Clio is the global leader in legal AI technology, empowering legal professionals and law firms of every size to work smarter, faster, and more securely. We are transforming the legal experience for all by bettering the lives of legal professionals while increasing access to justice. Security systems and practices are already in place, this role will be responsible for adopting and unifying the systems, communication, and oversight of security systems from across IT Systems, Application Security, and Compliance.
If you are local to one of our hubs (Burnaby, Calgary, or Toronto) you will be expected to be in office minimum twice per week on one of our Anchor Days. Your team will work closely with the IT Systems, Application Security, People, Compliance, and IT Services teams to ensure appropriate security coverage in detection, response, and establishing non-adversarial techniques. This role is established for the purpose of driving the cybersecurity definitions and posture across our fleet and systems — leading investigations, owning incident response end-to-end, and improving the operational quality of how we detect and respond to threats.
As Senior
CorpSec Analyst, you are both a senior operator and a project lead. You own detection and response work end-to-end, lead high-severity incidents, and raise the quality and velocity of how the team operates. you will help define how we use it in detection and response responsibly. Build & Run — Technical & Operational The role has senior technical expectations, including raising the operational bar of the team.
Lead investigations and incident response for medium- and high-severity security events — phishing campaigns, insider risk, compromised accounts, data-loss concerns — owning the response from triage through resolution and post-incident review. Own detection engineering across the corporate security stack — tune DLP, EDR, phishing templates, remediations, and SSO/IdP signals; Drive root-cause analysis after incidents and near-misses,
then translate findings into durable runbook, control, and tooling changes. Build and maintain automations and integrations that move work left — auto-remediation playbooks, signal enrichment, evidence collection pipelines.
Define, document, and evolve internal incident response playbooks for insider threat, compromised device, and data-loss scenarios. Tune and evolve security tooling for AI detection — address risks of unauthorized data movement, agentic workflows, and the lethal trifecta. Drive correlation and visibility capability across Clio's security stack so detection and investigation stay timely as the company continues to grow.
Drive cross-team initiatives that no single team owns — DLP policy refinement, MDM coverage, audit log centralization, AI tooling guardrails. Support security compliance requirements for SOC 2, ISO 27001, GovRAMP, and PCI-DSS — own and design technical evidence pipelines, not just one-off collection. 5–8 years of hands-on experience in security operations, detection engineering, or incident response. ~ Deep hands-on experience with at least three of: EDR, DLP, Phishing platforms, SIEM, or Google Workspace security controls — you've configured, tuned, and operated them in production. ~ Demonstrated experience leading security incidents end-to-end — you've been the incident commander, not just a contributor. ~ Track record of root-cause investigation — you fix the problem, not the symptom, and translate the fix into a durable control or automation. ~ Comfort with ambiguity — you can take an open-ended problem ("our DLP signal-to-noise is bad") and produce a concrete, prioritized plan.
~ Growth mindset when it comes to process improvement and new technologies, especially AI.
Experience designing or operating SIEM or detection-as-code pipelines.
Experience contributing to security compliance programs including SOC 2, ISO 27001, GovRAMP, or FedRAMP. Scripting fluency (Python, Bash, PowerShell) for automating investigation, evidence collection, and remediation. Industry certifications such as CISSP, CISM, GCIH, GCIA, or CompTIA Security+.
Comfortable jumping onto due-diligence calls if Compliance requires assistance with customer Risk Interviews. You're a force multiplier — when you're on a project, the whole team gets better. You document decisions for the engineer who comes after you — your runbooks outlive the on-call rotation that wrote them.
You're principled about the visibility-trust tension — you treat security communication as a trust-building exercise. LI-Remote We have developed a series of programs and processes to ensure we are creating fair and competitive pay practices that form the foundation of our human and high-performing culture. Competitive, equitable salary with top-tier health benefits, dental, and vision insurance ~ Hybrid work environment, with expectation for local Clions (Vancouver, Calgary, Toronto, Dublin, London, Recent York City and Sydney) to be in office min.
Flexible time off policy, with an encouraged 20 days off per year. ~$The expected salary range for this role is $106,300 to $143,800 CAD. Diversity, Inclusion, Belonging and Equity (DIBE) & Accessibility We are dedicated to diversity, equity and inclusion. We pride ourselves in building and fostering an environment where our teams feel included, valued, and enabled to do the best work of their careers, wherever they choose to log in from.
We're a Human and High Performing AI company, meaning we use artificial intelligence to improve all of our operations. In recruitment, AI helps us streamline the process for greater efficiency.
📌 Senior Corporate Security Analyst (Toronto)
🏢 Clio
📍 Toronto