Sr Specialist, Adversary Detection,Cyber Threat Intelligence & Threat Hunting
Offre en anglaisThe role focuses on developing advanced detection content and executing hypothesis-driven threat hunting campaigns to identify adversarial activity. It involves operationalizing threat intelligence to strengthen cyber resilience across corporate IT, cloud, and operational technology environments.
- Sur place
- Toronto, ON
- Publié 13 août 2026
- Postuler avant le 12 sept. 2026
- 1 poste
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
Forgeahead Solutions Corporation
Technical Lead and Senior Software Engineer
- Sur place
The Hilary and Galen Weston Foundation
Program Manager, Neuroscience
- Sur place
Government of Ontario
Chef des services de soins de santé
- Sur place
Résumé du poste
Ready to build a rewarding career in an industry that is growing? Who We Are We are a global mining company dedicated to safely delivering nickel, copper, cobalt, and platinum group metals essential for the world’s energy transition. Our mission is to improve lives and shape a better future together. From utensils to cellphones to satellites, our operations simplify daily life and enhance connectivity. Our metals are integral to life-saving medical equipment and the electric vehicles driving the fight against climate change – our work truly matters. Join our diverse team of 15,000 talented individuals committed to transforming critical minerals into prosperity and sustainable development in countries like Canada, Brazil, Indonesia, the United Kingdom, and Japan. We invite you to use your skills with us and contribute to something meaningful and enduring. The Opportunity We are currently seeking a Sr. Specialist, Adversary Detection, Cyber Threat Intelligence & Threat Hunting Lead to join our Cyber Defense & Incident Response team in Toronto, Ontario. Combining expertise in Adversary Detection, Cyber Threat Intelligence, and Threat Hunting, you will transform intelligence into proactive security controls and advanced detection capabilities. Working across corporate IT, cloud environments, identities, endpoints, applications, and operational technology environments, will help strengthen cyber resilience across our global operations. Reporting to the Senior Manager, Cyber Defense & Incident Response, this role serves as the technical cornerstone of our Cyber Defense program. You will be responsible for ensuring our organization can identify, detect, and respond to adversarial activity before it impacts business operations. Key Responsibilities Adversary Detection Develop, test, and deploy advanced detection content mapped to MITRE ATT&CK techniques relevant to mining and critical infrastructure threats. Continuously tune and optimize detection logic to improve effectiveness and reduce false positives. Build and maintain a comprehensive detection catalog, including ATT&CK mappings, data sources, confidence levels, and review cycles. Collaborate with Security Operations teams to design and improve investigation playbooks and response procedures. Review managed detection and response (MDR) provider outputs, identify coverage gaps, and drive improvements in detection quality and performance. Establish and maintain detection engineering standards, documentation, testing methodologies, and operational processes. Cyber Threat Intelligence Consume, analyze, and operationalize threat intelligence from industry, government, commercial, and open-source sources. Produce regular threat intelligence reporting highlighting emerging threats, adversary activity, exploited vulnerabilities, and recommended defensive actions. Maintain detailed adversary profiles focused on actors targeting mining, critical infrastructure, energy, and global industrial organizations. Translate intelligence findings into actionable detections, threat hunts, risk advisories, and executive briefings. Manage and optimize threat intelligence feeds integrated with security monitoring and XDR platforms. Threat Hunting Design and execute hypothesis-driven threat hunting campaigns using frameworks such as MITRE ATT&CK and the Diamond Model. Identify malicious behaviors and attack techniques that may not be detected through automated controls. Develop new detection logic and analytical techniques based on hunting results. Partner with MDR providers and internal stakeholders on collaborative hunting initiatives and security investigations. Maintain comprehensive hunting documentation, findings, lessons learned, and recommendations. Technical Leadership & Governance Act as the primary technical liaison for the MDR provider's detection and threat hunting capabilities. Participate in operational reviews focused on detection coverage, false positive reduction, hunt outcomes, and emerging threats. Maintain and prioritize detection enhancement roadmaps and coverage gap remediation plans. Contribute to the ongoing maturity and effectiveness of the Cyber Defense program. Promote best practices, continuous improvement, and knowledge sharing across cybersecurity teams. About You Experience Minimum 8 years of cybersecurity experience with significant expertise in one or more of the following domains: Adversary Detection Threat Hunting Cyber Threat Intelligence Security Operations Experience supporting enterprise