Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Head of Cyber Defence & Incident Response

Full-time

Quadient

At Quadient , we support businesses of all sizes in their digital transformation and growth journey, unlocking operational efficiency with reliable, secure, and sustainable automation processes.

Our success in delivering innovation and business growth is inspired by the connections our diverse teams create every day, with our clients and each other.

It’s these connections that make Quadient such an exceptional place to grow your career, develop your skills and make a real impact – help our future-focused business lead the way in powering secure and sustainable business connections through digital and physical channels.

Job Description

  • Location: Qaudient offices, Markham Ontario, Canada or Eastern USA (EST Time zone)
  • The Head of Cyber Defence and Incident Response owns the organisation’s cyber defence capability across a hybrid environment (mix of on‑prem and cloud platforms), ensuring effective monitoring, detection, response and recovery.
  • Reports directly to the CISO and leads cyber defence operations (including the MSSP) and cybersecurity incident response across the organisation. This fits within the context of the broader organizational Crisis Management plan owned outside Technology.
  • A key focus is optimising security tooling (e.g., SIEM, SOAR, EDR/XDR, NDR, email security, vulnerability scanning) and driving strong vulnerability and threat management, using threat intelligence to prioritise defensive improvements.

Key Responsibilities

  • Own the incident response lifecycle (prepare, detect, analyse, contain, eradicate, recover), ensuring playbooks, tooling, and decision-making processes are in place and exercised.
  • Lead and coordinate response to security incidents, acting as incident commander where required, including stakeholder communications, forensic triage, and recovery coordination.
  • Manage the MSSP relationship end‑to‑end: service definition, SLAs/KPIs, escalation paths, continuous improvement plans, quality assurance, and commercial governance.
  • Optimise security monitoring and response tooling working across technology teams (e.g., SIEM, SOAR, EDR/XDR, NDR, email security) including use‑case coverage, alert quality, automation, logging strategy, and operational runbooks.
  • Own the vulnerability management programme (on‑prem and cloud), including scanning coverage, prioritisation, remediation SLAs, exception handling, verification, and executive reporting.
  • Drive threat management by operationalising threat intelligence (internal and external) into defensive priorities: detection use cases, hardening actions, control uplift and proactive hunting themes.
  • Lead continuous improvement of the defence stack: rationalise tools, tune detections, improve signal quality, reduce noise, and expand automation to accelerate triage and response.
  • Establish and run a threat hunting programme using hypothesis‑driven approaches, telemetry coverage mapping, and lessons learned from incidents and red-team activity.
  • Run regular tabletop exercises and simulations (including ransomware and cloud compromise scenarios), ensuring roles, escalation paths, and technical procedures are validated and improved.Own incident response governance: severity model, on‑call and escalation processes, evidence handling, case management, and alignment to legal/regulatory obligations.
  • Define and report cyber defence metrics (e.g., MTTD/MTTR, alert volumes and precision, incident trends, vuln remediation performance, control coverage), presenting insights and recommendations to senior leadership.
  • Lead post-incident reviews and root cause analysis, ensuring lessons learned translate into measurable improvements (detections, hardening, identity controls, backups, segmentation, and training).
  • Support business continuity and crisis management processes during cyber events, contributing to executive updates and coordinated communications with Legal/Privacy and other stakeholders.
  • Maintain and improve incident response documentation and readiness (playbooks, runbooks, contact trees), and ensure training is delivered for technical responders and business stakehol
  • Communicate cyber risk and active incidents clearly to technical and non‑technical audiences, including concise executive briefings and after‑action summaries.

Qualifications

  • Strong experience leading cyber defence/SOC and incident response, including major incident coordination, investigation, containment and recovery.
  • Hands-on understanding of detection and response tooling and concepts (SIEM, SOAR, EDR/XDR, NDR, email security, log pipelines), including tuning, use-case engineering and operational workflows.
  • Proven experience managing an MSSP or outsourced SOC capability, including SLAs/KPIs, service governance, escalations, and continuous improvement.
  • Strong experience running vulnerability management and threat management programmes, including prioritisation based on exploitability, exposure, and business impact.
  • Knowledge of incident response processes, digital forensics fundamentals, evidence handling, and working with legal/privacy and external forensic partners.
  • Experience defending hybrid environments (on‑prem and cloud), including identity signals, network telemetry, endpoint visibility, and cloud-native security monitoring.
  • Ability to operate under pressure and lead cross-functional teams through high-severity incidents, communicating clearly and making timely risk-based decisions.
  • Fluent in English – excellent written and verbal communication skills, including producing clear architecture guidance, standards, and security design documentation.

