# Information Security Operations Lead (Toronto, Canada)

**Company**: Starling Group
**Location**: Toronto, Ontario
**Work arrangement**: hybrid
**Experience**: senior
**Job type**: full-time
**Category**: IT
**Industry**: Finance

**Apply**: https://apply.workable.com/j/AC8DE477C7?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply
**Canonical**: https://yubhub.co/jobs/job_1669f9af-0ad

## Description

We are Starling, a global financial services company with a presence in the UK, Australia, and Canada. We offer a range of banking and software solutions to individuals and businesses.

We are looking for an experienced Information Security Operations Lead to join our team in Toronto. As a member of our Security Operations Centre (SOC) team, you will be responsible for leading a team of subject matter experts and analysts to ensure the management and continuous improvement of Information Security in line with Bank policy and procedure.

Key responsibilities:

- Lead a team of subject matter experts and analysts to ensure Information Security is managed and continuously improved

- Support the development and progression of the Information Security Analyst team

- Conduct incident triage, response, and investigations

- Interpret logs from various sources to identify root cause and determine next steps

- Collaborate with other teams to analyse, contain, eradicate, and recover from cyber security incidents

- Develop and maintain incident handling, response, and readiness processes

- Support detection engineering and threat hunting

- Document incidents and investigations

- Plan and participate in Tabletop Exercises

- Present investigation findings to technical and non-technical audiences

Requirements:

- 5+ years experience in an in-house SOC role and team, including cyber incident response and digital forensics function

- Experience in a similar role leading, developing and motivating a team of subject matter experts and other managers in Information and Cyber Security

- Understanding of AWS Security Solutions (or other Public Cloud Solutions)

- Analysis and Incident Response experience with Cloud systems (GCP, AWS)

- Experience working and supporting analytics/SIEM platforms

- Experience supporting and conducting Incident Response engagements

- Experience in endpoint based investigations

- Experience in cloud based investigations

- Experience with Incident Command and conducting Tabletop Exercises

- Excellent communication skills (both verbal and written)

- Demonstrated teamwork and collaboration skills

- Time management, problem-solving and interpersonal skills

- Eagerness to learn and apply knowledge to new security challenges

Benefits:

- A discretionary benefits stipend, payable on a monthly basis

- 20 days annual leave plus public holidays

## Skills

### Required
- AWS Security Solutions
- Cloud systems
- Incident Response
- Digital forensics
- Security Operations Centre (SOC)
- Analytics/SIEM platforms
- Endpoint investigations
- Cloud based investigations
- Incident Command
- Tabletop Exercises

### Nice to have
- Forensics: cloud (GCP, AWS); endpoint/server (Windows, MacOS, Linux); and/or network
- Programming in Python, Go and/or Java
- Cyber/Information Security related degree and/or relevant cyber security qualification(s)
- Malware analysis techniques

---

Source: [Apply at apply.workable.com](https://apply.workable.com/j/AC8DE477C7?utm_source=yubhub.co&utm_medium=jobs_feed&utm_campaign=apply)
