Incident Response Analyst
- LocationToronto, Canada
- Salary$5,000 β $7,000 / month
- Job typeFull time
- ExperienceMid level
- EducationBachelor's degree; GCIH/GCFE preferred
- WorkplaceOn-site
- Visa sponsorshipYes
- PostedSep 26, 2026
- Deadlineβ
Job Description
TechNova Solutions is hiring an Incident Response Analyst for our Toronto cyber-defence team handling security incidents for our platform and enterprise clients. You will lead investigations from detection through eradication β performing forensic analysis, containing threats, and driving lessons-learned improvements. Our Toronto team handles incidents for clients across North America, from ransomware outbreaks to sophisticated intrusions requiring weeks of forensic investigation. You will work with a well-drilled team following mature playbooks, with direct access to legal counsel and executive stakeholders during major incidents.
We sponsor visas through the Global Talent Stream, fund GCIH/GCFE certifications, and run realistic incident simulations quarterly. Our IR team is well-resourced, respected by engineering, and supported by dedicated threat-intelligence feeds. You will also maintain our threat-intelligence feeds and lead tabletop exercises for clients. Our lab environment lets you detonate real malware samples safely, building the hands-on skills that define elite responders, and you will receive funded GCIH, GCFE and advanced malware-analysis training.
Responsibilities
Lead end-to-end incident response: triage to eradication and recovery
Perform host and network forensic analysis
Contain threats across endpoints, cloud and identity systems
Coordinate with legal, comms and client stakeholders during incidents
Develop and maintain IR playbooks and runbooks
Conduct post-incident reviews and drive remediation actions
Requirements
3-5 years in incident response, SOC Tier 2/3 or DFIR roles
Strong forensic skills (disk, memory, cloud forensics)
Experience with EDR platforms (CrowdStrike, SentinelOne)
Knowledge of attacker TTPs and MITRE ATT&CK
GCIH, GCFE or equivalent certification preferred
Calm under pressure with excellent communication
Skills
Incident Response, Digital Forensics, CrowdStrike, MITRE ATT&CK, Memory Forensics, Network Forensics, Python, SIEM, Threat Intelligence, Playbooks
Benefits
Visa sponsorship via Global Talent Stream
Funded GCIH/GCFE certifications
Annual bonus and on-call compensation
Comprehensive health and dental benefits
Hybrid working in downtown Toronto