Jobs.ca
Jobs.ca
Language
ISA Cybersecurity logo

Incident Response Analyst, Digital Forensics & Incident Response

ISA Cybersecurityabout 20 hours ago
Hybrid
Toronto, Ontario, Canada
Mid Level
Full-Time

Top Benefits

Flexible Sick And Personal Days
Health Plan
Mental Health Resources

About the role

About the Role

The Incident Response (IR) Analyst is a hands-on technical responder within ISA Cybersecurity's Digital Forensics & Incident Response (DFIR) function, delivering the Security Incident Response (SIR) service across client engagements. The role executes forensic collection, analysis, and containment work under the direction of the Cyber Incident Response Commander, building the case-based experience and technical depth that lead toward Incident Commander and Senior Analyst career paths. The IR Analyst supports every stage of active engagements, from triage and evidence acquisition through eradication and post-incident reporting, working alongside the IR Commander, DFIR team members, and SOC teams. Strategic direction rests with the Incident Commander and final accountability for the DFIR program rests with the Senior Director, DFIR Services. The successful candidate will have practical experience supporting incident response and forensic investigations, strong technical fundamentals across endpoint, network, and cloud environments, and the composure to work effectively under the pressure of active incidents.

About Us

We are proud to be recognized as a top employer for multiple years in a row, we currently hold the distinctions of Canada’s Top Small and Medium Employers 2025, Greater Toronto’s Top Employers 2025 and are Certified Great Place to Work 2026-2027. ISA Cybersecurity is a proudly Canadian cyber and AI services and solutions provider. Trusted by over 500 clients from SMB to global enterprise, we empower organizations to safeguard their most critical assets and adopt AI securely. Through our highly customizable Cyber 360 and AI 360 offerings, we deliver a comprehensive range of governance, assurance, engineering protection, detection, and response services for the public and private sectors. Backed by over three decades of operational experience and a vast network of highly specialized and certified experts, we leverage cutting-edge technologies and AI to ensure that clients achieve their privacy, security, and business goals. We operate in a remote-first environment. Office presence is typically less than 20% of the time, varying by role and work requirements. Our office space, located at Bloor and Islington, is a collaborative space designed for in-person meetings and drop-ins. We enjoy hosting in-person quarterly townhalls and social events throughout the year to encourage teambuilding and collaboration.

Responsibilities

Support the Incident Commander in the execution of IR Retainer engagements and Emergency IRs, carrying out assigned workstreams within the incident. Perform digital forensic acquisition and analysis across endpoint, server, network, mobile, and cloud sources. Maintain chain-of-custody discipline suitable for legal proceedings throughout evidence handling. Gather and analyze evidence from logs, email, endpoint artifacts, and other sources to identify indicators of compromise and attacker activity. Reconstruct attack timelines from collected evidence to support root-cause analysis and scope determination. Apply and help refine DFIR playbooks and runbooks in the course of live engagements, flagging gaps or improvements to the IR Commander. Contribute to incident and digital evidence reports, including drafting technical findings for review by the IR Commander prior to client, legal, or law enforcement delivery. Participate in post-incident reviews and lessons-learned sessions, translating findings into playbooks, tooling, or training improvements. Assist with technical scoping input for proposals, Statements of Work (SOWs), and RFP responses as requested. Correlate threat intelligence and observed TTPs into incident analysis, and feed findings back to detection and threat hunting teams. Track and report on assigned incident metrics and contribute to continuous-improvement initiatives for the DFIR practice. Support the IR readiness program, including IR Plan engagements, Tabletop Exercises (TTX), and playbook validation. Act as a client-facing technical resource during engagements under the direction of the IR Commander. Collaborate with SOC analysts and Service Owners to keep incident response work aligned with detection capabilities.

