Threatlocker Specialist
The role focuses on designing and maintaining ThreatLocker policies, including allowlisting and ringfencing, to ensure a secure Zero Trust environment. It involves managing approval queues, auditing learning modes, and collaborating with SOC teams for security monitoring.
- Hybrid
- Toronto, ON
- Posted Aug 19, 2026
- Apply by Sep 18, 2026
- 1 position
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
Job summary
Threatlocker Specialist Hybrid 3 days in a week, Toronto, ON 6-9 Months Contract with possible Extension Job Summary This role is critical for ensuring endpoint application control remains secure and usable for engineering teams, particularly by acting as a dedicated support function during the stabilization phase of a "Default-Deny" rollout. In this role, you will be responsible for designing, implementing, auditing, and maintaining ThreatLocker policies across our organization (and/or client environments). You will play a critical role in preventing ransomware, malware, and unauthorized software execution by managing Application Whitelisting (Allowlisting), Ringfencing, Storage Control, and Elevation Control. The ideal candidate has a strong background in system administration or cybersecurity, possess a deep understanding of Windows operating systems, and is passionate about achieving a true Zero Trust security posture. Key Responsibilities Threatlocker Administration & Management ● Policy Creation & Tuning: Design, implement, and maintain Threatlocker Application Allowlisting policies to ensure only authorized software can execute. ● Ringfencing: Configure and manage Ringfencing policies to restrict what authorized applications can do (e.g., stopping PowerShell from talking to the internet or blocking Word from launching cmd.exe). ● Elevation Control: Implement and manage least-privilege access, creating rules for users to run specific applications as administrators without granting full local admin rights. ● Storage Control: Define and enforce policies for securing USB drives, network shares, and local files against unauthorized access or data exfiltration. ● Manage allowlisting, Learning Mode, and temporary exceptions. Monitoring, Auditing & Incident Response ● Approval Queue Management: Monitor and process daily ThreatLocker approval requests from users efficiently, balancing security with operational productivity. ● Learning Mode Audits: Review, analyze, and baseline new endpoints during the "Learning Mode" phase to ensure seamless transitions to "Secured Mode." ● Log Analysis & Reporting: Investigate blocked files, denied executions, and policy violations. Use ThreatLocker audit logs to identify potential security incidents or shadow IT. ● Integration: Collaborate with the SOC/SIEM team to forward ThreatLocker logs and integrate them into the broader security monitoring ecosystem. ● Triage blocked applications, scripts, DLLs, and installers. ● Track service metrics to ensure business productivity. Maintenance & Strategy ● Environment Maintenance: Keep ThreatLocker agents updated across all endpoints and servers. ● Testing & Validation: Test software updates and patch deployments in a sandbox environment to ensure they comply with existing ThreatLocker rules before company-wide rollout. ● Documentation: Maintain clear, up-to-date documentation of standard operating procedures (SOPs), policy exceptions, and approval workflows. ● Maintain Ringfencing and policy standards. Qualifications & Skills Required Experience ● ThreatLocker Expertise: Minimum of 3 years of hands-on experience specifically managing, configuring, and troubleshooting ThreatLocker in a production environment. ● IT/Cybersecurity Background: 3+ years of experience in System Administration, Helpdesk Tier 3, Network Engineering, or a Cybersecurity operations role. ● OS Proficiency: Deep, foundational knowledge of Windows OS (Registry, File Systems, Services, Active Directory, and Group Policy). Experience with macOS or Linux is a strong plus. ● Scripting: Basic familiarity with PowerShell or Command Prompt for troubleshooting and automation. Soft Skills ● Analytical Thinking: Ability to dissect complex application dependencies (e.g., figuring out why a niche accounting software was blocked by a specific DLL file). ● Customer-Centric Communication: Ability to explain security restrictions to non-technical staff diplomatically and find ways to enable business operations safely. ● Attention to Detail: Zero Trust requires precision; a misplaced rule can either cause a security gap or halt business operations. Preferred Certifications (A Plus, Not Required) ● ThreatLocker Professional or ThreatLocker Expert certifications. ● CompTIA Security+, CySA+, or Network+. ● Microsoft Certified: Windows Server or Azure Administrator.
What you’ll do
The role focuses on designing and maintaining ThreatLocker policies, including allowlisting and ringfencing, to ensure a secure Zero Trust environment. It involves managing approval queues, auditing learning modes, and collaborating with SOC teams for security monitoring.
Requirements
Candidates must have at least 3 years of hands-on experience with ThreatLocker and 3+ years in system administration or cybersecurity. Deep proficiency in Windows OS and basic PowerShell scripting skills are required.
Other relevant skills
Identified from the job description. Confirm important requirements above.
- ThreatLocker Administration
- Application Allowlisting
- Ringfencing
- Elevation Control
- Storage Control
- Windows OS
- PowerShell
- Active Directory
- Group Policy
- Zero Trust
- Log Analysis
- Incident Response
- System Administration
- Cybersecurity Operations
- Audit Log Analysis
- Endpoint Security
Job areas
- Security & Safety
- Technology
- Consulting
- Software
- Engineering
Additional details
- Minimum education
- Professional degree
- Minimum experience
- 3+ years
- Apply by
- Sep 18, 2026
- Posting language
- English
- Working hours
- 40 hours per week
- Office presence
- 3 days per week
- Seniority
- Mid-Senior level
- Application method
- Direct apply is available
