Senior Manager, JSOC & Threat Hunting (Toronto)

Senior Manager, JSOC & Threat Hunting (Toronto)

02 Sep
|
Questrade Financial Group
|
Toronto

02 Sep

Questrade Financial Group

Toronto

Questrade Financial Group (QFG), through its companies - Questrade, Questbank, Questrade Wealth Management, Community Trust Company, Zolo, and Flexiti, provides securities and foreign currency investment, professionally managed investment portfolios, mortgages, real estate services, financial services and more. We use cutting-edge technology to help Canadians become much more financially successful and secure.

At QFG, we combine human-centric collaboration with AI-driven innovation to redefine financial services. The ideal candidate will be a catalyst for change, using AI to transform and deliver unparalleled customer experiences and shaping a future where AI empowers our teams to do their best work.

Join our diverse, inclusive, and hybrid workplace to unleash your creativity and nurture your curiosity without limits. If you share this sense of infinite possibility, come shape your future at QFG.

What’s in it for you as an employee of QFG?

- Health & wellbeing resources and programs
- Paid vacation, personal, and sick days for work-life balance
- Competitive compensation and benefits packages
- Work-life balance in a hybrid environment with at least 3 days in office
- Career growth and development opportunities
- Opportunities to contribute to community causes
- Work with diverse team members in an inclusive and collaborative environment

This job posting is for an existing vacancy. We’re looking for our next Senior Manager, JSOC & Threat Hunting. Could It Be You?

The Senior Manager, JSOC & Threat Hunting is a hands-on technical leader accountable for security monitoring, incident response, threat hunting and intelligence, detection and security engineering, vulnerability management and DevSecOps across Questrade Financial Group's regulated entities. She/he leads the Joint Security Operations Centre (JSOC) as a 24x7, multi-shift operation spanning three teams (SOC and Incident Response, Threat Operations and Engineering, and DevSecOps), owns the JSOC service catalogue, and remains directly involved in major incidents, complex investigations, detection design, SIEM optimization and security tooling decisions. This is not a coordination-only leadership role.

The role operates in a dual regulatory environment covering CIRO regulated dealer and wealth entities and OSFI regulated federal financial institutions, and is the senior escalation point for cyber incident detection, containment and the incident inputs required for regulator reporting.

Need more details? Keep reading…

- JSOC leadership: Lead the Joint Security Operations Centre as a highly technical, hands-on leader across three teams: SOC and Incident Response, Threat Operations and Engineering, and DevSecOps. Remain directly involved in complex investigations, high-severity incidents, detection design, SIEM optimisation and security tooling decisions, and challenge technical assumptions rather than rely on tool-generated conclusions.
- Service catalogue: Own and maintain the JSOC service catalogue across three service lines (SOC/IR, Threat Operations, and DevSecOps), with defined service levels, a named owner and a named backup for every service line.
- 24x7 operations: Run alert monitoring and response as a continuous, multi-shift operation across five countries, ensuring coverage, shift handover discipline and consistent investigation quality across regions and time zones.
- Incident response: Own the incident management lifecycle end to end, including severity classification, escalation paths, playbooks, evidence handling and chain of custody, containment, remediation, recovery and lessons learned. Provide technical direction from triage through closure on major incidents and lead cross-functional coordination with engineering, infrastructure, cloud, identity, fraud, privacy, legal and business teams.
- Regulatory incident readiness: Ensure incident detection, classification and evidence are sufficient to meet OSFI technology and cyber security incident reporting expectations, including the 24-hour initial notification, and CIRO cybersecurity incident reporting obligations. Label every incident to the correct entity and regime and provide timely, accurate inputs to the Global Security Office, Legal, Privacy and Compliance.
- Detection engineering: Oversee the design, testing, tuning and lifecycle management of detection rules and alerts mapped to MITRE ATT&CK.; Improve SIEM effectiveness by reducing noise and false positives, optimising queries and ensuring alerts are actionable, and maintain a measured view of detection coverage and known gaps.
- Threat hunting: Develop and run a proactive threat hunting programme covering employee-facing and client-facing threats, informed by threat intelligence, attacker behaviours, environmental risk and observed detection gaps. Convert hunt findings into durable detections and control improvements.
- Cyber threat intelligence:



Own CTI tooling configuration, alert set-up, monitoring and response, and feed intelligence into detection, hunting, vulnerability prioritisation and fraud use cases.
- Vulnerability management and EASM: Own enterprise vulnerability management and external attack surface management, including EASM configuration and inventory, prioritisation by exploitability and entity exposure, and remediation tracking with named owners and committed dates in partnership with technology owners.
- SIEM and security engineering: Provide technical leadership for Elastic Security, including log source onboarding, parsing and configuration, data ingestion, query development, dashboards, detection rules, integrations and platform optimisation. Ensure logging and telemetry across applications, APIs, endpoints, identity systems, networks, cloud platforms and third-party services provide the visibility required to detect and investigate activity.
- Security solutions: Own deployment, administration and lifecycle management of JSOC security solutions, including Zscaler (ZIA, ZPA, ZDX) and email security, and evaluate and improve tools, integrations and workflows on measurable operational value.
- Security and fraud R&D;: Direct security and fraud research and development within the JSOC, including AI-assisted triage and automation, in line with enterprise AI governance requirements. Apply change control and independent review before any internally built tooling enters production, maintaining segregation between building a control and monitoring it.
- DevSecOps: Lead the DevSecOps team in SAST and DAST configuration, application vulnerability management and application security advisory, prioritised by regulated-entity exposure. Partner with engineering and platform teams to integrate security controls and testing into CI/CD pipelines, investigate application-layer threats and strengthen detection across the software development lifecycle.
- Integrity and fraud investigations: Support integrity investigations for Compliance, HR, Fraud and Legal under evidence-handling standards, and partner with Enterprise Fraud on account takeover, abuse and fraud-adjacent detection and response affecting online financial services.
- Metrics and reporting: Define and monitor operational metrics including detection coverage, alert quality, time to detect and respond, investigation outcomes, recurring incident patterns and control gaps, and prepare quarterly executive and Board committee reporting content for the Global Security Office.
- Exercises and post-incident review: Participate in and facilitate incident simulations, technical tabletop exercises and post-incident reviews, ensuring lessons result in concrete improvements to controls, detections and response procedures.
- Team leadership: Hire, coach, develop and manage the JSOC leadership layer and, through them, the wider team. Raise the team's technical depth, set clear expectations for investigation quality and operational ownership, and manage span of control, shift staffing and succession so that no service line depends on a single person.
- Collaboration and assurance: Partner with Cyber Strategy, Risk and GRC, Offensive Security, Identity and Access Management, Enterprise Fraud, Enterprise Architecture, Cloud and Infrastructure, Privacy, Legal, Internal Audit and entity compliance officers. Provide evidence for SOC 2, ISO 27001, NIST CSF and regulator reviews covering detection and response controls.
- Communication: Review complex technical findings and communicate business impact, evidence and recommended actions clearly to technical and non-technical stakeholders, including executive and Board committee audiences.
- Currency: Stay current with attacker techniques, application security risks, security operations practices, cloud-native security operations and technologies relevant to a Canadian regulated financial group.
- So are YOU our next Senior Manager, JSOC & Threat Hunting? You are if you…

- Have 10+ years of relevant cybersecurity experience, including substantial experience in security operations, incident response, detection engineering or threat hunting, with 5+ years leading technical security professionals and at least 2 years leading managers or team leads.
- Strong hands-on incident response experience, including investigation, scoping, containment, remediation, recovery and post-incident analysis, with major incident leadership in a regulated financial services workplace.




