Jobs in Canada

Security Incident Response Engineer in Canada

253 active opportunities · Updated October 2026

Explore current security incident response engineer jobs across Canada. Filter by work mode, employment type, experience, department, date posted and distance.

C
📍 Toronto, Ontario, Canada· Full-time
✓ Quality checkedCompany trend -91.5%

Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! Security Clearance: Active Secret+ clearance strongly preferred; candidates eligible and willing to obtain clearance will also be considered. More information about Canadian Security Clearance is available here . As an Infrastructure Security Engineer, your key responsibilities include: Deploy, and manage infrastructure for Protected B classified environments, ensuring compliance with ITSG-33 and Canadian government standards Design and implement security controls for cloud (AWS, GCP, Azure) and hybrid/multi-cloud deployments Evaluate, implement, and manage security tools and technologies for training cluster and inference infrastructure hardening Implement security best practices including IAM, encryption, logging, and monitoring Participate in security incident response activities, including detection, analysis, containment, and remediation Conduct regular vulnerability assessments and penetration testing of infrastructure components Maintain comprehensive security documentation, procedures, and configurations for classified environments Maintain active Secret+ security clearance and adhere to all Canadian government security

AWSAzureGCPKubernetes
R
📍 Bellevue, WA; Menlo Park, CA· Full-time
✓ Quality checkedCompany trend -76.2%

Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you’re ready to be at the epicenter of this historic cultural and financial shift, keep reading. About the team + role We are building an elite team, applying frontier technologies to the world’s biggest financial problems. We’re looking for bold thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn’t a place for complacency, it’s where ambitious people do the best work of their careers. We’re a high-performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards. About the Team The Security Operations (SecOps) team at Robinhood proactively safeguards our platform and millions of customers. We monitor, detect, and respond to security threats in real time while staying ahead of risks through threat intelligence, Red Team operations, and research partnerships. We are building the next generation of security operations—leveraging AI-driven automation, Autonomic Security Operations (ASO), and innovative detection frameworks to set the standard across the cybersecurity industry! About the Role As a Staff Security Engineer (IC6) on the Detection & Response team, you will drive our incident response strategy, build robust detection engineering frameworks, and mentor engineers across the organization. In this high-impact role, you will command high-stress incident responses, eliminate operational noise by developing an AI-native detection platform, and help shape the broader AI-agentic ecosystem for SecOps. You will work closely with cross-functional partners in Proactive Security, Security Engineering, Insider Trust, Infrastructure, Legal, and Communications to protect Robinhood’s ecosystem. This role is based in our Bellevue, WA a

VueAWSKubernetesAI
S
📍 Toronto, Ontario, Canada· Full-time· Remote
✓ High-confidence listingCompany trend -100%

C$162K – C$420K/yr

Quick readStrong listing-quality and freshness signals

About Sentry Software runs the world and the pace is faster than ever. Sentry helps developers fix errors and performance issues before users notice, so teams can spend less time firefighting and more time building. Trusted by 200,000+ organizations, Sentry is today’s application monitoring standard and our team is building its AI-native future. About The Role The Security Team is responsible for securing all things Sentry: our customers, our code, and everything in between. We are a small but growing team with broad scope, high trust, and the autonomy to tackle hard security problems with creativity and an engineering mindset. We work at a company with a strong developer culture, building a product that millions of developers genuinely love and rely on. That context shapes everything about how we operate. We take a pragmatic approach to preventing and responding to security risks. In this role not only will you build and contribute to systems which detect malicious activity, you will have the unique opportunity to implement new controls to prevent future incidents. You will work across detection and response and corporate security domains. You'll contribute to practices that keep Sentry secure as we grow: alert triage for corporate and production, detection engineering, deploying preventative controls, identity and access management, investigations and incident response, and more. You'll partner with teams across the company to prevent and respond to security incidents. You will work as a technical collaborator who prioritizes preventative controls, defense in depth, and high signal alerting practices. As Sentry expands our agentic product capabilities and development practices, you'll also find yourself at the frontier of a new set of security approaches and challenges. In this role, you will Maintain, improve, and own detection engineering systems. We own and operate our own detection stack and are building agentic triage with thoughtful security response and orc

PythonReactAWSAzure
R
📍 Denver, CO; Menlo Park, CA· Full-time
✓ Quality checkedCompany trend -76.2%

Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you’re ready to be at the epicenter of this historic cultural and financial shift, keep reading. About the team + role We are building an elite team, applying frontier technologies to the world’s biggest financial problems. We’re looking for bold thinkers. Sharp problem-solvers. Builders who are wired to make an impact. Robinhood isn’t a place for complacency, it’s where ambitious people do the best work of their careers. We’re a high-performing, fast-moving team with ethics at the center of everything we do. Expectations are high, and so are the rewards. The Security Operations (SecOps) team protects Robinhood and its customers by detecting, investigating, and responding to security threats across our production systems, endpoints, and cloud environments. We combine detection engineering, incident response, and threat intelligence to identify emerging risks, strengthen our defenses, and reduce the impact of attacks before they reach our customers. As we continue to evolve our security platform, we're embracing AI and automation to help our teams move faster, uncover threats more effectively, and scale our defenses against increasingly sophisticated adversaries. As the Manager of Response, Automation, Intelligence and Detection Engineering (RAID) within SecOps, you will lead teams across North America, shaping the strategy, execution, and long term evolution of our defensive security capabilities. You'll be responsible for building high performing teams, maturing our detection and incident response programs, and ensuring we stay ahead of an increasingly sophisticated threat landscape. Working closely with Security, Engineering, Infrastructure, and Trust & Safety, you'll translate emerging threats into scalable defenses wh

VueAWSAIGo
F
📍 Toronto, Canada· Full-time
✓ High-confidence listing
Quick readStrong listing-quality and freshness signals

About Forma.ai: Forma.ai is a Series B startup that's revolutionizing how sales compensation is designed, managed and optimized. We handle billions in annual managed commissions for market leaders like Edmentum, Stryker, and Autodesk. Our growth has been fuelled by our passion for fundamentally changing and shaping how companies use sales intelligence to drive business strategy. We’re welcoming equally driven individuals who are excited about creating something big! The Opportunity As a Staff Security Engineer, you will be a hands-on technical leader strengthening security across Forma's application, cloud infrastructure, development lifecycle, internal systems, and incident-response practices. Security today is shared across Engineering and DevOps. You'll work closely with both teams and have real room to shape how Forma approaches security as we grow. Depending on your interests and the needs of the business, the role could develop into a deeper individual-contributor position or help build a dedicated security team. You'll work directly with Engineering, DevOps, IT, Product, Legal, and Privacy to identify risks, design practical controls, automate security processes, and help teams ship secure and reliable software. What you'll do Cloud and infrastructure security Design and implement security controls across Forma's AWS environments, with a focus on IAM, least-privilege access, service identities, and account boundaries. Embed security requirements into Terraform and other Infrastructure as Code, and improve secrets, certificate, encryption-key, and credential management. Build automated checks for insecure configurations, excessive permissions, exposed resources, and configuration drift across Kubernetes, containers, serverless workloads, networking, and data services. Application, data, and AI security Run threat modelling and security architecture reviews for new products, services, APIs, data pipelines, and third-party integrations

PythonAWSKubernetesCI/CD
C
📍 Canada· Full-time· Remote
✓ High-confidence listing

From C$154K/yr

Quick readStrong listing-quality and freshness signals

Ready to do the most impactful work of your career? At Coinbase , we are uncompromising on our mission to increase economic freedom. The bar is high, the environment is intense, and we like it that way. This isn't a place for complacency, it’s a place to be pushed past your perceived limits. If you're ready to build the future of finance alongside people who refuse to settle for "good enough," you belong here. Coinbase is a remote-first, but not remote-only company. Expect to get together quarterly for intense in-person working sessions called “surges.” learn more about working at Coinbase . As an Offensive Security Engineer on the Application Security team within Security, you'll pioneer how Coinbase uses frontier AI models to scale vulnerability discovery, red team AI systems, and automate security workflows. This role bridges traditional penetration testing with next-generation AI-augmented offensive security, directly accelerating our ability to protect products and customers. You'll own the development of AI-driven security tooling and collaborate across Vulnerability Management, Offensive Security, and Incident Response to fundamentally shift how we operate. What you'll do: Build, deploy, and maintain custom security scanners that leverage frontier models to detect vulnerabilities at scale across Coinbase's product surface. Lead red teaming efforts against internal AI systems, including jailbreak testing, prompt injection analysis, and tool abuse simulation. Develop AI-driven automation for vulnerability triage, validation, and remediation workflows to accelerate the bug bounty and vulnerability response pipelines. Partner with engineering teams to prioritize, remediate, and verify fixes for critical vulnerabilities discovered through AI-augmented and manual testing. Mentor junior security engineers on integrating AI into offensive security workflows to scale team capabilities. Required Skills and Experience: 3+ years of experience in application s

