13 Aug
|
Mjolnir Security
|
Toronto
13 Aug
Mjolnir Security
Toronto
Company Description
Mjolnir Security Inc. is a Canadian-owned and operated cybersecurity firm providing advanced AI/ML-driven security operations, threat detection, dark web intelligence, digital forensics, and incident response services. The organization supports both corporate and public agencies, with a solid focus on law enforcement and specialized cyber training for police services across Canada. Since its launch in 2017, Mjolnir’s leadership team has brought over a century of combined experience in delivering security solutions to clients ranging from Fortune 500 companies to small family-owned businesses.
The team has deep industry expertise across sectors including energy, utilities, mining, transportation, telecom, health care, manufacturing, military, and government. Mjolnir is recognized for its committed, knowledgeable, and trusted security professionals who work closely with clients to address complex cyber threats.
We are hiring an experienced Level 2 Security Analyst to work onsite from our Toronto office. You are the escalation point for our Level 1 analysts and the person clients hear from when something real is happening in their environment. You will investigate escalated detections, determine scope and impact, drive containment, and hand off to our DFIR practice when an incident warrants deeper forensic work.
A significant portion of our client base operates in both official languages. This role requires professional fluency in English and French — not conversational familiarity. You will write incident notifications, brief client stakeholders, and take escalation calls in both languages.
What you will do:
- Take ownership of escalated alerts from Level 1, validating findings and driving investigations to a documented conclusion
- Perform in-depth analysis across endpoint, identity, email, cloud, and network telemetry to establish root cause, scope, and impact
- Build and refine detection logic, tune rules to reduce false positives, and close gaps you identify during investigations
- Execute containment and remediation actions within client-approved playbooks, and recommend actions that fall outside them
- Write clear incident notifications, investigation summaries, and client-facing reports in English and French
- Brief client technical contacts and, when required, non-technical stakeholders during active incidents
- Act as the technical handoff point to the DFIR team when an incident escalates beyond SOC scope, including preservation of evidence and chain of custody
- Mentor Level 1 analysts — review their work, coach their triage decisions, and improve the runbooks they rely on
- Contribute to proactive threat hunting campaigns informed by our threat intelligence function
- Participate in an on-call rotation for after-hours escalations
What you bring
Required
- Four or more years in a security operations role, including at least two years operating at Level 2 or equivalent escalation responsibility
- Professional working fluency in English and French, spoken and written, sufficient to lead a client call and author a formal notification in either language
- Demonstrated hands-on investigation experience across SIEM, EDR, identity,
and email security telemetry — including writing your own queries rather than working solely from prebuilt dashboards
- Practical command of attacker tradecraft and the ability to map observed activity to MITRE ATT&CK;
- Working knowledge of Windows and Linux internals, Active Directory and Entra ID, and common cloud service telemetry
- Strong written documentation discipline — your case notes need to hold up to client and, occasionally, legal scrutiny
- Ability to work onsite in our Toronto office five days per week
- Eligibility to work in Canada, and willingness to undergo a criminal record check and employment verification as a condition of employment (several of our clients require this)
Preferred
- Certifications such as GCIA, GCIH, GCFA, BTL2, or Microsoft SC-200
- Prior experience in an MSSP or multi-tenant environment, managing competing client priorities
- Exposure to digital forensics, malware triage, or incident response consulting
- Familiarity with Canadian regulatory and privacy obligations relevant to financial services or critical infrastructure clients
- Scripting ability (Python, PowerShell) for enrichment and automation
This is an onsite role based in downtown Toronto. Our SOC operates on scheduled coverage with an on-call rotation for escalations outside standard hours. Occasional travel to client sites within the Greater Toronto Area may be required during major incidents. We thank all applicants for their interest. Only shortlisted candidates will be contacted for next steps.
Mjolnir Security is an equal opportunity employer. We welcome applications from all qualified candidates and provide accommodation throughout the recruitment process on request.
📌 Security Analyst, Level 2 (Bilingual — English/French) (Toronto)
🏢 Mjolnir Security
📍 Toronto