SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Cyber Defence Analyst

Nesto - Canada - Hybrid - posted 2026-09-17

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Nesto Cloud is Canada's cloud-native, AI-driven mortgage technology platform serving financial institutions. The company modernizes lending through AI intelligent automation, proprietary cloud technology, and business process outsourcing solutions. Nesto Group administers over CAD $80 billion in residential and commercial mortgages and has been recognized as one of Deloitte's Fast 50 companies for three consecutive years. You will join the Cyber Defence team as a Senior Cyber Defence Analyst, reporting to the Cyber Defence Director. This is a hands-on role focused on investigation, detection engineering, and building AI-driven defence capabilities in a 100% cloud, developer-centric environment. Key responsibilities include: - Lead triage-to-remediation on critical and high-severity investigations - Conduct proactive threat hunts and operationalize findings into detections and playbooks - Operate and optimize Google SecOps SIEM, SOAR, and SentinelOne, building detection content, dashboards, and playbooks - Design, code, and deploy detection rules across cloud, endpoint, and application layers with minimal false positive rates - Implement Blue Team coverage across cloud infrastructure (Azure, GCP), MS365/Entra ID, containers, CI/CD pipelines, and application layers - Tune existing detections and close coverage gaps; maintain detection knowledge base - Partner with DevOps and engineering teams to embed detection and response capability into cloud-native architectures - Consume threat intelligence (IOCs, TTPs) and translate into hunts and detections - Participate in purple team exercises and document findings - Validate detection coverage against Red Team scenarios - Evaluate and pilot AI/ML tools for detection augmentation, anomaly detection, and alert triage - Implement selected tools into SIEM/SOAR workflows and measure effectiveness You'll work with a modern tech stack and AI-driven development frameworks designed to help you innovate and accelerate your career. The role offers accelerated growth, exposure to production systems, and collaboration with high-performing talent. Requirements: - 7+ years of experience in a SOC, Cyber Defence, or Blue Team role with demonstrated seniority in investigations - Hands-on expertise in SIEM/SOAR platforms (Google SecOps, Splunk, or similar) - Strong detection engineering and threat hunting capabilities - Proficiency in cloud security (Azure, GCP, or AWS) - Experience with endpoint detection and response (EDR) tools such as SentinelOne - Coding/scripting ability (Python, Go, or similar) for detection automation - Understanding of cloud-native architectures, containers, and CI/CD security - Familiarity with threat intelligence frameworks and MITRE ATT&CK - Experience in purple team exercises or adversary simulation - Ability to work in a fast-paced, dev-centric environment - Strong communication skills and ability to partner across technical teams

Similar roles