PythonAWSAIGo
C
📍 Toronto, Ontario, Canada· Full-time
✓ Quality checkedCompany trend -91.5%

Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! As a Senior Security Engineer you will: Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues Lead security operation functions – including vulnerability management, SAST, DAST, detection engineering, and incident response – in CI/CD and cloud-native production environments Integrate security into our applications throughout the software development lifecycle Collaborate with product and development teams, driving the success of larger projects to ensure that software is built and deployed securely without compromising agility and speed Driving and supporting bug bounty program, application security reviews and threat modeling, including code review and dynamic testing Assess and integrate security tools to automate and scale security processes, i.e: evaluate open-source vs vendor solutions Gather and analyze security metrics to address security issues with cross-team dependencies Be a problem solver who is empathetic to developer concerns and will employ constructive and flexible approach to building innovative solutions You may be a good fit if: 5

CI/CDGitRestAI
T
📍 San Francisco, Canada
✓ High-confidence listingCompany trend -94.4%
Quick readStrong listing-quality and freshness signals

About Us Twitch is the world’s biggest live streaming service, with global communities built around gaming, entertainment, music, sports, cooking, and more. It is where thousands of communities come together for whatever, every day. We’re about community, inside and out. You’ll find coworkers who are eager to team up, collaborate, and smash (or elegantly solve) problems together. We’re on a quest to empower live communities, so if this sounds good to you, see what we’re up to on LinkedIn and X , and discover the projects we’re solving on our Blog . Be sure to explore our Interviewing Guide to learn how to ace our interview process. About the Role Twitch Security Platform builds and operates the technology at the intersection of security, privacy, software engineering, and data engineering. As a Senior Engineering Manager, Security Platform, you will guide a diverse group of software engineers to build critical tools and automation solutions used across Twitch. You will report to the Director of Security, Identity, and Privacy Platforms. You will manage engineers responsible for operating our security data platform handling billions of weekly events, a multi-petabyte data lake, and numerous analysis tools that provide critical data across the organization to support important security programs. You will also lead engineers responsible for writing software to accomplish security at scale through automation, libraries, and services. With this team, you will lead the full software development lifecycle from product discovery, roadmap prioritization, and execution. Programs you support will include Fraud, Service-to-Service Auth, Detection and Incident Response, Vulnerability Management, Engineering Intelligence, and Privacy. You are experienced in software and data engineering, you bring awareness of the industry's cutting edge, and you're passionate about security. If this sounds accurate, come join us! You can work from San Francisc

G
📍 British Columbia, Canada· Full-time
✓ High-confidence listingCompany trend -100%

From C$107K/yr

Quick readStrong listing-quality and freshness signals

Location Details: At GoDaddy the future of work looks different for each team. Some teams work in the office full-time; others have a hybrid arrangement (they work remotely some days and in the office some days) and some work entirely remotely.​ Remote: This is a remote position, so you’ll be working remotely from your home. You may occasionally visit a GoDaddy office to meet with your team for events or meetings. About the Team Global Compute builds and operates the core cloud infrastructure that engineering teams rely on every day. We provision and manage AWS accounts across the company, operate the network backbone that connects them, and maintain the security guardrails that keep those environments safe, compliant, and scalable. We believe reliability is an engineering challenge, not an operations task. We automate repetitive work, build for scale before it becomes a problem, and invest heavily in observability to identify issues before they impact the business. What you'll get to do... Operate and scale AWS production infrastructure, owning the health of services that provision, secure, and manage accounts across GoDaddy AWS organisations. Design, build, and maintain cloud platform capabilities using Python, CloudFormation, AWS CDK, and automation-first practices. Drive cost optimisation initiatives that improve efficiency and deliver measurable business impact. Improve observability through monitoring, alerting, dashboards, and operational tooling. Participate in on-call rotations, lead incident response efforts, and drive long-term reliability improvements through blameless post-incident reviews. Support strategic AWS initiatives across networking, identity, governance, and multi-account architecture. Review code and designs, contribute documentation and operational runbooks, and mentor fellow engineers. Leverage AI-assisted tooling to improve engineering productivity, accelerate automation, and reduce operati

PythonAWSCI/CDGit
O
📍 Washington, Ontario, Canada· Full-time
✓ High-confidence listingCompany trend -63.6%

