Cybersecurity Incident Response Commander at ISA Cybersecurity | CA | Rezi

Cybersecurity Incident Response Commander at ISA Cybersecurity

Cybersecurity Incident Response Commander

ISA Cybersecurity · CA

Yesterday

Cybersecurity Incident Response Commander

ISA Cybersecurity · CA

a day ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

The Cybersecurity Incident Response (IR) Commander is the technical and operational authority for ISA Cybersecurity's Digital Forensics & Incident Response (DFIR) function, holding expert-level command of the Security Incident Response (SIR) service during client engagements. This role focuses on technical authority, judgment under pressure, and external-grade SME presence, rather than line management. The IR Commander leads the Response side of ISA's Protect-Detect-Respond model through influence, process ownership, and direct command on engagements. While people-leadership behaviors are valued, formal direct reports are not a requirement at hire. The role reports to the Senior Director, DFIR Services and requires extensive experience commanding ransomware, business email compromise, data exfiltration, and complex multi-vector engagements, with external recognition as a subject-matter expert in incident response and digital forensics.

Responsibilities

  • Serve as Incident Commander for all IR Retainer engagements and Emergency IRs delivered by ISA Cybersecurity.
  • Lead digital forensic investigations across endpoint, server, network, mobile, and cloud sources.
  • Ensure chain-of-custody discipline suitable for legal proceedings.
  • Develop, manage, and continuously refine DFIR processes, procedures, playbooks, and runbooks.
  • Conduct regular reviews and updates to DFIR people, processes, and technologies.
  • Present incident and digital evidence reports to key stakeholders including law enforcement, legal counsel, and clients.
  • Lead post-incident reporting and client walk-throughs and translate lessons learned into improvements.
  • Educate internal and external stakeholders on incident identification and response best practices.
  • Support presales activities including proposals, Statements of Work (SOWs), and RFP responses.
  • Own the technical quality of the DFIR practice in alignment with the Security Incident Response (SIR) service card.
  • Integrate threat intelligence into incident analysis and feed TTPs back into detection content and hunting hypotheses.
  • Identify, define, track, and report on DFIR metrics; run continuous-improvement cycles against them.
  • Lead and manage the IR readiness program including IR Plan engagements, Tabletop Exercises (TTX), and Playbook development and/or validation.
  • Serve as a senior client-facing voice during engagements and a trusted advisor.
  • Brief executives, boards, regulators, legal counsel, and law enforcement as required.
  • Represent ISA externally as a recognized DFIR subject matter expert.
  • Collaborate closely with SOC leadership, analysts, and Service Owners to ensure incident response integration.
  • Coach DFIR analysts and Incident Managers through technical authority, case-based pairing, and matrix influence.
  • Participate in hiring panels and rotation planning.

Requirements

  • 10+ years of progressive experience in cybersecurity, with at least 7 years in incident response and digital forensics roles.
  • Demonstrated experience as Incident Commander on multiple high-severity engagements (e.g., ransomware, BEC, APT intrusion, large-scale data breach).
  • Expert-level knowledge of the incident response lifecycle, containment and eradication strategies, and digital forensic methodologies.
  • Hands-on expertise across host, network, memory, mobile, and cloud forensics, including chain-of-custody discipline suitable for legal proceedings.
  • Proficient working with Windows, Linux, and MacOS.
  • Experience with multi-cloud forensics (AWS, Azure, GCP, Microsoft 365, Google Workspace) and SaaS-platform investigations.
  • Experience with OSINT (Open-Source Intelligence), including gathering and correlating publicly available information.
  • Working knowledge of multiple security control families such as EDR, SIEM, SOAR, NDR, identity, email security, DLP.
  • Deep familiarity with MITRE ATT&CK and current ransomware/APT TTPs.
  • Working knowledge of NIST SP 800-61, ISO 27035, ISO 27001:2022, NIST CSF, SOC 2, and CSA CCM.
  • Demonstrated ability to identify, define, track, and report on operational and service-quality metrics, and to run continuous-improvement cycles against them.
  • Excellent leadership-by-influence, executive communication, and stakeholder management skills.
  • Must be able to communicate clearly under pressure and to non-technical audiences.
  • Trusted advisor presence; ability to brief client executives and boards on cyber risk, governance, and resilience.
  • Bachelor’s degree in computer science, Information Security, or related field, or equivalent professional experience.
  • CISSP (required).
  • Willingness to participate in 24x7 on-call rotation for IR Retainers and Emergency IRs.
  • Ability to obtain Government of Canada security clearance.
  • Strong English language skills, written and verbal.
  • People leadership experience including coaching, mentoring, performance feedback, hiring panels.
  • Experience leading or contributing to MSSP service delivery including contractual SLAs, RACI models, 24x7 operations, and onboarding/transition workflows.
  • Recognized externally as a subject matter expert through published research, conference talks, MITRE ATT&CK contributions, media commentary, or industry awards.
  • Experience supporting law enforcement engagements (RCMP NC3, CCCS/CCIRC, FBI Cyber), Anton Piller orders, expert witness testimony, or regulatory investigations.
  • Experience with dark web monitoring and social-media threat monitoring.
  • Multilingual capability is an asset.

