Senior Security Engineer at EvenUp
Canada, Ontario, Canada -
Full Time


Start Date

Immediate

Expiry Date

22 Nov, 26

Salary

0.0

Posted On

24 Aug, 26

Experience

0 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

Yes

Skills

Industry

Information Technology & Services

Description

Responsibilities

Build Our Detection Platform: Lead SIEM evaluation and implementation, design log ingestion and routing pipelines, and make deliberate cost/retention trade-offs across hot search and long-term archive

Engineer High-Signal Detections: Develop and tune detection content across cloud, identity, endpoint, SaaS, and application telemetry — with an emphasis on business-logic detections built on our own products' audit events

Define the Telemetry Contract: Partner with Engineering and DevOps to specify what our applications and infrastructure must log — the audit events that make our most important risks detectable in the first place

Lead Incident Response: Build and maintain IR playbooks and runbooks, coordinate response during security events, run the annual tabletop exercise, and drive post-incident reviews that actually change things

Detect Data Exposure: Partner with internal teams to detect sensitive data moving where it shouldn't — including PHI — across applications, endpoints, and SaaS

Manage 24/7 Coverage: Define requirements for and direct our managed detection partners, own escalation procedures, and continuously raise the bar on what "monitored" means

Qualification

checkRepresents the skills you have

Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.

Security OperationsDetection EngineeringIncident ResponseSecurity Information and Event Management (SIEM)PythonSQLCloud-Native TelemetrySecurity AutomationApplication InstrumentationManaged Detection and Response (MDR/MSSP)Required

5+ years in security operations, detection engineering, or incident response, including experience building (not just running) a detection and response capability at a startup or high-growth technology company

Hands-on experience implementing or significantly maturing a SIEM, including custom log sources and detection content — not just operating one that was handed to you

Strong detection engineering skills: writing detections in Python, SQL, or a rules DSL, managing them in version control, and measuring their quality

Real incident response experience — you've led investigations, written the playbooks, and run the retros

Experience with cloud-native telemetry (AWS/GCP/Azure control plane, identity providers, endpoint, SaaS audit logs)

Strong programming or automation skills (Python preferred); comfort building integrations and response automation

A builder mentality — you'd rather engineer the alert away than triage it forever

Preferred

Experience partnering directly with software engineers to instrument applications for security visibility is a strong plus

Familiarity with securing or monitoring AI/LLM-powered systems is a strong plus

Experience working with MDR/MSSP providers — and opinions about what they're good and bad at

Relevant security certifications (GIAC/GCIA/GCIH, CISSP, etc.) are a plus, but practical engineering experience matters more

Benefits

Choice of medical, dental, and vision insurance plans for you and your family.

Additional insurance coverage options for life, accident, or critical illness.

Flexible paid time off, sick leave, short-term and long-term disability.

10 US observed holidays, and Canadian statutory holidays by province.

A home office stipend.

401(k) for US-based employees and RRSP for Canada-based employees.

Paid parental leave.

A local in-person meet-up program.

Hubs in San Francisco and Toronto.

Hybrid work arrangement with an expectation of being in the Toronto office three days per week.

Responsibilities
Loading...