Base Career helps you apply smarter for this job.
Key skills for this role
Security Monitoring and Incident Response:
Monitors security events and alerts from various sources (SIEM, endpoint detection, SASE, etc.) and analyzes them to identify potential security incidents.
Leads security incident response efforts, including investigation, containment, eradication, and recovery.
Develops and maintains incident response plans, playbooks, and procedures.
Coordinates with cross-functional teams (IT, Engineering, Legal, etc.) during security incidents.
Perform root cause analysis of security incidents and recommend preventive measures. Independently analyzes complex security incidents, identifying root causes and developing solutions and drives them to completion.
Participate in an on-call rotation.
Security Tooling and Automation:
Manage and maintain security tools and technologies, such as SIEM, EDR, and SASE platforms.
Develop and implement automation scripts and workflows to improve security operations efficiency and effectiveness.
Demonstrated ability to leverage GCP services (e.g., Cloud Functions, Cloud Run) to host and automate security scripts and tools for event enrichment and response.
Proficiency in utilizing GCP services like Pub/Sub, Dataflow, BigQuery, and Cloud Storage for data processing, analysis, and enrichment.
Evaluate and recommend new security tools and technologies to enhance our security posture.
Manage and maintain infrastructure through Terraform.
Threat Management:
Conduct threat research and analysis to identify emerging threats and vulnerabilities.
Develop and implement threat detection rules and use cases.
Security Engineering and Architecture:
Contribute to the design and implementation of security systems architectures and solutions.
Evaluate and recommend security controls for new and existing systems.
Ensure security best practices are followed in system development and implementation.
Collaboration and Communication:
Collaborate with other teams to ensure security is integrated into all aspects of the organization's operations.
Communicate security risks and issues to technical and non-technical audiences, including leadership.
Mentors and provides guidance to junior security analysts and engineers to develop their technical growth.
Compliance and Reporting:
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
, CAN
, CAN
Toronto, CAN
, USA
Toronto, CAN
Toronto, CAN
, USA
, USA
Ensure compliance with relevant security standards and regulations (e.g., HITRUST, NIST, GDPR).
Prepare and present security reports to management.
Participate in routine audits within the organization
About You
Bachelor of Science degree (BS) in Computer Science (or a related field)
Minimum of 7 years in Cybersecurity with a strong focus on Incident Response, or
Minimum of 3 years in Security Operations with hands-on experience in SOAR and other automation tools.
Deep and broad technical understanding of security concepts, principles, and technologies.
Experience with security monitoring tools (e.g., SIEM, EDR), including configuration and administration of these tools.
Proven leading and coordinating incident response processes and methodologies.
Proficiency in scripting languages (e.g., Python, Go).
You have some Infrastructure as Code (Terraform, Ansible) experience or a strong desire to learn.
Experience with threat intelligence platforms and implementing these in security operations.
Strong analytical and problem-solving skills.
You are a collaborator at your core
Excellent communication and interpersonal skills.
Nice to Haves
Security certifications (e.g., OffSec Certifications, GIAC Certifications).
Experience with digital forensics
Experience with cloud security (AWS, Azure, GCP).
Experience with Security Orchestration,Automation and Response (SOAR).
Knowledge of networking protocols and security.
Contributions to the security community at League, and more broadly (eg. blog posts, conference presentations, etc.)
Use AI tools as part of your daily workflow to enhance productivity, problem-solving, and decision-making (e.g., drafting, analysis, coding, research, or process automation)
Apply judgment and accountability when using AI by reviewing outputs for accuracy, bias, and quality before use
Continuously learn and adapt as new AI tools and capabilities emerge, incorporating them into your ways of working
Identify opportunities to improve how work gets done from personal productivity to team-level workflows by leveraging AI effectively
Operate with strong data responsibility and security awareness, especially when working with sensitive or regulated information
Individual Contributors: Use AI to improve personal productivity and quality of output
Senior ICs / Managers: Integrate AI into team workflows and improve processes
Leaders: Drive AI adoption at the organizational level and shape how work is done across teams
Demonstrated experience using AI tools in a practical, responsible way
Curiosity and openness to experimenting with new technologies
Ability to balance efficiency with quality and sound judgment
Security-Related Responsibilities
Compliance with Information Security Policies
Compliance with League’s secure coding practice
Responsibility and accountability for executing League's policies and procedures
Notification of HR, Legal, Compliance & Security of any incidents, breaches or policy violations
CANADA APPLICANTS ONLY: The Canada-specific compensation range below for this full-time position is exclusive of bonus, equity and benefits. This range reflects the minimum and maximum target for base salaries for the position across all Canadian locations. The salary range is intentional to account for the performance and career progressions a Leaguer will experience in the role throughout their time at League. Where in the band you may land is determined by job-related skills/experience. Your recruiter can share more about the specific salary range specific to your skills and experience during the hiring process.
You should receive a confirmation email after submitting your application.
A recruiter (not a computer) reviews all applications at League.
If we see alignment with League's needs, a recruiter will reach out to learn more about your goals. The recruiter will also share the team-specific interview process depending on the roles you are exploring.
The final step is an offer, which we hope you will accept!
Prior to joining us, we conduct reference and background checks. Additional checks could be required for US Candidates, depending on the role you are exploring.
Learn about our platform, leadership team and partners
Highmark Health, Google Cloud, League: new digital front door to seamless care
Former Providence President and Workday EVP of Corporate Strategy join League Board of Directors
League raises $95 million USD in Series C to build world’s leading healthcare CX platform
Forbes x League: The Platformization Of Healthcare Is Here
Fast Company x League: If we want better innovations in healthtech, we need more competition
Security Monitoring and Incident Response:
Monitors security events and alerts from various sources (SIEM, endpoint detection, SASE, etc.) and analyzes them to identify potential security incidents.
Leads security incident response efforts, including investigation, containment, eradication, and recovery.
Develops and maintains incident response plans, playbooks, and procedures.
Coordinates with cross-functional teams (IT, Engineering, Legal, etc.) during security incidents.
Perform root cause analysis of security incidents and recommend preventive measures. Independently analyzes complex security incidents, identifying root causes and developing solutions and drives them to completion.
Participate in an on-call rotation.
Security Tooling and Automation:
Manage and maintain security tools and technologies, such as SIEM, EDR, and SASE platforms.
Develop and implement automation scripts and workflows to improve security operations efficiency and effectiveness.
Demonstrated ability to leverage GCP services (e.g., Cloud Functions, Cloud Run) to host and automate security scripts and tools for event enrichment and response.
Proficiency in utilizing GCP services like Pub/Sub, Dataflow, BigQuery, and Cloud Storage for data processing, analysis, and enrichment.
Evaluate and recommend new security tools and technologies to enhance our security posture.
Manage and maintain infrastructure through Terraform.
Threat Management:
Conduct threat research and analysis to identify emerging threats and vulnerabilities.
Develop and implement threat detection rules and use cases.
Security Engineering and Architecture:
Contribute to the design and implementation of security systems architectures and solutions.
Evaluate and recommend security controls for new and existing systems.
Ensure security best practices are followed in system development and implementation.
Collaboration and Communication:
Collaborate with other teams to ensure security is integrated into all aspects of the organization's operations.
Communicate security risks and issues to technical and non-technical audiences, including leadership.
Mentors and provides guidance to junior security analysts and engineers to develop their technical growth.
Compliance and Reporting:
Ensure compliance with relevant security standards and regulations (e.g., HITRUST, NIST, GDPR).
Prepare and present security reports to management.
Participate in routine audits within the organization
About You
Bachelor of Science degree (BS) in Computer Science (or a related field)
Minimum of 7 years in Cybersecurity with a strong focus on Incident Response, or
Minimum of 3 years in Security Operations with hands-on experience in SOAR and other automation tools.
Deep and broad technical understanding of security concepts, principles, and technologies.
Experience with security monitoring tools (e.g., SIEM, EDR), including configuration and administration of these tools.
Proven leading and coordinating incident response processes and methodologies.
Proficiency in scripting languages (e.g., Python, Go).
You have some Infrastructure as Code (Terraform, Ansible) experience or a strong desire to learn.
Experience with threat intelligence platforms and implementing these in security operations.
Strong analytical and problem-solving skills.
You are a collaborator at your core
Excellent communication and interpersonal skills.
Nice to Haves
Security certifications (e.g., OffSec Certifications, GIAC Certifications).
Experience with digital forensics
Experience with cloud security (AWS, Azure, GCP).
Experience with Security Orchestration,Automation and Response (SOAR).
Knowledge of networking protocols and security.
Contributions to the security community at League, and more broadly (eg. blog posts, conference presentations, etc.)
Use AI tools as part of your daily workflow to enhance productivity, problem-solving, and decision-making (e.g., drafting, analysis, coding, research, or process automation)
Apply judgment and accountability when using AI by reviewing outputs for accuracy, bias, and quality before use
Continuously learn and adapt as new AI tools and capabilities emerge, incorporating them into your ways of working
Identify opportunities to improve how work gets done from personal productivity to team-level workflows by leveraging AI effectively
Operate with strong data responsibility and security awareness, especially when working with sensitive or regulated information
Individual Contributors: Use AI to improve personal productivity and quality of output
Senior ICs / Managers: Integrate AI into team workflows and improve processes
Leaders: Drive AI adoption at the organizational level and shape how work is done across teams
Demonstrated experience using AI tools in a practical, responsible way
Curiosity and openness to experimenting with new technologies
Ability to balance efficiency with quality and sound judgment
Security-Related Responsibilities
Compliance with Information Security Policies
Compliance with League’s secure coding practice
Responsibility and accountability for executing League's policies and procedures
Notification of HR, Legal, Compliance & Security of any incidents, breaches or policy violations
CANADA APPLICANTS ONLY: The Canada-specific compensation range below for this full-time position is exclusive of bonus, equity and benefits. This range reflects the minimum and maximum target for base salaries for the position across all Canadian locations. The salary range is intentional to account for the performance and career progressions a Leaguer will experience in the role throughout their time at League. Where in the band you may land is determined by job-related skills/experience. Your recruiter can share more about the specific salary range specific to your skills and experience during the hiring process.
You should receive a confirmation email after submitting your application.
A recruiter (not a computer) reviews all applications at League.
If we see alignment with League's needs, a recruiter will reach out to learn more about your goals. The recruiter will also share the team-specific interview process depending on the roles you are exploring.
The final step is an offer, which we hope you will accept!
Prior to joining us, we conduct reference and background checks. Additional checks could be required for US Candidates, depending on the role you are exploring.
Learn about our platform, leadership team and partners
Highmark Health, Google Cloud, League: new digital front door to seamless care
Former Providence President and Workday EVP of Corporate Strategy join League Board of Directors
League raises $95 million USD in Series C to build world’s leading healthcare CX platform
Forbes x League: The Platformization Of Healthcare Is Here
Fast Company x League: If we want better innovations in healthtech, we need more competition
Healthcare platform company building consumer-centric digital front doors that empower people to live healthier lives through personalized and always-on health experiences.
Visit company websiteJobs and hiring trendsSenior
Apply faster on company sites with our extension.