From $200K/yr

Quick readStrong listing-quality and freshness signals

Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. About Okta for AI Agents Okta secures access for 20,000 organizations and billions of users. Okta for AI Agents extends that work to the agentic shift. Deploying an AI agent is not like deploying traditional software. You are putting professional work output into production, and it needs deep integration, continuous tuning, and change management. Every agent needs an identity, a scope, an audit trail, and a way to be shut down when it goes wrong. Most enterprises have not built this yet. We are. We hire builders who see the cracks in enterprise agent identity that everyone else has learned to live with. The Role You embed inside four to five of Okta’s most strategic enterprise customers as their dedicated technical partner for agent identity. You sit alongside their identity, platform, and security engineering teams, write production code in their environment, and own the technical outcome from prototype through production. You are a builder-consultant. You go past architecture diagrams to code, debug, and ship bespoke agent identity solutions inside the customer’s environment. You ship secure agents faster for the customer, and you feed real field insight back to Okta product engineering. Responsibilities Become the customer’s trusted technical voice on agent security. Sit in their standups, design reviews, and incident response. Earn a seat on their architecture review board and security council for agent risk decisions. Architect and deploy with the cust

AWSGitRestMachine Learning
HI
📍 San Francisco, Canada
✓ High-confidence listing

$149.9K – $270K/yr

Quick readStrong listing-quality and freshness signals

Who We Are HP IQ is HP’s new AI innovation lab. Combining startup agility with HP’s global scale, we’re building intelligent technologies that redefine how the world works, creates, and collaborates. We’re assembling a diverse, world-class team—engineers, designers, researchers, and product minds—focused on creating an intelligent ecosystem across HP’s portfolio. Together, we’re developing intuitive, adaptive solutions that spark creativity, boost productivity, and make collaboration seamless. We create breakthrough solutions that make complex tasks feel effortless, teamwork more natural, and ideas more impactful—always with a human-centric mindset. By embedding AI advancements into every HP product and service, we’re expanding what’s possible for individuals, organisations, and the future of work. Join us as we reinvent work, so people everywhere can do their best work. About The Role As a Senior Platform Engineer at HP IQ, you will help build and evolve the infrastructure, tooling, and shared platform capabilities that enable our engineering teams to develop and operate reliable, secure, and scalable services across cloud and edge environments . You will work closely with application, services, AI/ML, and security teams to improve developer velocity, production readiness, reliability, and operational efficiency across a heterogeneous infrastructure footprint. What You Might Do Design, build, and maintain shared infrastructure and platform capabilities across cloud and edge environments. Build automation and self-service tooling that improves engineering velocity and operational consistency. Develop and maintain Infrastructure-as-Code, deployment workflows, and environment provisioning. Partner with engineering teams on production readiness, including reliability, security, observability, scalability, and recovery. Improve monitoring, alerting, incident response, and operational tooling across distributed environments. Automate repetitive operational t

PythonKubernetesAI
TI
📍 San Francisco, Canada· Full-time
✓ High-confidence listing

$136.3K – $273.9K/yr

Quick readStrong listing-quality and freshness signals

TextNow is on a mission to make communications affordable and accessible for everyone. As a full MVNO operating our own mobile core network over LTE and 5G NSA, we have the unique advantage of controlling our network infrastructure end-to-end. We operate the HSS, PGW, and other critical network functions, giving us the flexibility to innovate and deliver exceptional service to millions of users. About the Role Join us in our mission to break down barriers to communication and free the flow of conversation for people everywhere. T extNow is looking for a new SecOps team member to secure, monitor , and enable automated response within our infrastructure. What You’ll Do Ensure Secure & Reliable Systems: Design, implement, and maintain security-focused infrastructure to protect TextNow’s services while ensuring reliability and scalability. Security Automation & Infrastructure as Code: Develop and enforce best practices using Terraform, Ansible, Crowdstrike , and AWS security tools , ensuring secure configurations, automated compliance checks, and infrastructure as code. Threat Detection & Incident Response: Participate in an on-call rotation to respond to security incidents, investigate vulnerabilities, and implement proactive measures to prevent future threats. Work closely with engineering teams to remediate security risks. Monitoring & Logging for Security: Improve observability by implementing security monitoring solutions, logging best practices, and alerting mechanisms to detect anomalies and suspicious activity. Access Control & Identity Management: Manage IAM roles, permissions, and policies to ensure least privilege access and enforce security controls across cloud and internal systems. Collaboration & Security Advocacy: Wo

