About the Role
The Cybersecurity Incident Response (IR) Commander is the technical and operational authority for ISA Cybersecurity's Digital Forensics & Incident Response (DFIR) function, holding expert-level command of the Security Incident Response (SIR) service during client engagements. This role focuses on technical authority, judgment under pressure, and external-grade SME presence, rather than line management. The IR Commander leads the Response side of ISA's Protect-Detect-Respond model through influence, process ownership, and direct command on engagements. While people-leadership behaviors are valued, formal direct reports are not a requirement at hire. The role reports to the Senior Director, DFIR Services and requires extensive experience commanding ransomware, business email compromise, data exfiltration, and complex multi-vector engagements, with external recognition as a subject-matter expert in incident response and digital forensics.
Responsibilities
- Serve as Incident Commander for all IR Retainer engagements and Emergency IRs delivered by ISA Cybersecurity.
- Lead digital forensic investigations across endpoint, server, network, mobile, and cloud sources.
- Ensure chain-of-custody discipline suitable for legal proceedings.
- Develop, manage, and continuously refine DFIR processes, procedures, playbooks, and runbooks.
- Conduct regular reviews and updates to DFIR people, processes, and technologies.
- Present incident and digital evidence reports to key stakeholders including law enforcement, legal counsel, and clients.
- Lead post-incident reporting and client walk-throughs and translate lessons learned into improvements.
- Educate internal and external stakeholders on incident identification and response best practices.
- Support presales activities including proposals, Statements of Work (SOWs), and RFP responses.
- Own the technical quality of the DFIR practice in alignment with the Security Incident Response (SIR) service card.
- Integrate threat intelligence into incident analysis and feed TTPs back into detection content and hunting hypotheses.
- Identify, define, track, and report on DFIR metrics; run continuous-improvement cycles against them.
- Lead and manage the IR readiness program including IR Plan engagements, Tabletop Exercises (TTX), and Playbook development and/or validation.
- Serve as a senior client-facing voice during engagements and a trusted advisor.
- Brief executives, boards, regulators, legal counsel, and law enforcement as required.
- Represent ISA externally as a recognized DFIR subject matter expert.
- Collaborate closely with SOC leadership, analysts, and Service Owners to ensure incident response integration.
- Coach DFIR analysts and Incident Managers through technical authority, case-based pairing, and matrix influence.
- Participate in hiring panels and rotation planning.
Requirements
- 10+ years of progressive experience in cybersecurity, with at least 7 years in incident response and digital forensics roles.
- Demonstrated experience as Incident Commander on multiple high-severity engagements (e.g., ransomware, BEC, APT intrusion, large-scale data breach).
- Expert-level knowledge of the incident response lifecycle, containment and eradication strategies, and digital forensic methodologies.
- Hands-on expertise across host, network, memory, mobile, and cloud forensics, including chain-of-custody discipline suitable for legal proceedings.
- Proficient working with Windows, Linux, and MacOS.
- Experience with multi-cloud forensics (AWS, Azure, GCP, Microsoft 365, Google Workspace) and SaaS-platform investigations.
- Experience with OSINT (Open-Source Intelligence), including gathering and correlating publicly available information.
- Working knowledge of multiple security control families such as EDR, SIEM, SOAR, NDR, identity, email security, DLP.
- Deep familiarity with MITRE ATT&CK and current ransomware/APT TTPs.
- Working knowledge of NIST SP 800-61, ISO 27035, ISO 27001:2022, NIST CSF, SOC 2, and CSA CCM.
- Demonstrated ability to identify, define, track, and report on operational and service-quality metrics, and to run continuous-improvement cycles against them.
- Excellent leadership-by-influence, executive communication, and stakeholder management skills.
- Must be able to communicate clearly under pressure and to non-technical audiences.
- Trusted advisor presence; ability to brief client executives and boards on cyber risk, governance, and resilience.
- Bachelor’s degree in computer science, Information Security, or related field, or equivalent professional experience.
- CISSP (required).
- Willingness to participate in 24x7 on-call rotation for IR Retainers and Emergency IRs.
- Ability to obtain Government of Canada security clearance.
- Strong English language skills, written and verbal.
- People leadership experience including coaching, mentoring, performance feedback, hiring panels.
- Experience leading or contributing to MSSP service delivery including contractual SLAs, RACI models, 24x7 operations, and onboarding/transition workflows.
- Recognized externally as a subject matter expert through published research, conference talks, MITRE ATT&CK contributions, media commentary, or industry awards.
- Experience supporting law enforcement engagements (RCMP NC3, CCCS/CCIRC, FBI Cyber), Anton Piller orders, expert witness testimony, or regulatory investigations.