Desirable

  • Certifications such as GCIH, GCIA, GNFA, CISSP, CISM, or equivalent experience in incident response and security operations.
  • Experience with threat hunting, purple teaming, and using MITRE ATT&CK to structure detections, gaps analysis, and defensive improvements.
  • Experience with security operations in cloud platforms and common tools (e.g., Microsoft Defender, Sentinel, Splunk, CrowdStrike, Palo Alto, AWS/Azure security services) and integrating telemetry across environments.
  • Calm under pressure, able to lead effectively during incidents and make timely decisions with incomplete information.
  • Highly collaborative, able to coordinate across IT, engineering, legal/privacy, and business leaders during investigations and recovery.
  • Operationally rigorous with strong attention to detail, documentation and evidence quality (case notes, timelines, lessons learned).
  • Continuous improvement mindset—drives measurable outcomes through tooling optimisation, process refinement, and coaching teams to improve security hygiene.

Additional Information

See Full Job description

Rewards & Benefits

  • Flexible Work: Embrace a hybrid work model blending office and remote setup for a balanced lifestyle.
  • Endless Learning: Access global opportunities for growth through our 24/7 online learning platform.
  • Inclusive Community: Join our Empowered Communities and engage in our Philanthropy program.
  • Comprehensive Rewards: Enjoy competitive Total Rewards covering wellness, work/life balance, and more, including a generous referral scheme.
  • Caring for Wellbeing: Access our complimentary employee assistance program for mental health support.

Smart Work at Quadient

At Quadient, our Smart Work approach fosters connection, collaboration, and innovation while offering flexibility based on role requirements. Whether on-site, hybrid, or remote, our work environments are designed to support productivity and engagement. Hybrid employees balance remote and in-office work, on-site roles contribute daily to our vibrant workplace culture, and remote employees stay connected through virtual collaboration and in-person events. No matter where you work, you’ll be part of a dynamic, people-first community that drives success together.

Be yourself at Quadient

Our values define how we work as a team: Empowerment, Passion, Inspiration and Community. They inspire us to be EPIC. Together. What makes Quadient different is how different we are. We’re a team of individuals with one goal but many perspectives. When you connect with Quadient, you become part of a community that cares - in a culture that embraces differences and values every voice.

We will consider any reasonable modifications to the interview process. If you require any assistance with the application process, please email us at ***email_hidden***

Quadient is an Equal Employment Opportunity Employer. *: We firmly believe in zero discrimination in employment on any basis, including race, color, religion, sex, national origin, age, disability, veteran or military status, genetic information, citizenship status, and any other characteristics protected by local, state, or federal law.

People. Connected.

Vacancy posted 11 days ago
Similar jobs that could be interesting for youBased on the Head of Cyber Defence & Incident Response in Markham, ON vacancy
  •  ...channels. Job Description Location: Qaudient offices, Markham Ontario, Canada or Eastern USA (EST Time zone) The Head of Cyber Defence and Incident Response owns the organisation’s cyber defence capability across a hybrid environment (mix of on‑prem and cloud... 
    Suggested
    Full time
    Work at office
    Local area
    Remote work
    Flexible hours

    Quadient

    Markham, ON
    11 days ago
  • $150k - $170k per year

     ...seeking a Director, Information Security & Cyber Risk to lead and operationalize our global security program. This role is responsible for executing CarltonOne’s security...  ...access controls, encryption standards, and incident response processes. Coordinate application security... 
    Suggested
    Work at office

