Information Security Specialist ( Attack Surface Reduction)

TDToronto, ON
CA$96,900 - CA$136,800Onsite

About The Position

This role focuses on Attack Surface Reduction (ASR) within the Information Security domain. The specialist will be responsible for hunting threats, identifying vulnerabilities, and recommending mitigations to reduce the bank's overall attack surface. This involves analyzing internal and external intelligence, participating in ASR operations in enterprise and cloud environments, and developing advanced methodologies to detect adversary tools, techniques, and procedures. The role requires producing metrics, tuning detection infrastructure, and documenting best practices. The specialist will act as a subject matter expert for host-based and network-based analysis, collaborating with various security teams and influencing the organization's security culture.

Requirements

  • Bachelor's Degree/Master's degree (preferred) in an IT/Cyber-related field or equivalent experience.
  • At least 7+ years of cyber security experience.
  • 3+ years of experience in a malware reverse engineering, threat hunting, DFIR, threat detection or threat intelligence position (preferred).
  • Expert knowledge of log management, security analytics and event management platform mechanics.
  • Experienced with SIEM, SOAR, EDR, cloud-native tools, and other cyber security tool sets.
  • Advanced knowledge of Endpoint & Identity/IAM architectures, operations, and investigations; cloud hunting experience is preferred.
  • Displayed proficiency in Security Incident & Event Management and Endpoint Detection & Response tooling; Splunk ES, CrowdStrike, Logscale, Defender for Endpoint (MDE)/ MS Sentinel, Wiz Defend.
  • Deep understanding of coding/scripting and APIs in support of investigations, localized automation, and integrations; Python experience a plus.
  • Must be able to identify and generate detection logic to enhance the enterprises defensibility.
  • Hands on experience with writing and implementing complex analytics queries, threat visualization dashboards, and large data volume analysis (e.g. Splunk, Logscale, KQL, syslog, etc.).
  • Strong working knowledge of security-relevant data, including network protocols, ports and common services, such as TCP/IP network protocols and application layer protocols (e.g. HTTP/S, DNS, FTP, SMTP, Active Directory, etc.).
  • Extensive knowledge of Windows, Mac and Linux-based endpoints including operating systems, services, file systems, and agents.
  • Excellent written and oral communication skills.
  • Organizational and self-directing skills.
  • Ability to initiate, coordinate and prioritize responsibilities and follow through on tasks to completion.
  • Ability to work independently on a variety of assignments with minimal supervision.

Nice To Haves

  • Master's degree in an IT/Cyber-related field.
  • 3+ years of experience in a malware reverse engineering, threat hunting, DFIR, threat detection or threat intelligence position.
  • Cloud hunting experience.
  • Netskope, Akamai, AppOmni, Qualys & Symantec DLP experience.
  • Python experience.
  • Obtained at least 2 of the certifications from the following lists: General Cyber certs (CISSP, CISM, CASP+, CEH, GSEC, GCIH, GCIA, GMON), Endpoint / Forensic certs (GREM, GCFE, GCFA, CHFI, CCFE, CFCE, EnCE), Cloud certs (CCSP, CCSK, GCP, AWS, Cloud+, MS Azure Associate or Solutions Architect Expert), Pen-testing certs (GPEN, CPENT, eCPPT, OSCP, OSCE), Coding/Scripting/SIEM certs (SPLUNK and/or KQL Certification, Scripting/Python certificate).

Responsibilities

  • Hunt on TTPs, threats/risks and/or vulnerabilities aligned to the MITRE Att3ck framework based on both internal and external intelligence data.
  • Proactively identify possible threats, risks or security control gaps to the enterprise and produce detection & mitigation recommendations to reduce the overall Attack Surface for the bank.
  • Participate in proactive ASR operations within the enterprise and cloud using threat intelligence, analysis of anomalous log data and results of brainstorming sessions to detect and mitigate threats.
  • Develop advanced methodologies to identify threat adversary tools, techniques, and procedures.
  • Produce metrics and develop dashboards to identify potential threats, suspicious/anomalous activity, malware, etc.
  • Drive the tuning of detection infrastructure with technology teams to identify emerging threats.
  • Document best practices to enhance hunting playbooks, procedures, and courses of action.
  • Act as a subject matter expert for hunting via host-based and network-based analysis and will work cross-functionally with their peers on other teams such as intelligence, SOC analysts, IR team, and security engineering.
  • Proactively review internal processes and activities and identify opportunities for improvement.
  • Influence behavior to reduce risk and foster a strong information security management culture throughout the enterprise.
  • Remain informed of emerging issues, industry trends and/or relevant changes to the security landscape.

Benefits

  • Base salary
  • Variable compensation
  • Health and well-being benefits
  • Savings and retirement programs
  • Paid time off
  • Banking benefits and discounts
  • Career development
  • Reward and recognition programs
  • Training programs
  • Competitive benefits plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service