or critical infrastructure environments. Proven hands-on experience developing SIEM, XDR, EDR, or detection content. Experience operationalizing cyber threat intelligence and converting intelligence into defensive actions. Demonstrated experience conducting structured, hypothesis-driven threat hunting activities. Experience working with managed detection and response providers and security operations teams. Education Undergraduate degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related discipline. Skills & Competencies Strong knowledge of MITRE ATT&CK, adversary emulation, threat modeling, and detection engineering. Experience with Cortex XDR, Microsoft Sentinel, Splunk, or equivalent security platforms. Understanding modern attack techniques targeting cloud, identity, endpoint, and enterprise environments. Ability to analyze threat intelligence from structured and unstructured sources. Strong analytical and investigative skills with a proactive, hypothesis-driven mindset. Excellent written and verbal communication skills. Ability to communicate technical findings effectively to both technical and business audiences. Highly organized with strong documentation and reporting discipline . Preferred Qualifications GIAC certifications such as GCTI, GDAT, GCIA, or GCIH. Palo Alto Networks XDR or XSIAM certifications. FOR578 Cyber Threat Intelligence training or equivalent. Experience in mining, energy, utilities, manufacturing, or other critical infrastructure sectors. Familiarity with OT/ICS cybersecurity environments. Experience with Python, PowerShell, XSOAR/XSIAM automation, OpenCTI, MISP, or similar platforms. What We Offer You Competitive compensation including a variable annual incentive plan Participation in a competitive Defined Contribution Pension package Comprehensive benefits package (company paid core coverage, health and dental coverage, flex accounts, disability plans, and optional insurances) Leave for all of life’s reasons (vacation, personal, sick, parental) Work culture dedicated to safety, diversity & inclusion, and career growth Employee Family Assistance Program Virtual Healthcare online Online training and career development opportunities Why Toronto Vale's Toronto office, nestled in the heart of Canada's largest city, serves as a pivotal hub for the company's operations. This office is central to Vale’s finance, strategic planning, commercial (marketing and sales), and sustainability teams, driving key initiatives that support the company's global mission. Toronto’s vibrant, diverse, and dynamic environment enhances Vale’s ability to innovate and excel in these critical areas, reflecting the city's status as a leading international business center. Include to Transform At Vale Base Metals, we are committed to ensuring an inclusive work environment where people feel comfortable to be themselves. Vale encourages everyone to express their ideas and opinions and values the plurality of individual profiles. We want our people to feel that all voices are heard, all cultures respected and that a variety of perspectives are not only welcome – they are critical to our success. We treat each other fairly and with dignity regardless of race, gender, nationality, ethnic origin, religion, age, sexual orientation, or any other personal consideration that makes us different. Vale is an equal opportunity employer seeking to increase diversity across our operations and improve equal opportunity at Vale and in the mining industry. In accordance with the Accessibility for Ontarians with Disabilities Act, accommodation is available throughout our recruitment process for applicants with disabilities. #ValeBaseMetals
Ce que vous ferez
The role focuses on developing advanced detection content and executing hypothesis-driven threat hunting campaigns to identify adversarial activity. It involves operationalizing threat intelligence to strengthen cyber resilience across corporate IT, cloud, and operational technology environments.
Exigences
Requires a minimum of 8 years of cybersecurity experience with expertise in detection, hunting, or intelligence, and a bachelor's degree in a technical field. Proficiency with security platforms like Cortex XDR or Sentinel and knowledge of the MITRE ATT&CK framework are essential.
Avantages
• Variable annual incentive plan • Defined Contribution Pension package • Health and dental coverage • Flex accounts • Disability plans • Optional insurances • Vacation • Personal leave • Sick leave • Parental leave • Employee Family Assistance Program • Virtual Healthcare online • Online training and career development opportunities
Compétences indiquées
- PythonSouhaitée
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Adversary Detection
- Threat Hunting
- Cyber Threat Intelligence
- MITRE ATT&CK
- SIEM
- XDR
- EDR
- Cortex XDR
- Microsoft Sentinel
- Splunk
- Detection Engineering
- Threat Modeling
- Adversary Emulation
- Python
- PowerShell
- OT/ICS Cybersecurity
Domaines d’emploi
- Security & Safety
- Technology
- Engineering
- Manufacturing
- Management & Leadership
Renseignements supplémentaires
- Formation minimale
- Baccalauréat
- Expérience minimale
- 10+ ans
- Postuler avant le
- 12 sept. 2026
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
- Niveau d’expérience
- Mid-Senior level