ability to assess and communicate those risks effectively to customers.
- Experience across areas such as computer, network, cloud, memory, and email forensics, threat hunting, threat analysis, web application security, penetration testing, red/blue team exercises, or OSINT.
- Strong understanding of the MITRE ATT&CK framework.
- Excellent verbal communication and strong written communication skills.
- Demonstrated ability to manage priorities, delegate effectively, and coordinate work across multiple incidents.
- Ability to remain logical, pragmatic, meticulous, analytical, and authoritative during high-pressure situations.
- Strong technical leadership skills and the ability to manage and mentor incident response teams.
- Curiosity, sound judgment, a willingness to ask questions, and a strong commitment to continuous learning.
- Collaborative mindset with a willingness to share knowledge and support the development of junior analysts.
- Ability to occasionally start early, work late, or support weekends and holidays when customer incidents require it.
- Cybersecurity certifications such as CISSP, GCFA, or similar are an asset.
- Experience with SIEM platforms such as Splunk or ELK is desirable.
- Experience writing SQL queries is a plus.
- Experience scripting with PowerShell, Python, or Bash is desirable.
- Willingness to provide occasional overtime support during peak periods or critical engagements.
- Base salary of $131,000–$219,000 CAD.
- Additional compensation, including eligibility for a bonus.
- Comprehensive employee benefits package.
- Remote-first working model, with some roles potentially requiring a hybrid approach.
- Opportunity to lead high-profile cybersecurity incidents and complex DFIR engagements.
- Exposure to advanced forensic investigations, threat intelligence, cloud security, and incident response.
- Work alongside experienced cybersecurity professionals in a globally distributed environment.
- Opportunities to mentor analysts and contribute to the development of incident response capabilities.
- Employee-led diversity and inclusion networks supporting community, education, and advocacy.
- Annual charity, fundraising, and employee volunteer initiatives.
- Global sustainability initiatives focused on reducing environmental impact.
- Global fitness and trivia activities supporting employee engagement and wellbeing.
- Global wellbeing days, monthly wellbeing webinars, and training focused on employee health and wellbeing.
- Applicants must have legal authorization to work in Canada without requiring employer sponsorship.
Requirements:
The ideal candidate brings extensive hands-on incident response leadership experience, strong forensic expertise, and the ability to make sound decisions during complex and high-pressure cybersecurity events. You should be comfortable leading technical teams and customer engagements rather than simply reviewing investigative data.
Benefits:
Skills
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company