- Experience with dark web monitoring and social-media threat monitoring.
- Multilingual capability is an asset.
Skills
- Incident Response
- Digital Forensics
- Ransomware Response
- Business Email Compromise Response
- Data Exfiltration Response
- Endpoint Forensics
- Server Forensics
- Network Forensics
- Mobile Forensics
- Cloud Forensics
- Chain-of-Custody
- DFIR Process Development
- DFIR Process Refinement
- DFIR Playbook Development
- DFIR Runbook Development
- Threat Intelligence Integration
- DFIR Metrics Tracking
- IR Readiness Program Management
- Tabletop Exercises (TTX)
- Executive Briefings
- Law Enforcement Briefings
- Regulatory Briefings
- External Subject Matter Expertise
- SOC Integration
- Coaching DFIR Analysts
- Coaching Incident Managers
- Hiring Panel Participation
- Windows Forensics
- Linux Forensics
- MacOS Forensics
- Multi-Cloud Forensics (AWS, Azure, GCP)
- Microsoft 365 Forensics
- Google Workspace Forensics
- SaaS Platform Investigations
- OSINT
- EDR
- SIEM
- SOAR
- NDR
- Identity Security
- Email Security
- DLP
- MITRE ATT&CK
- NIST SP 800-61
- ISO 27035
- ISO 27001:2022
- NIST CSF
- SOC 2
- CSA CCM
- Leadership-by-Influence
- Executive Communication
- Stakeholder Management
- Client Advisory
- Cyber Risk Communication
- Governance Communication
- Resilience Communication
- Mentoring
- Performance Feedback
- MSSP Service Delivery
- Service Level Agreements (SLAs)
- RACI Models
- 24x7 Operations
- Onboarding Workflows
- Transition Workflows
- Published Research
- Conference Speaking
- MITRE ATT&CK Contributions
- Media Commentary
- Industry Awards
- Law Enforcement Support
- Anton Piller Orders
- Expert Witness Testimony
- Regulatory Investigations
- Dark Web Monitoring
- Social Media Threat Monitoring
- Multilingual Capability
Location
- Remote-first
Work Type
- Remote
- Full-time
Experience Level
- Expert
- Senior
Education Level
- Bachelor’s degree in computer science, Information Security, or related field, or equivalent professional experience.
- CISSP (required)
- GCIH
- GCFA
- GCIA
- GX-FA
- GSE
- OSCP
- CISM
- CCSP
- EnCE
- CHFI
- ECIH
- AWS Security Specialty
- Azure Security Engineer
- Google Professional Cloud Security Engineer
Salary/Compensations
- $135,000-$157,500
- $180,000
Benefits
- Flexible sick and personal days
- Generous health plan with enhanced mental health resources and programs
- Professional development opportunities
- Education reimbursement up to $2,000 annually
- Maternity and parental leave top-up
- Employee referral bonus of $2,000
- Competitive salaries
- RRSP matching
- Bonus programs
- Distance remote working policy
- LinkedIn Learning access
- Service anniversary recognition
- Generous five-year milestone service awards
- President’s Club recognizing special achievement awards
- Spot rewards providing opportunities for instant peer recognition
About the Company
- Proudly Canadian cyber and AI services and solutions provider.
- Trusted by over 500 clients from SMB to global enterprise.
- Empower organizations to safeguard their most critical assets and adopt AI securely.
- Offerings include Cyber 360 and AI 360.
- Deliver a comprehensive range of governance, assurance, engineering protection, detection, and response services for the public and private sectors.
- Backed by over three decades of operational experience and a vast network of highly specialized and certified experts.
- Leverage cutting-edge technologies and AI to ensure clients achieve their privacy, security, and business goals.
- Recognized as a top employer for multiple years in a row.
- Hold the distinctions of Canada’s Top Small and Medium Employers 2025, Greater Toronto’s Top Employers 2025.
- Certified Great Place to Work 2026-2027.
- Operate in a remote-first environment.
- Office presence is typically less than 20% of the time.
- Office space located at Bloor and Islington is a collaborative space designed for in-person meetings and drop-ins.
- Enjoy hosting in-person quarterly townhalls and social events throughout the year to encourage teambuilding and collaboration.
- Lead with our 'Why': to make people feel safe.
- Embrace core values of Explore, Persevere, Adapt and Uplift.
Equal Opportunity
- ISA Cybersecurity is committed to providing accommodations for applicants with disabilities. If you require specific accommodation because of a disability or medical need, please inform ISAs Human Resources team (peopleoperations@e-isa.com) so arrangements can be made for appropriate accommodation to be in place during the recruitment process.
