Senior Security Engineer (Toronto)

Senior Security Engineer (Toronto)

19 Aug
|
EvenUp
|
Toronto

19 Aug

EvenUp

Toronto

Who you are

- 5+ years in security operations, detection engineering, or incident response, including experience building (not just running) a detection and response capability at a startup or high-growth technology company

- Hands-on experience implementing or significantly maturing a SIEM, including custom log sources and detection content — not just operating one that was handed to you

- Strong detection engineering skills: writing detections in Python, SQL, or a rules DSL, managing them in version control, and measuring their quality

- Real incident response experience — you've led investigations, written the playbooks, and run the retros

- Experience with cloud-native telemetry (AWS/GCP/Azure control plane, identity providers, endpoint, SaaS audit logs)

- Strong programming or automation skills (Python preferred); comfort building integrations and response automation

- Experience partnering directly with software engineers to instrument applications for security visibility is a solid plus

- Familiarity with securing or monitoring AI/LLM-powered systems is a strong plus

- Experience working with MDR/MSSP providers — and opinions about what they're good and bad at
- A builder mentality — you'd rather engineer the alert away than triage it forever

- Relevant security certifications (GIAC/GCIA/GCIH, CISSP, etc.) are a plus, but practical engineering experience matters more

What the job involves

- We're looking for a hands-on Senior Security Engineer to build our detection and response program: the telemetry pipelines, the SIEM, the detection content, and the incident response muscle behind them. You won't inherit a SOC — you'll design one





- This isn't a role where you'll stare at a queue of vendor alerts. The threats that matter most to us don't come out of any box: they live in our own applications and data flows, and detecting them means partnering with the engineers who build those systems. We believe security should accelerate the business, not slow it down. If you're excited about treating detection as an engineering discipline, we'd love to chat

- Build the program, not just the rules: select the SIEM, design the telemetry architecture, and write the first generation of detections; your technical decisions become the foundation

- Detect what actually matters: focus on highest-stakes risks unique to our business, like sensitive data moving to the wrong place, misuse of internal systems, and exposure of health information, as generic detection content cannot address these

- Detection as code: detections are written, version-controlled, tested, and reviewed like software

- Own incident response: define how EvenUp responds to incidents, including playbooks, tabletop exercises, and post-incident reviews

- Direct the vendors, don't answer to them: when using managed providers for 24/7 coverage, you set the requirements, escalation logic, and quality standards

- Build Our Detection Platform:



Lead SIEM evaluation and implementation, design log ingestion and routing pipelines, and make deliberate cost/retention trade-offs across hot search and long-term archive

- Engineer High-Signal Detections: Develop and tune detection content across cloud, identity, endpoint, SaaS, and application telemetry — with an emphasis on business-logic detections built on our own products' audit events

- Define the Telemetry Contract: Partner with Engineering and DevOps to specify what our applications and infrastructure must log — the audit events that make our most important risks detectable in the first place

- Lead Incident Response: Build and maintain IR playbooks and runbooks, coordinate response during security events, run the annual tabletop exercise, and drive post-incident reviews that actually change things

- Detect Data Exposure: Partner with internal teams to detect sensitive data moving where it shouldn't — including PHI — across applications, endpoints, and SaaS

- Manage 24/7 Coverage: Define requirements for and direct our managed detection partners, own escalation procedures, and continuously raise the bar on what "monitored" means

Benefits

- Flexible working hours to match your style

- Offsites - get to meet your coworkers on a fully-expenses trip ever 6-12 months
- A variety of virtual team events such as game nights & happy hours

- Choice of medical, dental, and vision insurance plans for you and your family

- Flexible paid time off and 10+ holidays per year
- A stipend to upgrade your home office for fully-remote roles

- 401k for US-based employees

📌 Senior Security Engineer (Toronto)
🏢 EvenUp
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior security engineer (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: senior security engineer (toronto) / toronto