Senior Manager, Jsoc & Threat Hunting (Toronto)

Senior Manager, Jsoc & Threat Hunting (Toronto)

13 Sep
|
Questrade Financial Group
|
Toronto

13 Sep

Questrade Financial Group

Toronto

What’s in it for you as an employee of QFG? Health & wellbeing resources and programs Paid vacation, personal, and sick days for work-life balance Competitive compensation and benefits packages Work-life balance in a hybrid environment with at least 3 days in office Career growth and development opportunities Opportunities to contribute to community causes Work with diverse team members in an inclusive and team-oriented environment We’re looking for our next Senior Manager, JSOC & Threat Hunting. Could It Be You? The Senior Manager, JSOC & Threat Hunting is a hands-on technical leader accountable for security monitoring, incident response, threat hunting and intelligence, detection and security engineering, vulnerability management and DevSecOps across Questrade Financial Group's regulated entities. She/he leads the Joint Security Operations Centre (JSOC) as a 24x7, multi-shift operation spanning three teams (SOC and Incident Response, Threat Operations and Engineering, and DevSecOps), owns the JSOC service catalogue, and remains directly involved in major incidents, complex investigations, detection design, SIEM optimization and security tooling decisions. This is not a coordination-only leadership role. The role operates in a dual regulatory environment covering CIRO regulated dealer and wealth entities and OSFI regulated federal financial institutions, and is the senior escalation point for cyber incident detection, containment and the incident inputs required for regulator reporting. Need more details? Keep reading… JSOC leadership: Lead the Joint Security Operations Centre as a highly technical, hands-on leader across three teams: SOC and Incident Response, Threat Operations and Engineering, and DevSecOps. Remain directly involved in complex investigations, high-severity incidents, detection design, SIEM optimisation and security tooling decisions, and challenge technical assumptions rather than rely on tool-generated conclusions. Service catalogue: Own and maintain the JSOC service catalogue across three service lines (SOC/IR, Threat Operations, and DevSecOps), with defined service levels, a named owner and a named backup for every service line.



24x7 operations: Run alert monitoring and response as a continuous, multi-shift operation across five countries, ensuring coverage, shift handover discipline and consistent investigation quality across regions and time zones. Incident response: Own the incident management lifecycle end to end, including severity classification, escalation paths, playbooks, evidence handling and chain of custody, containment, remediation, recovery and lessons learned. Provide technical direction from triage through closure on major incidents and lead cross-functional coordination with engineering, infrastructure, cloud, identity, fraud, privacy, legal and business teams. Regulatory incident readiness: Ensure incident detection, classification and evidence are sufficient to meet OSFI technology and cyber security incident reporting expectations, including the 24-hour initial notification, and CIRO cybersecurity incident reporting obligations. Label every incident to the correct entity and regime and provide timely, accurate inputs to the Global Security Office, Legal, Privacy and Compliance. Detection engineering: Oversee the design, testing, tuning and lifecycle management of detection rules and alerts mapped to MITRE ATT&CK. Improve SIEM effectiveness by reducing noise and false positives, optimising queries and ensuring alerts are actionable, and maintain a measured view of detection coverage and known gaps. Threat hunting: Develop and run a proactive threat hunting programme covering employee-facing and client-facing threats, informed by threat intelligence, attacker behaviours, environmental risk and observed detection gaps. Convert hunt findings into durable detections and control improvements. Cyber threat intelligence: Own CTI tooling configuration, alert set-up,



monitoring and response, and feed intelligence into detection, hunting, vulnerability prioritisation and fraud use cases. Vulnerability management and EASM: Own enterprise vulnerability management and external attack surface management, including EASM configuration and inventory, prioritisation by exploitability and entity exposure, and remediation tracking with named owners and committed dates in partnership with technology owners. SIEM and security engineering: Provide technical leadership for Elastic Security, including log source onboarding, parsing and configuration, data ingestion, query development, dashboards, detection rules, integrations and platform optimisation. Ensure logging and telemetry across applications, APIs, endpoints, identity systems, networks, cloud platforms and third‑party services provide the visibility required to detect and investigate activity. Security solutions: Own deployment, administration and lifecycle management of JSOC security solutions, including Zscaler (ZIA, ZPA, ZDX) and email security, and evaluate and improve tools, integrations and workflows on measurable operational value. Security and fraud R&D: Direct security and fraud research and development within the JSOC, including AI‑assisted triage and automation, in line with enterprise AI governance requirements. Apply change control and independent review before any internally built tooling enters production, maintaining segregation between building a control and monitoring it. DevSecOps: Lead the DevSecOps team in SAST and DAST configuration, application vulnerability management and application security advisory, prioritised by regulated‑entity exposure. Partner with engineering and platform teams to integrate security controls and testing into CI/CD pipelines, investigate application‑layer threats and strengthen detection across the software development lifecycle. Integrity and fraud investigations: Support integrity investigations for Compliance, HR, Fraud and Legal under evidence‑handling standards, and partner with Enterprise Fraud on

📌 Senior Manager, Jsoc & Threat Hunting (Toronto)
🏢 Questrade Financial Group
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior manager, jsoc & threat hunting (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: senior manager, jsoc & threat hunting (toronto) / toronto