About The Position

We are currently seeking a Sr. Specialist, Adversary Detection, Cyber Threat Intelligence & Threat Hunting Lead to join our Cyber Defense & Incident Response team in Toronto, Ontario. Combining expertise in Adversary Detection, Cyber Threat Intelligence, and Threat Hunting, you will transform intelligence into proactive security controls and advanced detection capabilities. Working across corporate IT, cloud environments, identities, endpoints, applications, and operational technology environments, will help strengthen cyber resilience across our global operations. Reporting to the Senior Manager, Cyber Defense & Incident Response, this role serves as the technical cornerstone of our Cyber Defense program. You will be responsible for ensuring our organization can identify, detect, and respond to adversarial activity before it impacts business operations.

Requirements

  • Minimum 8 years of cybersecurity experience with significant expertise in one or more of the following domains: Adversary Detection, Threat Hunting, Cyber Threat Intelligence, Security Operations.
  • Experience supporting enterprise or critical infrastructure environments.
  • Proven hands-on experience developing SIEM, XDR, EDR, or detection content.
  • Experience operationalizing cyber threat intelligence and converting intelligence into defensive actions.
  • Demonstrated experience conducting structured, hypothesis-driven threat hunting activities.
  • Experience working with managed detection and response providers and security operations teams.
  • Undergraduate degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related discipline.
  • Strong knowledge of MITRE ATT&CK, adversary emulation, threat modeling, and detection engineering.
  • Experience with Cortex XDR, Microsoft Sentinel, Splunk, or equivalent security platforms.
  • Understanding modern attack techniques targeting cloud, identity, endpoint, and enterprise environments.
  • Ability to analyze threat intelligence from structured and unstructured sources.
  • Strong analytical and investigative skills with a proactive, hypothesis-driven mindset.
  • Excellent written and verbal communication skills.
  • Ability to communicate technical findings effectively to both technical and business audiences.
  • Highly organized with strong documentation and reporting discipline.

Nice To Haves

  • GIAC certifications such as GCTI, GDAT, GCIA, or GCIH.
  • Palo Alto Networks XDR or XSIAM certifications.
  • FOR578 Cyber Threat Intelligence training or equivalent.
  • Experience in mining, energy, utilities, manufacturing, or other critical infrastructure sectors.
  • Familiarity with OT/ICS cybersecurity environments.
  • Experience with Python, PowerShell, XSOAR/XSIAM automation, OpenCTI, MISP, or similar platforms.

Responsibilities

  • Develop, test, and deploy advanced detection content mapped to MITRE ATT&CK techniques relevant to mining and critical infrastructure threats.
  • Continuously tune and optimize detection logic to improve effectiveness and reduce false positives.
  • Build and maintain a comprehensive detection catalog, including ATT&CK mappings, data sources, confidence levels, and review cycles.
  • Collaborate with Security Operations teams to design and improve investigation playbooks and response procedures.
  • Review managed detection and response (MDR) provider outputs, identify coverage gaps, and drive improvements in detection quality and performance.
  • Establish and maintain detection engineering standards, documentation, testing methodologies, and operational processes.
  • Consume, analyze, and operationalize threat intelligence from industry, government, commercial, and open-source sources.
  • Produce regular threat intelligence reporting highlighting emerging threats, adversary activity, exploited vulnerabilities, and recommended defensive actions.
  • Maintain detailed adversary profiles focused on actors targeting mining, critical infrastructure, energy, and global industrial organizations.
  • Translate intelligence findings into actionable detections, threat hunts, risk advisories, and executive briefings.
  • Manage and optimize threat intelligence feeds integrated with security monitoring and XDR platforms.
  • Design and execute hypothesis-driven threat hunting campaigns using frameworks such as MITRE ATT&CK and the Diamond Model.
  • Identify malicious behaviors and attack techniques that may not be detected through automated controls.
  • Develop new detection logic and analytical techniques based on hunting results.
  • Partner with MDR providers and internal stakeholders on collaborative hunting initiatives and security investigations.
  • Maintain comprehensive hunting documentation, findings, lessons learned, and recommendations.
  • Act as the primary technical liaison for the MDR provider's detection and threat hunting capabilities.
  • Participate in operational reviews focused on detection coverage, false positive reduction, hunt outcomes, and emerging threats.
  • Maintain and prioritize detection enhancement roadmaps and coverage gap remediation plans.
  • Contribute to the ongoing maturity and effectiveness of the Cyber Defense program.
  • Promote best practices, continuous improvement, and knowledge sharing across cybersecurity teams.

Benefits

  • Competitive compensation including a variable annual incentive plan
  • Participation in a competitive Defined Contribution Pension package
  • Comprehensive benefits package (company paid core coverage, health and dental coverage, flex accounts, disability plans, and optional insurances)
  • Leave for all of life’s reasons (vacation, personal, sick, parental)
  • Work culture dedicated to safety, diversity & inclusion, and career growth
  • Employee Family Assistance Program
  • Virtual Healthcare online
  • Online training and career development opportunities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service