About eSentire:
Founded in 2001 and headquartered in Waterloo, Ontario, eSentire is a global leader in eSentire, the Authority in Managed Detection and Response (MDR), protects the critical data and applications of 2000+ organizations in 80+ countries across 35 industries from known and unknown cyber threats by providing Exposure Management, Managed Detection and Response and Incident Response services designed to build an organization's cyber resilience & prevent business disruption. Founded in 2001, eSentire protects the world's most targeted organizations, with 65% of its global base recognized as critical infrastructure, vital to economic health and stability. By combining open XDR platform technology, 24/7 threat hunting, and proven security operations leadership, eSentire's award-winning MDR services and team of experts help organizations anticipate, withstand and recover from cyberattacks..
About the Role:
eSentire’s Security Operations Centre (SOC) organized into three specialized service delivery teams (Customer Excellence, Investigations, and Incident Response) working in close partnership with AI SOC Innovation, which builds and operates eSentire’s unified AI-first investigation platform. The SOC delivers services to customers worldwide on a 24x7 basis and is trusted by organizations globally to detect and respond to cyber threats and protect them from business disruption.
The Customer Excellence team is the primary frontline for eSentire’s customers. It provides 24x7 live support, runs escalations and outreach for complex or sensitive situations, and drives the enablement and QA programs that keep the SOC’s people, process, and tools continuously improving.
The Security Specialist is a senior individual contributor and a trusted expert. You are deeply technical, fully immersed in eSentire’s offerings, and quick to spot a process or tool that doesn’t work as efficiently or accurately as it could. Colleagues, customers, and partner teams count on your judgment.
You build the content and automated case playbooks that make the team faster, diagnose problems, and carry feedback to teams across eSentire. You also take part in live support, lead complex and sensitive escalations and named-resource engagements, and audit and coach on support quality. Specialists provide key support in escalated situations.
This role reports to a Security Lead or Security Manager
Responsibilities:
Responsibilities may evolve over time to meet changing business priorities and operational requirements.
Live support, complex escalations & named-resource engagements – 50%.
- Take part in live support, picking up the technical and high-impact cases that need your depth and acting as an expert resource for the shift.
- Lead complex or sensitive customer escalations and named-resource engagements as needed.
- Own escalated situations and high-stakes conversations, representing the SOC.
- Take handoffs from Senior Security Analysts when an escalation needs deeper expertise and explain why it moved so the next one is handled earlier.
- Contribute to After Action Reviews and RCAs for the escalations you led, including the underlying gaps and proposed fixes.
Content, playbooks & continuous improvement – 35%.
- Build and deliver content (training, knowledge base articles, guides) that improves customer support outcomes.
- Design automated case playbooks that speed up resolution and reduce touchpoints for customers, in partnership with SOC Innovation. Validate the content works for the people who use it and revise when it doesn’t.
- Perform high-level troubleshooting and diagnostic review to identify issues in services, tooling, and processes, and trace them to root cause.
- Work cross-functionally to report issues, shape and help develop new functionality, and confirm that fixes work in practice.
- Capture and share feedback within the SOC, with case references and evidence attached. Follow up so it is acknowledged and routed.
Quality audits & coaching – 15%.
- Audit customer support work for quality, response times, and interaction skills, using the team’s quality criteria.
- Coach analysts on what the audits show, in partnership with their Security Lead. The Lead keeps ownership of performance management, so share individual results and patterns with them.
- Turn patterns across audits into coaching focus areas, content, or process changes.
Standing expectations
These apply at every level of the Customer Excellence team.
- Hold the customer’s interest as the deciding factor in every judgment call.
- Work in lockstep with Technical Account Managers: share anything that affects the customer relationship early and stay aligned on what each of you is telling the customer.
- Keep case records and documentation accurate and current, so anyone can pick up the work without going back to the customer.
- Stay current on threats, eSentire’s detection coverage, SOC tooling, processes, and AI-driven capability as they evolve
Requirements:
- 7-10+ years’ experience in a Security Operations Centre (MDR or MSSP) or customer-facing security role, including leading escalations or complex case management.
- Advanced knowledge of adversary behaviour and the MITRE ATT&CK framework: you can map observed activity to techniques, explain the attack chain to a customer in plain language, and judge severity and likely next steps.
- Advanced knowledge of Windows internals and endpoint telemetry: process trees and parent/child relationships, services, scheduled tasks, registry, persistence mechanisms, credential access, lateral movement, and Windows event logs. Working knowledge of Linux and macOS endpoint behaviour.
