Security Operations Analyst - Copperleaf
Job in
Toronto, Ontario, M5A, Canada
Listing for:
IFS
Full Time
position
Listed on 2026-01-12
Job specializations:
-
IT/Tech
Cybersecurity, Security Manager, Network Security
Job Description & How to Apply Below
Job Description About the Role:
IFS Canada is hiring a Security Operations Analyst to help defend a hybrid environment — with a mix of legacy on-prem infrastructure and growing cloud-native services across AWS and Azure.
This is a hands-on role within our Security Operations team. You'll be responsible for building and refining detection logic, responding to incidents, and coordinating vulnerability remediation efforts. The ideal candidate is comfortable navigating across endpoint, network, and cloud contexts — and is curious enough to chase down leads others might miss.
You’ll also play a key role in ensuring our security controls and practices support compliance with ISO 27001, SOC 2, and other regulatory frameworks.
Who We’re Looking For:
We're seeking someone who’s curious by nature and analytical by default — the kind of person who asks “what else is this connected to?” after every alert. You enjoy exploring how systems work, breaking things in test environments, and tinkering with new detection ideas.
While this role is primarily defensive, we welcome candidates with an interest in red teaming, adversary emulation, or purple team activities
. Over time, there’s potential to grow into a more proactive simulation-focused role — working with engineering teams to anticipate and test attacker behavior.
If you're passionate about building detections, breaking assumptions, and closing gaps
, you’ll thrive here.
Key Responsibilities:
Investigate and respond to alerts from SIEM, EDR, and cloud-native logging systemsCorrelate activity across identity, endpoint, network, and cloud data to detect threatsBuild, tune, and maintain detection logic using query languages and regular expressionsCreate and maintain investigation playbooks, detection documentation, and response templatesCoordinate vulnerability management activities
:
Work with IT and Dev Ops to validate, prioritize, and track remediation
Support compliance evidence collection for vulnerability closureTune endpoint, firewall, and DNS protections based on evolving threat intelligenceContribute to detection gap analysis, threat modeling, and internal red team exercisesAssist with enforcement of policies and evidence collection for ISO 27001/SOC 2 complianceRecommend improvements to logging, alerting, and monitoring pipelinesQualifications
Preferred Experience
2+ years in a SOC, detection engineering, or security analyst roleExperience working in a technology or SaaS company, ideally under ISO 27001 or SOC 2Familiarity with IAM, endpoint security, vulnerability management, and cloud loggingExperience writing detection logic in query-based systems (LEQL, SQL, regex, etc.)Exposure to AWS and/or Azure security tools (, IAM, Cloud Trail, Defender for Cloud)Scripting or automation knowledge in Power Shell, Bash, or Python is a plusMust-have
CompTIA Security+ or equivalent.Nice-to-have
ISC2 CC.Microsoft SC-900, AWS Security Specialist or CompTIA Network+.
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here: