SlipstreamJobsFresh Startup & VC-Backed Jobs

Analyste sénior en cyberdéfense

Nesto - Montreal, QC, Canada - Hybrid - posted 2026-09-17

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Nesto Cloud is Canada's end-to-end cloud-native mortgage technology platform powered by AI. The company helps financial institutions modernize lending through intelligent AI automation, proprietary AI and cloud technology, and business process outsourcing (BPO) solutions. Nesto Group manages over CAD 80 billion in residential and commercial mortgage loans and has been recognized on Deloitte's Fast 50 list for three consecutive years. You will join the Cyber Defense team as a Senior Analyst reporting to the Director of Cyber Defense. This role is ideal for someone who thrives on hands-on investigations, detection engineering, and building innovative AI-powered defense capabilities within a 100% cloud and developer-focused environment. Key Responsibilities: - Lead the investigation process from triage through remediation for critical and high-priority incidents - Conduct proactive threat hunting; translate findings into detections and playbooks - Leverage and optimize Google SecOps SIEM, SOAR, and SentinelOne tools; design detection content, dashboards, and playbooks - Design, code, and deploy detection rules across cloud, endpoints, and application layers with minimal false positives - Extend Blue Team coverage beyond endpoints/servers to include cloud infrastructure (Azure, GCP), MS365/Entra ID, containers, CI/CD pipelines, and application layers - Refine existing detections, close coverage gaps, and maintain the detection knowledge base - Collaborate with DevOps and engineering teams to embed detection and response capabilities into application and cloud-native architectures - Analyze threat intelligence (IOCs, TTPs) and translate into threat hunts and detections - Participate in Purple Team exercises; document findings and create detections to close gaps - Validate detection coverage using Red Team scenarios - Evaluate and pilot AI/ML tools for detection augmentation, anomaly detection, and alert triage - Integrate selected tools into SIEM/SOAR workflows; measure effectiveness Requirements: - 7+ years of experience in SOC, Cyber Defense, or Blue Team roles with demonstrated seniority in investigations - Solid hands-on experience with SOAR, SIEM data ingestion, use-case development, and optimization - Proficiency in detection engineering and threat hunting methodologies - Strong understanding of cloud security (Azure, GCP) and modern application architectures - Experience with Google SecOps, SentinelOne, or similar EDR/XDR platforms - Familiarity with CI/CD pipelines, container security, and infrastructure-as-code concepts - Coding ability in Python, Go, or similar languages for detection rule development - Knowledge of MITRE ATT&CK framework and threat intelligence integration - Excellent communication and documentation skills - Ability to work independently and collaborate across technical teams

Similar roles