Back to job search
TI
TEKFORTUNE INCVerified Job Source

Threatlocker Specialist

The role focuses on designing and maintaining ThreatLocker policies, including allowlisting and ringfencing, to ensure a secure Zero Trust environment. It involves managing approval queues, auditing learning modes, and collaborating with SOC teams for security monitoring.

  • Hybrid
  • Toronto, ON
  • Posted Aug 19, 2026
  • Apply by Sep 18, 2026
  • 1 position

More jobs you can apply to directly

Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.

Job summary

Threatlocker Specialist Hybrid 3 days in a week, Toronto, ON 6-9 Months Contract with possible Extension Job Summary This role is critical for ensuring endpoint application control remains secure and usable for engineering teams, particularly by acting as a dedicated support function during the stabilization phase of a "Default-Deny" rollout. In this role, you will be responsible for designing, implementing, auditing, and maintaining ThreatLocker policies across our organization (and/or client environments). You will play a critical role in preventing ransomware, malware, and unauthorized software execution by managing Application Whitelisting (Allowlisting), Ringfencing, Storage Control, and Elevation Control. The ideal candidate has a strong background in system administration or cybersecurity, possess a deep understanding of Windows operating systems, and is passionate about achieving a true Zero Trust security posture. Key Responsibilities Threatlocker Administration & Management ● Policy Creation & Tuning: Design, implement, and maintain Threatlocker Application Allowlisting policies to ensure only authorized software can execute. ● Ringfencing: Configure and manage Ringfencing policies to restrict what authorized applications can do (e.g., stopping PowerShell from talking to the internet or blocking Word from launching cmd.exe). ● Elevation Control: Implement and manage least-privilege access, creating rules for users to run specific applications as administrators without granting full local admin rights. ● Storage Control: Define and enforce policies for securing USB drives, network shares, and local files against unauthorized access or data exfiltration. ● Manage allowlisting, Learning Mode, and temporary exceptions. Monitoring, Auditing & Incident Response ● Approval Queue Management: Monitor and process daily ThreatLocker approval requests from users efficiently, balancing security with operational productivity. ● Learning Mode Audits: Review, analyze, and baseline new endpoints during the "Learning Mode" phase to ensure seamless transitions to "Secured Mode." ● Log Analysis & Reporting: Investigate blocked files, denied executions, and policy violations. Use ThreatLocker audit logs to identify potential security incidents or shadow IT. ● Integration: Collaborate with the SOC/SIEM team to forward ThreatLocker logs and integrate them into the broader security monitoring ecosystem. ● Triage blocked applications, scripts, DLLs, and installers. ● Track service metrics to ensure business productivity. Maintenance & Strategy ● Environment Maintenance: Keep ThreatLocker agents updated across all endpoints and servers. ● Testing & Validation: Test software updates and patch deployments in a sandbox environment to ensure they comply with existing ThreatLocker rules before company-wide rollout. ● Documentation: Maintain clear, up-to-date documentation of standard operating procedures (SOPs), policy exceptions, and approval workflows. ● Maintain Ringfencing and policy standards. Qualifications & Skills Required Experience ● ThreatLocker Expertise: Minimum of 3 years of hands-on experience specifically managing, configuring, and troubleshooting ThreatLocker in a production environment. ● IT/Cybersecurity Background: 3+ years of experience in System Administration, Helpdesk Tier 3, Network Engineering, or a Cybersecurity operations role. ● OS Proficiency: Deep, foundational knowledge of Windows OS (Registry, File Systems, Services, Active Directory, and Group Policy). Experience with macOS or Linux is a strong plus. ● Scripting: Basic familiarity with PowerShell or Command Prompt for troubleshooting and automation. Soft Skills ● Analytical Thinking: Ability to dissect complex application dependencies (e.g., figuring out why a niche accounting software was blocked by a specific DLL file). ● Customer-Centric Communication: Ability to explain security restrictions to non-technical staff diplomatically and find ways to enable business operations safely. ● Attention to Detail: Zero Trust requires precision; a misplaced rule can either cause a security gap or halt business operations. Preferred Certifications (A Plus, Not Required) ● ThreatLocker Professional or ThreatLocker Expert certifications. ● CompTIA Security+, CySA+, or Network+. ● Microsoft Certified: Windows Server or Azure Administrator.

What you’ll do

The role focuses on designing and maintaining ThreatLocker policies, including allowlisting and ringfencing, to ensure a secure Zero Trust environment. It involves managing approval queues, auditing learning modes, and collaborating with SOC teams for security monitoring.

Requirements

Candidates must have at least 3 years of hands-on experience with ThreatLocker and 3+ years in system administration or cybersecurity. Deep proficiency in Windows OS and basic PowerShell scripting skills are required.

Other relevant skills

Identified from the job description. Confirm important requirements above.

  • ThreatLocker Administration
  • Application Allowlisting
  • Ringfencing
  • Elevation Control
  • Storage Control
  • Windows OS
  • PowerShell
  • Active Directory
  • Group Policy
  • Zero Trust
  • Log Analysis
  • Incident Response
  • System Administration
  • Cybersecurity Operations
  • Audit Log Analysis
  • Endpoint Security

Job areas

  • Security & Safety
  • Technology
  • Consulting
  • Software
  • Engineering

Additional details

Minimum education
Professional degree
Minimum experience
3+ years
Apply by
Sep 18, 2026
Posting language
English
Working hours
40 hours per week
Office presence
3 days per week
Seniority
Mid-Senior level
Application method
Direct apply is available