AWSCI/CDGitAI
DU
📍 San Francisco, Canada· Full-time
✓ High-confidence listing

From $962.4K/yr

Quick readStrong listing-quality and freshness signals

About the Team The Global Safety and Security team advances DoorDash by protecting people, property, operations, brand, and reputation. Within that team, Protective Services safeguards executives and residences through executive protection, intelligence collection, threat monitoring, residential security, and secure transportation. We manage risk and deliver value through technology and a people-first approach, and we strive to always be ahead of the curve and there for our people, anytime, anywhere. About the Role We are hiring Protective Services Associates to join the Protective Services team, providing residential security coverage and on-site protective presence in support of executives. This is the entry point on our cross-trained career ladder. Associates build proficiency across residential security, monitoring and threat reporting, and close-protection fundamentals, with a structured path to Senior Associate and beyond as you grow. Responsibilities Residential Security Coverage: Provide dedicated, round-the-clock physical security presence at a residential property as part of a rotating shift team. Monitoring & Threat Reporting: Monitor camera systems and access points, document and report security-relevant activity, and hand off findings to the team's intelligence function. Access Control: Screen and coordinate visitors, deliveries, and vendors according to established protocols. Logistics Coordination: Plan and manage the logistics of residential security operations, including scheduling, shift handoffs, and coverage during events or executive travel. Coordinate with drivers and other Protective Services team members to align movements, timing, and coverage. Incident Response: Respond to security incidents or anomalies, following established escalation procedures. Professional Conduct: Serve as a trusted, hands-on point of contact for executives, anticipating needs, exercising sound judgment in real time, and delivering discreet, concierge-level servi

AWSGitRestAI
DU
📍 San Francisco, Canada· Full-time
✓ High-confidence listing

From $1.1M/yr

Quick readStrong listing-quality and freshness signals

About the Team DoorDash's Protective Services function safeguards executives, their families, and residences through executive protection, residential security, threat management, and secure transportation across a three-brand global enterprise. The team operates 24/7 and is built on the principle that protection starts before an incident, not after. The people who do this work well combine operational discipline with personal composure, take ownership of outcomes rather than tasks, and represent the program in every interaction with the principal population. About the Role The Protective Services Agent provides close protection for DoorDash executives and their families across all operating environments, including corporate headquarters, domestic and international travel, company events, and residential settings. The role requires a trained executive protection professional who develops and implements security plans, conducts advances and risk assessments, coordinates with law enforcement and venue partners, and serves as the principal's primary security presence. Personnel must be capable of managing incidents and serving as first responders on scene. Operations regularly involve extended duty periods, irregular schedules, and short-notice deployments. Potential travel up to 25% of the time. You are excited about this opportunity because you will… Provide close protection across all principal environments. Serve as the primary security presence for executives and their families across headquarters, travel, events, and residential operations. Maintain continuous situational awareness, assess threats in real time, and execute protective protocols effectively and unobtrusively. Plan and execute security operations. Develop and implement comprehensive security plans for executive movements and events, incorporating site surveys, route planning, risk assessments, staffing requirements, screening procedures, and emergency response strategies. Conduct advances for all pr

AWSGitRestAI
C
📍 Toronto, Ontario, Canada· Full-time
✓ Quality checkedCompany trend -91.5%

Who are we? Cohere is the leading security-first enterprise AI company. We build cutting-edge foundation AI models and end-to-end products that are designed to solve real-world business problems. We’re training and deploying frontier models for enterprises who are building AI systems. We believe that our work is instrumental to the widespread adoption of AI and we are looking for folks that want to be part of that. We obsess over what we build. Each one of us is responsible for contributing to increasing the capabilities of our models and the value they drive for our customers. Cohere is a team of researchers, engineers, designers, and more, who are all passionate about their craft. We are a global technology company headquartered in Toronto with key offices in London, New York City, San Francisco, Montreal, Paris, Berlin and Seoul. Join us! As a Senior Security Operations Engineer you will: Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues Harden our cloud-native environments (AWS, OCI, GCP) by introducing secure by default designs and features into network, tooling, and processes Own and drive resolutions for enabling engineers to design, build, and use infrastructure securely at scale by deploying secure architectures using infrastructure-as-code and reusable code libraries Manage IAM / RBAC for cloud infrastructure, and partner with IT on streamling authentication/authorization to ensure unified access control across the board Deploy and operationalize some of the security services and tools (eg: SIEM, SOAR, domain monitoring, endpoint tooling, cloud security tooling) Respond to security incidents and harden environments post-incidents. Support control monitoring and remediation for compliance initiatives Gather and analyze security metrics to address security issues with cross-team dependencies Be a problem solver who is empathetic to developer concerns and will employ construc

PythonAWSAzureGCP
🔔

Get new security incident response engineer jobs in Canada by email

Daily job updates · Unsubscribe anytime