Qualifications

3+ years of progressive experience in cybersecurity, including direct experience in incident response and/or digital forensics. Working knowledge of the incident response lifecycle, containment and eradication strategies, and digital forensic methodologies. Hands-on experience with host, network, or cloud forensics, including exposure to chain-of-custody requirements. Proficient working with Windows, Linux, and MacOS environments. Exposure to cloud forensics or investigations (AWS, Azure, GCP, Microsoft 365, Google Workspace). Working knowledge of security control families such as EDR, SIEM, SOAR, NDR, identity, email security, or DLP. Familiarity with MITRE ATT&CK and current ransomware/APT TTPs. Familiarity with frameworks such as NIST SP 800-61, ISO 27035, or NIST CSF is an asset. Clear written and verbal communication skills; ability to document technical findings for both technical and non-technical audiences. Bachelor's degree in computer science, Information Security, or related field, or equivalent professional experience. Willingness to participate in 24x7 on-call rotation for IR Retainers and Emergency IRs. Ability to obtain Government of Canada security clearance. Strong English language skills, written and verbal.

Nice to Have

Experience supporting MSSP service delivery, including contractual SLAs and 24x7 operations. Exposure to OSINT gathering and correlation in support of threat actor attribution or exposure analysis. Experience supporting law enforcement engagements or regulatory investigations. Exposure to dark web or social-media threat monitoring. Multilingual capability is an asset.

Certifications

Preferred: GCIH, GCFA, GCFE Nice to have: OSCP, CySA+, CHFI, ECIH, CompTIA Security+, CISSP (or actively pursuing) Cloud (any of): AWS Security Specialty, Azure Security Engineer, Google Professional Cloud Security Engineer Why Join Us? At ISA Cybersecurity we lead with our "Why". Our Why is to make people feel safe. This not only applies to the result of services that we provide to our clients, but how people feel when interacting with us. Whether you're an employee of ISA or a client we want you to feel safe and supported. Each one of our team members is expected to uphold this leadership quality and embrace it through consistent demonstration of our core values of Explore, Persevere, Adapt and Uplift. We are proud to offer a variety of employee friendly programs that enable our team to perform at their best.

Highlights of our programs and policies include

Flexible sick and personal days for all employees Generous health plan with enhanced mental health resources and programs Professional development opportunities and education reimbursement up to $2,000 annually for all employees Maternity and parental leave top-up Employee referral bonus of $2,000 Competitive salaries complemented with RRSP matching and bonus programs Distance remote working policy LinkedIn Learning access for all team members We also place great value on celebrating the contributions of all employees through the following service recognition programs: Service anniversary recognition and generous five-year milestone service awards President’s Club recognizing special achievement awards: Team Member of the Year for Sales, CIOC and Cyber Services, the Rich Uhrich Founder’s Award that is nominated on by all employees and four President’s Awards (Risk Taker, Lost Without You, Money Maker and On the Rise) Spot rewards providing opportunities for instant peer recognition Information-sharing and team-building initiatives include: Annual kick-off meeting to communicate our strategic priorities Quarterly town hall meetings Regular team get togethers and client events Scheduled employee feedback surveys and goal setting focus groups Thank you for your interest in joining ISA Cybersecurity. Our team looks forward to reviewing your application. We will be reaching out to you directly if your experience matches our needs. Vacancy Status: This posting is for an existing vacancy.

Salary Range: $75,000-90,000-105,000

AI Disclosure: ISA Cybersecurity does not currently use artificial intelligence tools as part of our recruitment process.

Accessibility

ISA Cybersecurity is committed to providing accommodations for applicants with disabilities. If you require specific accommodation because of a disability or medical need, please inform ISAs Human Resources team (peopleoperations@e-isa.com) so arrangements can be made for appropriate accommodation to be in place during the recruitment process.

About ISA Cybersecurity

Computer and Network Security
51-200
Founded in 1992

ISA Cybersecurity is one of Canada’s leading cybersecurity services and solutions providers. We serve over 500 clients, from SMB to global enterprise, in finance, government, healthcare, education, and more. For over three decades, we have been providing customers with advisory and technical services on complex and evolving issues related to cybersecurity. In addition to Canadian offices in Toronto, Ottawa, and Calgary, and an office in London, England, ISA Cybersecurity operates a world-class, 24/7/365, SOC 2 Type 2 security operations centre in Ontario. We are recognized as a Major Player in both the latest IDC MarketScape: Canadian Security Services Vendor Assessment and the latest IDC MarketScape: Canadian MDR Services Vendor Assessment.

Similar Jobs