Title: Senior Cyber Security Specialist - Technology Group
Employee Working Location: Partially Virtual / Hybrid (Canada)
Employment Status: Permanent Full-time
The Canadian Red Cross (Red Cross) - an inspirational not for profit organization, helps people and communities in Canada and around the world in times of need and supports them in strengthening their resilience. As one of Canada's Best Employers 2026, we are committed to having an accessible, diverse, inclusive, and barrier-free work environment.
In this role, you will:
- Monitor, analyze, and respond to cybersecurity threats and security events across the organization using enterprise monitoring and detection capabilities.
- Lead cybersecurity incident investigation, containment, eradication, recovery, stakeholder coordination, and post-incident improvement activities.
- Administer and continuously improve Microsoft Sentinel SIEM, including data connectors, analytics rules, watchlists, automation playbooks, workbooks, dashboards, and threat detection use cases.
- Monitor and triage alerts from Microsoft Defender XDR, cloud, identity, endpoint, network, and other security technologies to identify malicious activity and reduce organizational risk.
- Administer, monitor, and optimize enterprise firewall and network security technologies, including firewall policies, security zones, network segmentation, NAT, VPN, IDS/IPS, access controls, rule reviews, and configuration management.
- Investigate and respond to network-based threats, intrusion attempts, malicious traffic, and security events identified through firewall, IDS/IPS, endpoint protection, and SIEM technologies.
- Administer and maintain Microsoft Defender for Office 365, Exchange Online Protection, and related email security capabilities to protect against phishing, malware, spoofing, and business email compromise.
- Develop and maintain email security policies, threat protection rules, block and allow lists, quarantine processes, secure mail routing, and domain protection controls including SPF, DKIM, and DMARC.
- Coordinate vulnerability management activities, including risk-based prioritization, remediation tracking, exception management, reporting, and validation of technical security controls.
- Support threat hunting, security architecture reviews, tabletop exercises, operational metrics, playbooks, lessons-learned reviews, and continuous improvement of cyber defence capabilities.
What we are looking for:
- A college diploma or university degree in Computer Science, Information Security, Information Technology, Cybersecurity, Engineering, or a related discipline, or an equivalent combination of education and experience.
- A minimum of 6 to 9 years of progressive cybersecurity experience, including significant experience in security operations, incident response, SIEM administration, threat management, network security, or cyber defence.
- Hands-on experience administering and optimizing Microsoft Sentinel SIEM, including analytics rules, automation workflows, workbooks, dashboards, data connectors, and detection use cases.
- Experience with Microsoft Defender XDR and related capabilities, including Defender for Endpoint, Defender for Identity,
- Defender for Office 365, Defender for Cloud Apps, and Defender for Cloud.
- Hands-on experience administering enterprise firewall platforms such as Palo Alto, Fortinet, Cisco, Check Point, or equivalent technologies, including policies, security zones, NAT, VPN, segmentation, access controls, and rule lifecycle management.
- Strong knowledge of network security principles, including TCP/IP, routing, switching, DNS security, IDS/IPS, secure remote access, network segmentation, and Zero Trust architectures.
- Experience administering Microsoft Defender for Office 365, Exchange Online Protection, Mimecast, Proofpoint, Barracuda, or equivalent email security platforms, including policies, quarantine, block and allow lists, and threat protection rules.
- Experience investigating phishing, business email compromise, spoofing, malware delivery, malicious network traffic, and other network- or email-borne threats.
- Knowledge of cybersecurity incident response, digital forensics, threat intelligence, evidence handling, vulnerability management, and email authentication technologies including SPF, DKIM, and DMARC; certifications such as CISSP, GCIH, GCIA, SC-200, AZ-500, Security+, PCNSA/PCNSE, etc.
- Fluency in English is required; French is an asset.
Working Conditions:
- Participation in an on-call cybersecurity incident response rotation may be required.
- Occasional work outside regular business hours may be required to support security incidents, investigations, maintenance activities, or emergency responses.
- Work involves managing multiple priorities and responding to rapidly evolving cybersecurity threats in a dynamic environment.
- Limited travel may be required for organizational meetings, training, emergency response support, or security-related activities.
- As we work with and support people and communities in Canada and around the world, applicants whose first language is not English may be required to perform the responsibilities of the role in English.
- Eligibility to work in Canada: At this time, we welcome applications from candidates eligible to work in Canada. If you are not a citizen or permanent resident of Canada, carefully review your visa to determine whether you are eligible to work in the role.
- If selected for this role, you will be required to complete a successful pre-employment screening process, including a satisfactory Enhanced Police Information Check (E-PIC).