12 Aug
|
Mjolnir Security
|
Toronto
12 Aug
Mjolnir Security
Toronto
Company Description Mjolnir Security Inc. is a Canadian-owned and operated cybersecurity firm providing advanced AI/ML-driven security operations, threat detection, dark web intelligence, digital forensics, and incident response services. The organization supports both corporate and public agencies, with a strong focus on law enforcement and specialized cyber training for police services across Canada. Since its launch in 2017, Mjolnir’s leadership team has brought over a century of combined experience in delivering security solutions to clients ranging from Fortune 500 companies to small family-owned businesses.
The team has deep industry expertise across sectors including energy, utilities, mining, transportation, telecom, health care, manufacturing, military, and government. Mjolnir is recognized for its committed, knowledgeable, and trusted security professionals who work closely with clients to address complex cyber threats. We are hiring an experienced Level 2 Security Analyst to work onsite from our Toronto office.
You are the escalation point for our Level 1 analysts and the person clients hear from when something real is happening in their environment. You will investigate escalated detections, determine scope and impact, drive containment, and hand off to our DFIR practice when an incident warrants deeper forensic work. A significant portion of our client base operates in both official languages.
This role requires professional fluency in English and French — not conversational familiarity. You will write incident notifications, brief client stakeholders, and take escalation calls in both languages. What you will do:
Take ownership of escalated alerts from Level 1, validating findings and driving investigations to a documented conclusion
Perform in-depth analysis across endpoint, identity, email, cloud, and network telemetry to establish root cause, scope, and impact
Build and refine detection logic, tune rules to reduce false positives, and close gaps you identify during investigations
Execute containment and remediation actions within client-approved playbooks, and recommend actions that fall outside them
Write clear incident notifications, investigation summaries, and client-facing reports in English and French
Brief client technical contacts and, when required, non-technical stakeholders during active incidents
Act as the technical handoff point to the DFIR team when an incident escalates beyond SOC scope, including preservation of evidence and chain of custody
Mentor Level 1 analysts — review their work, coach their triage decisions, and improve the runbooks they rely on
Contribute to proactive threat hunting campaigns informed by our threat intelligence function
Participate in an on-call rotation for after-hours escalations What you bring Required
Four or more years in a security operations role, including at least two years operating at Level 2 or equivalent escalation responsibility
Professional working fluency in English and French, spoken and written, sufficient to lead a client call and author a formal notification in either language
Demonstrated hands-on investigation experience across SIEM, EDR, identity,
and email security telemetry — including writing your own queries rather than working solely from prebuilt dashboards
Practical command of attacker tradecraft and the ability to map observed activity to MITRE ATT&CK;
Working knowledge of Windows and Linux internals, Active Directory and Entra ID, and common cloud service telemetry
Strong written documentation discipline — your case notes need to hold up to client and, occasionally, legal scrutiny
Ability to work onsite in our Toronto office five days per week
Eligibility to work in Canada, and willingness to undergo a criminal record check and employment verification as a condition of employment (several of our clients require this) Preferred
Certifications such as GCIA, GCIH, GCFA, BTL2, or Microsoft SC-200
Prior experience in an MSSP or multi-tenant environment, managing competing client priorities
Exposure to digital forensics, malware triage, or incident response consulting
Familiarity with Canadian regulatory and privacy obligations relevant to financial services or critical infrastructure clients
Scripting ability (Python, PowerShell) for enrichment and automation This is an onsite role based in downtown Toronto. Our SOC operates on scheduled coverage with an on-call rotation for escalations outside standard hours. Occasional travel to client sites within the Greater Toronto Area may be required during major incidents. We thank all applicants for their interest. Only shortlisted candidates will be contacted for next steps.
Mjolnir
Security is an equal prospect employer. We welcome applications from all qualified candidates and provide accommodation throughout the recruitment process on request.
📌 Security Analyst, Level 2 (Bilingual — English/French) (Toronto)
🏢 Mjolnir Security
📍 Toronto