SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Nesto Cloud is Canada's cloud-native, AI-driven mortgage technology platform serving financial institutions. The company modernizes lending through AI intelligent automation, proprietary cloud technology, and business process outsourcing solutions. Nesto Group administers over CAD $80 billion in residential and commercial mortgages and has been recognized as one of Deloitte's Fast 50 companies for three consecutive years.
You will join the Cyber Defence team as a Senior Cyber Defence Analyst, reporting to the Cyber Defence Director. This is a hands-on role focused on investigation, detection engineering, and building AI-driven defence capabilities in a 100% cloud, developer-centric environment.
Key responsibilities include:
- Lead triage-to-remediation on critical and high-severity investigations
- Conduct proactive threat hunts and operationalize findings into detections and playbooks
- Operate and optimize Google SecOps SIEM, SOAR, and SentinelOne, building detection content, dashboards, and playbooks
- Design, code, and deploy detection rules across cloud, endpoint, and application layers with minimal false positive rates
- Implement Blue Team coverage across cloud infrastructure (Azure, GCP), MS365/Entra ID, containers, CI/CD pipelines, and application layers
- Tune existing detections and close coverage gaps; maintain detection knowledge base
- Partner with DevOps and engineering teams to embed detection and response capability into cloud-native architectures
- Consume threat intelligence (IOCs, TTPs) and translate into hunts and detections
- Participate in purple team exercises and document findings
- Validate detection coverage against Red Team scenarios
- Evaluate and pilot AI/ML tools for detection augmentation, anomaly detection, and alert triage
- Implement selected tools into SIEM/SOAR workflows and measure effectiveness
You'll work with a modern tech stack and AI-driven development frameworks designed to help you innovate and accelerate your career. The role offers accelerated growth, exposure to production systems, and collaboration with high-performing talent.
Requirements:
- 7+ years of experience in a SOC, Cyber Defence, or Blue Team role with demonstrated seniority in investigations
- Hands-on expertise in SIEM/SOAR platforms (Google SecOps, Splunk, or similar)
- Strong detection engineering and threat hunting capabilities
- Proficiency in cloud security (Azure, GCP, or AWS)
- Experience with endpoint detection and response (EDR) tools such as SentinelOne
- Coding/scripting ability (Python, Go, or similar) for detection automation
- Understanding of cloud-native architectures, containers, and CI/CD security
- Familiarity with threat intelligence frameworks and MITRE ATT&CK
- Experience in purple team exercises or adversary simulation
- Ability to work in a fast-paced, dev-centric environment
- Strong communication skills and ability to partner across technical teams