- Demonstrated experience running a 24x7 or follow-the-sun security operations function across multiple countries and shifts.
- Demonstrated experience conducting threat hunts and converting findings into durable detections or security improvements.
- Deep knowledge of SIEM operations, including alert development, query optimisation, data onboarding, false-positive reduction and detection coverage measurement.
- Strong practical experience with Elastic Security, Elasticsearch, Kibana, Elastic Query Language (EQL) and Kibana Query Language (KQL), or equivalent query and detection capabilities.
- Solid understanding of application security concepts, including common web and API attack techniques, secure development practices, vulnerability management and application-layer telemetry.
- Strong knowledge of endpoint, network, identity, cloud and application security data sources, and the ability to analyse logs, network activity, authentication events, endpoint telemetry and application behaviour without relying solely on tool-generated conclusions.
- Experience with MITRE ATT&CK; and the Cyber Kill Chain, and with developing security automation, scripts, integrations or repeatable investigation workflows.
- Strong written and verbal communication skills, with the ability to explain technical risk clearly, make sound decisions in high-pressure situations and present to executive and Board committee audiences.
- A leadership style grounded in technical credibility, accountability, collaboration and continuous improvement, with proven ability to build a leadership layer and manage span of control across a geographically distributed team.
- Experience in a regulated financial services environment such as banking, brokerage, wealth management, payments or fintech.

- CISSP, GCIH, GCIA, GCFA, GNFA, OSED, CPTS, Security+ or equivalent practical experience.

- Familiarity with OSFI B-13, B-10 and E-21, OSFI technology and cyber security incident reporting expectations and CIRO cybersecurity incident reporting obligations, or demonstrated ability to learn a new prudential regime quickly.
- Deep expertise with Zscaler products, including ZIA, ZPA, ZDX and related integrations and telemetry.
- Familiarity with CrowdStrike Falcon, Wiz, Aikido and cloud-native security operations in Google Cloud Platform or another major cloud provider.
- Experience integrating security controls and testing into CI/CD pipelines, and familiarity with SOAR platforms and AI-assisted triage and automation workflows.
- Experience investigating fraud, account takeover, abuse or other threats affecting online financial services.
- Experience with scripting or development in Python, JavaScript, Bash or another relevant language.

Work Arrangement

- Leads a globally distributed team operating a follow-the-sun model across Canada, Brazil, Armenia, Israel and Argentina, with shift-based SOC coverage (Shifts A, B and C) and flexible Eastern Time coverage.
- Working day anchored to the Toronto Eastern Time business day for executive, entity, auditor and regulator-facing engagement.
- Available for major incident escalation outside business hours, with a named deputy arrangement in place for planned absence so that incident command never depends on a single person.
- Working language is English, written and spoken, at a standard suitable for regulator-facing incident reporting and Board committee reporting.

Compensation Information:

- Base salary range: $170,000 - $185,000
- The final compensation package will be commensurate with the successful candidate's experience, skills, and geographic location (Canada). It includes a comprehensive benefits plan and a competitive incentive (bonus) program for Full-Time Permanent roles.

Sounds like you? Click below to apply! At Questrade Financial Group of Companies, with multiple office locations around the world, we are committed to fostering a diverse, inclusive and accessible work environment. This is an environment where individuals are treated with dignity and respect. Here, the unique skills and experience you bring will be valued.

You will be supported and motivated, so that you can harness your unlimited potential. Our team reflects the diversity of the communities we serve and operate in. Having a collaborative and diverse team helps us push boundaries to bring the future of fintech into existence—not only for the benefit of our customers, but for those who build their career with us.

Questrade Financial Group of companies Applicant Tracking System utilizes artificial intelligence (AI) for application screening. The AI system operates on predetermined criteria, with final decisions subject to human review.

Candidates selected for an interview will be contacted directly. If you require accommodation during the recruitment/selection process, please let us know and we will work with you to meet your needs.

📌 Senior Manager, JSOC & Threat Hunting (Toronto)
🏢 Questrade Financial Group
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior manager, jsoc & threat hunting (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: senior manager, jsoc & threat hunting (toronto) / toronto