Overview At CAAT, we’re passionate about what we do. We’re known for a can-do culture and a commitment to better retirement security. We challenge the status quo and have a broad impact on the hundreds of employers we serve, from education institutions to major corporations and household brands. We’re driven by core values and a shared purpose and are growing rapidly as part of our mission. About The Role We are seeking a Senior Cybersecurity Engineer – ML SecOps for our Technology & IT Services Management team. Reporting to the Manager, Cybersecurity Operations, the Senior Cybersecurity Engineer – ML SecOps provides expert technical leadership in security operations, ML-driven detection engineering, SOAR automation, and adversarial security testing, directly supporting next-generation SOC capabilities. This role leads complex incident investigations, advanced forensics, and threat-hunting, while designing ML-enhanced detection models and automation pipelines to improve SOC efficiency. The engineer evaluates emerging AI/ML security technologies, conducts resilience testing, and supports major incident response with hands-on expertise and architectural guidance. As a technical authority within the Cybersecurity Operations team, they mentor junior staff, develop detection content, and drive continuous improvement to align ML-driven capabilities with evolving threats and regulatory standards. Their work advances the organization’s 24x7 SOC strategy, enabling cyber defenders to operate with greater precision and intelligence. Responsibilities Lead advanced security engineering initiatives across hybrid and cloud environments, delivering robust detections, continuous monitoring, forensics, and incident response capabilities. Develop sophisticated AI and ML-based detections, including behavioral analytics, anomaly models, and predictive SOC monitoring frameworks for emerging threats. Design and automate cross-platform SOAR workflows, Sentinel playbooks, enrichment pipelines, and containment logic to enhance SOC response efficiency. Architect, optimize, and scale Microsoft Sentinel through customized KQL analytics, UEBA models, and automation to reduce false positives. Maintain expert proficiency with EDR, SIEM, SOAR,
and cloud-native tools such as CrowdStrike, Tenable, and Azure Defender. Lead intelligence-driven, hypothesis-based, and ML-assisted threat hunting operations to uncover emerging tactics and reduce attacker dwell time. Secure MLOps pipelines through governance controls, model validation, artifact integrity, CI/CD protection, and resilient retraining workflows. Enhance SOC effectiveness by developing new detections, reusable content, AI-driven playbooks, and modernized response processes across all tiers. Collaborate closely with Cloud, Identity, Data, and DevOps teams to embed detection logic and automated controls into enterprise platforms, while interacting with external vendors and Managed Security Service Providers (MSSPs). Act as senior technical escalation point, performing in-depth analysis, forensics, and containment support during high-severity cybersecurity incidents. Qualifications Bachelor’s degree in Computer Science, Cybersecurity, or related field, or equivalent hands-on experience. A minimum of seven (7) to ten (10) years of progressive, hands-on cybersecurity experience in SOC operations, detection engineering, and incident response. A minimum of six (6) years of applied experience with ML/AI-driven security operations, including behavioral analytics, anomaly detection, and SOAR automation. Expert knowledge of security frameworks including MITRE ATT&CK, NIST AI RMF, and Zero Trust architectures. Proven ability to engineer and automate ML-augmented detection pipelines and integrate threat hunting into SOC workflows. Deep experience securing cloud-native infrastructure (Azure/AWS/GCP) and applying security automation via Python, PowerShell, or Bash. Hands-on experience in digital forensics (endpoint, cloud, malware) and supporting major incident response investigations. Background in securing MLOps pipelines, ensuring governance, model integrity,
and CI/CD security for AI/ML workflows. Demonstrated ability to uplift SOC capabilities through reusable detection libraries, AI-enhanced frameworks, and mentoring junior staff. Industry certifications (CIH, GCFA, GNFA, GCFE, GCTI, GMON, GCDA, OSCP, OSCE, OSEP, CRTO, Machine learning or cloud certifications AWS/Azure ML, TensorFlow, Google Cloud Qualified ML Engineer) are preferred. Compensation and Benefits The target hiring salary for this position is $122,000 – $152,600. Placement within our salary range will be based on factors such as internal equity, market conditions, and the candidate’s experience, skills, and qualifications relevant to the role. At CAAT, we believe innovation, passion, and purpose are ingredients for a great work environment. We’re proud of our people and the impact they have as catalysts for change. We offer competitive compensation, exceptional benefits, and an environment where people can grow and thrive. When you work with CAAT, you’ll enjoy: Opportunities to Build a Better You: continuous learning and career growth. Comprehensive & Holistic Care: Total Rewards program for physical, mental, and financial wellness, flexible work arrangements, benefits, and a defined benefit pension plan. A Place to Collaborate and Win: a collaborative culture recognized as one of Canada’s admired corporate cultures and top employers. Work that Truly Matters: contributing to better retirement security for Canadians. If you believe Canadians deserve a future with secure retirement income, CAAT could be the right fit. Start your journey with us today. Apply now. Learn more about us at No artificial intelligence tools are used to screen, assess, or select applicants for this position. AI tools may be used to help recruiters identify potential candidates on external platforms. All hiring decisions are made by human reviewers. DEIB and Accessibility CAAT is an equal opportunity employer. We will accommodate needs under the Accessibility for Ontarians with Disabilities Act and the Ontario Human Rights Code. If accommodation is required during the application process, please contact or call Human Resources at. #J-18808-Ljbffr
📌 Senior Cybersecurity Engineer - Ml Secops - $122,000 - $152,600 A Year (Toronto)
🏢 Caat
📍 Toronto