- Hands-on investigation experience with EDR platforms (such as CrowdStrike, Microsoft Defender for Endpoint, SentinelOne, or equivalent), including interpreting detections, scoping activity across hosts, and knowing which response actions are safe to take and when.
- Hands-on experience with SIEM and log platforms (such as Splunk, Microsoft Sentinel, or equivalent), including writing and tuning queries (SPL, KQL, or similar) and regular expressions to validate a detection and scope an incident.
- Working knowledge of networking and network telemetry: TCP/IP, DNS, HTTP/S and TLS, plus proxy, firewall, and NDR or packet capture data, well enough to separate malicious traffic from benign.
- Working knowledge of cloud and identity security: Microsoft 365 and Entra ID, Active Directory, and AWS, Azure, or GCP audit logs. This includes authentication flows (SSO, MFA, Kerberos, OAuth) and common abuse patterns such as token theft, MFA fatigue, and business email compromise.
- Experience with email and phishing analysis: message headers, SPF/DKIM/DMARC results, and URL and attachment triage.
- Understanding of how detections are built and tuned, including the trade-off between false positives and false negatives. You can explain why a detection misfired and what would make it more accurate.
- Experience troubleshooting complex issues in security tooling and services, such as agent health, log ingestion gaps, integration or API failures, and tracing them to root cause. You can read JSON and API responses.
- Working knowledge of AI and LLM concepts in cybersecurity, with the ability to translate a process into clear decision logic (inputs, conditions, outputs, and failure cases) that another team can automate, and to build or use tooling that improves efficiency and supports security investigations.
- Experience applying responsible and ethical AI practices in security, including refining prompts and interpreting results to reduce bias and support objective conclusions, contributing to model training and validation, assessing when AI-generated conclusions are safe or need manual review, and identifying and communicating emerging AI risks (e.g., drift, adversarial inputs, inconsistent logic) while staying current on AI-powered threats and defensive capabilities.
- Experience auditing, coaching, or mentoring others, formally or informally.
- Experience building training, knowledge content, or documented procedures that other people use.
- Strong written and verbal communication skills, with the ability to lead sensitive conversations and drive escalated issues to resolution.
- Work scheduled shifts in a 24x7 operation, which can include nights, weekends, and holidays.
Preferred Requirements:
- Industry certifications (GCIH, GCFA, GX-FA, GCFR, GPEN, GEIR, etc.) or equivalent.
- Ability to read and write scripts for triage and analysis (PowerShell or Python, for example).
- Experience with digital forensics, malware triage, or sandbox analysis.
- Experience applying threat intelligence to investigations or detection improvement.
- Exposure to case automation, SOAR, or playbook design work.
- Experience maintaining a knowledge base or playbooks rooted in adult learning (andragogical) principles.
- Familiarity with MDR/XDR tooling.
This posting is for an existing vacancy
Compensation Range
The expected base salary range for this role is $96,000 – $120,000 CAD. This range is for the primary location for which the job is posted. Actual compensation may vary depending on location and job-related factors such as qualifications, experience, knowledge, skills, and internal equity.
Our Culture and Values
We celebrate diversity, operating with mutual respect and consideration, in an environment that fosters inclusivity for all. We believe that a variety of perspectives, backgrounds, and experiences make us stronger – if you’re enthusiastic about this opportunity but don’t meet every qualification, we encourage you to apply anyway. It takes a diverse set of thoughts, cultures, backgrounds, and perspectives to be a true market leader.
Total Rewards
We believe in rewarding performance and providing comprehensive benefits tailored to support your well-being. Our package includes:
- We reward strong performance through role-specific incentive programs, including either an annual bonus program or a competitive commission plan
- Competitive benefit program
- Paid parental leave
- Matching RRSP or 401K program
- Competitive employee referral bonus
Artificial Intelligence (AI) Notice:
As part of our recruitment process, eSentire may use Artificial Intelligence (AI) tools to assist recruiters with reviewing and summarizing application materials. All candidate evaluations and hiring decisions are made by members of our hiring team
Accommodation
If you have any accessibility requirements during the recruitment process, please reach out to our HR team at talentacquisition@esentire.com and any accommodation needs will be addressed upon request. Your talents and unique perspectives are valued, and we look forward to the opportunity to work together to build a more inclusive future.
It's our mission at eSentire to protect our customers 24/7/365 and we extend this conviction to job seekers. During the application and interview process, eSentire will communicate with you from one of our corporate "@esentire.com" email addresses, never from a public email address.