Senior Security Engineer - Detection & Response

EvenUpToronto, ON
CA$150,000 - CA$245,000Hybrid

About The Position

EvenUp is seeking a hands-on Senior Security Engineer to build its detection and response program from the ground up. This role involves designing and implementing telemetry pipelines, SIEM, detection content, and incident response capabilities. The focus is on detecting threats within the company's applications and data flows by partnering with engineering teams, treating detection as an engineering discipline. The company is a fast-growing vertical SaaS company backed by top VCs, aiming to close the justice gap using technology and AI.

Requirements

  • 5+ years in security operations, detection engineering, or incident response, including experience building a detection and response capability at a startup or high-growth technology company.
  • Hands-on experience implementing or significantly maturing a SIEM, including custom log sources and detection content.
  • Strong detection engineering skills: writing detections in Python, SQL, or a rules DSL, managing them in version control, and measuring their quality.
  • Real incident response experience — led investigations, written playbooks, and run retrospectives.
  • Experience with cloud-native telemetry (AWS/GCP/Azure control plane, identity providers, endpoint, SaaS audit logs).
  • Strong programming or automation skills (Python preferred); comfort building integrations and response automation.
  • Experience working with MDR/MSSP providers.

Nice To Haves

  • Experience partnering directly with software engineers to instrument applications for security visibility.
  • Familiarity with securing or monitoring AI/LLM-powered systems.
  • Relevant security certifications (GIAC/GCIA/GCIH, CISSP, etc.).

Responsibilities

  • Lead SIEM evaluation and implementation, design log ingestion and routing pipelines, and make deliberate cost/retention trade-offs.
  • Develop and tune detection content across cloud, identity, endpoint, SaaS, and application telemetry, with an emphasis on business-logic detections.
  • Partner with Engineering and DevOps to specify what applications and infrastructure must log for security visibility.
  • Build and maintain Incident Response (IR) playbooks and runbooks, coordinate response during security events, run tabletop exercises, and drive post-incident reviews.
  • Partner with internal teams to detect sensitive data moving where it shouldn't across applications, endpoints, and SaaS.
  • Define requirements for and direct managed detection partners, own escalation procedures, and continuously raise the bar on monitoring.

Benefits

  • Choice of medical, dental, and vision insurance plans for you and your family.
  • Additional insurance coverage options for life, accident, or critical illness.
  • Flexible paid time off, sick leave, short-term and long-term disability.
  • 10 US observed holidays, and Canadian statutory holidays by province.
  • A home office stipend.
  • 401(k) for US-based employees and RRSP for Canada-based employees.
  • Paid parental leave.
  • A local in-person meet-up program.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service