Skills

  • Incident Response
  • Digital Forensics
  • Ransomware Response
  • Business Email Compromise Response
  • Data Exfiltration Response
  • Endpoint Forensics
  • Server Forensics
  • Network Forensics
  • Mobile Forensics
  • Cloud Forensics
  • Chain-of-Custody
  • DFIR Process Development
  • DFIR Process Refinement
  • DFIR Playbook Development
  • DFIR Runbook Development
  • Threat Intelligence Integration
  • DFIR Metrics Tracking
  • IR Readiness Program Management
  • Tabletop Exercises (TTX)
  • Executive Briefings
  • Law Enforcement Briefings
  • Regulatory Briefings
  • External Subject Matter Expertise
  • SOC Integration
  • Coaching DFIR Analysts
  • Coaching Incident Managers
  • Hiring Panel Participation
  • Windows Forensics
  • Linux Forensics
  • MacOS Forensics
  • Multi-Cloud Forensics (AWS, Azure, GCP)
  • Microsoft 365 Forensics
  • Google Workspace Forensics
  • SaaS Platform Investigations
  • OSINT
  • EDR
  • SIEM
  • SOAR
  • NDR
  • Identity Security
  • Email Security
  • DLP
  • MITRE ATT&CK
  • NIST SP 800-61
  • ISO 27035
  • ISO 27001:2022
  • NIST CSF
  • SOC 2
  • CSA CCM
  • Leadership-by-Influence
  • Executive Communication
  • Stakeholder Management
  • Client Advisory
  • Cyber Risk Communication
  • Governance Communication
  • Resilience Communication
  • Mentoring
  • Performance Feedback
  • MSSP Service Delivery
  • Service Level Agreements (SLAs)
  • RACI Models
  • 24x7 Operations
  • Onboarding Workflows
  • Transition Workflows
  • Published Research
  • Conference Speaking
  • MITRE ATT&CK Contributions
  • Media Commentary
  • Industry Awards
  • Law Enforcement Support
  • Anton Piller Orders
  • Expert Witness Testimony
  • Regulatory Investigations
  • Dark Web Monitoring
  • Social Media Threat Monitoring
  • Multilingual Capability

Location

  • Remote-first

Work Type

  • Remote
  • Full-time

Experience Level

  • Expert
  • Senior

Education Level

  • Bachelor’s degree in computer science, Information Security, or related field, or equivalent professional experience.
  • CISSP (required)
  • GCIH
  • GCFA
  • GCIA
  • GX-FA
  • GSE
  • OSCP
  • CISM
  • CCSP
  • EnCE
  • CHFI
  • ECIH
  • AWS Security Specialty
  • Azure Security Engineer
  • Google Professional Cloud Security Engineer

Salary/Compensations

  • $135,000-$157,500
  • $180,000

Benefits

  • Flexible sick and personal days
  • Generous health plan with enhanced mental health resources and programs
  • Professional development opportunities
  • Education reimbursement up to $2,000 annually
  • Maternity and parental leave top-up
  • Employee referral bonus of $2,000
  • Competitive salaries
  • RRSP matching
  • Bonus programs
  • Distance remote working policy
  • LinkedIn Learning access
  • Service anniversary recognition
  • Generous five-year milestone service awards
  • President’s Club recognizing special achievement awards
  • Spot rewards providing opportunities for instant peer recognition

About the Company

  • Proudly Canadian cyber and AI services and solutions provider.
  • Trusted by over 500 clients from SMB to global enterprise.
  • Empower organizations to safeguard their most critical assets and adopt AI securely.
  • Offerings include Cyber 360 and AI 360.
  • Deliver a comprehensive range of governance, assurance, engineering protection, detection, and response services for the public and private sectors.
  • Backed by over three decades of operational experience and a vast network of highly specialized and certified experts.
  • Leverage cutting-edge technologies and AI to ensure clients achieve their privacy, security, and business goals.
  • Recognized as a top employer for multiple years in a row.
  • Hold the distinctions of Canada’s Top Small and Medium Employers 2025, Greater Toronto’s Top Employers 2025.
  • Certified Great Place to Work 2026-2027.
  • Operate in a remote-first environment.
  • Office presence is typically less than 20% of the time.
  • Office space located at Bloor and Islington is a collaborative space designed for in-person meetings and drop-ins.
  • Enjoy hosting in-person quarterly townhalls and social events throughout the year to encourage teambuilding and collaboration.
  • Lead with our 'Why': to make people feel safe.
  • Embrace core values of Explore, Persevere, Adapt and Uplift.

Equal Opportunity

  • ISA Cybersecurity is committed to providing accommodations for applicants with disabilities. If you require specific accommodation because of a disability or medical need, please inform ISAs Human Resources team (peopleoperations@e-isa.com) so arrangements can be made for appropriate accommodation to be in place during the recruitment process.