    CarltonOne

    Markham, ON
    19 days ago
  • $75 per hour

     ...Markham area, and they are looking to add to their team an interim Head of Accounting & Finance for an initial term of 3 months. ***...  ...etc. As the Interim Head of Accounting & Finance, you will be responsible for both doing hands on accounting/reporting/etc. work and... 
    Suggested
    Contract work
    Interim role
    Work at office
    Markham, ON
    a month ago
  •  ...Job Responsibility: Who We Are BGIS is a leading provider of customized...  ...physical security related incidents, issues, questions, or concerns...  ...Knowledge of information and cyber security principles and...  ...communications. Must be dependable, responsive, customer-focused and possess... 
    Suggested
    Full time
    For contractors
    Work at office

    BGIS

    Markham, ON
    1 day ago
  •  ...Sprinkler Technician – Fire Protection is responsible for inspection, testing, maintenance, and...  ...Diagnoses issues with sprinkler heads, piping, valves, backflow preventers, and...  ...activation, system failures, and water-related incidents. Compliance & Code Assurance Ensures... 
    Suggested
    Hourly pay
    Remplacement
    Full time

    BGIS

    Markham, ON
    2 days ago
  • $105k - $115k per year

     ...Opportunity The Corporate Security Manager is responsible for providing physical security...  ...position will be based out of the Aviva Head Office, located in Markham, Ontario, with...  ...Demonstrated experience managing security incidents and leading complex investigations into physical... 
    Full time
    Internship
    Work at office
    Local area
    Flexible hours

    Aviva

    Markham, ON
    1 day ago
  • $45k - $55k per year

     ...supported after move-in. Key Responsibilities Act as the primary point...  ...steps Ensure a 24-hour response time commitment to all homeowner...  ...records of all on-site incidents reported by homeowners at our...  ...site teams, tradespeople, and head office staff to ensure homeowner... 
    Full time
    Work at office

    JD Development Group

    Markham, ON
    4 days ago
  •  ...the Quality and Risk Consultant will lead prevention and responses to resident safety incidents and support risk management and issue management. This...  ...Work in partnership with operational leaders and other head office leads in advancing safety culture across the organization... 
    Long term contract
    Remplacement
    Full time
    Internship
    Work at office

    Extendicare

    Markham, ON
    1 day ago
  • $40k per year

     ...across Windows OS, MS 365 platform, Active Directory, foundation of cyber security skills and practices, understanding of service KPIs...  ...trust and rapport What makes you stand out Familiarity with incident management processes and procedures is beneficial but not a... 
    Internship
    Remote work
    Flexible hours

    Aviva

    Markham, ON
    9 days ago
  • $83.14k - $98.73k per year

     ...The primary responsibility of the Security Engineer is to manage the day-to-day support for data systems, ensuring all systems function optimally...  ...support business operations. This role involves coordinating cyber security support across all platforms, troubleshooting and... 
    Casual work
    Work at office
    1 day per week

    Honda Canada Inc.

    Markham, ON
    18 days ago
  • $58.8k per year

     ...to Team Leader, Claims Services; the Bodily Injury Analyst is responsible for the handling of bodily injury tort claims in Alberta. This...  ...to deal with non-represented claimants as well as plaintiff and Defence Counsel on a regular basis. Investigates claims regarding liability... 
    Work at office
    Work from home
    Night shift

    TD Bank

    Markham, ON
    6 days ago
  •  .... This position will be based at our Head Office in Markham, Ontario. Extendicare...  ...offers a hybrid working environment. Key Responsibilities Include Manage general ledger...  ...analyzing resumes, or assessing candidate responses. These tools assist our recruitment team... 
    Long term contract
    Remplacement
    Full time
    Internship
    Work at office

    Extendicare

    Markham, ON
    8 days ago
  •  ...you want to be part of an iconic American brand, and help lead the way for where we’re headed, we’d love to have you join us. About the role As the General Manager, you are responsible for leading your team to deliver a profitable store business plan. You ensure your... 
    Full time
    Work at office
    Flexible hours
    Night shift

    Gap

    Markham, ON
    6 days ago
  •  ...management leadership position. The successful candidate will be responsible for driving new customer acquisition, developing strategic...  ...· Engage with hospital administrators, CIOs, CEOs, Operations Heads, Patient Experience Leaders, and Digital Transformation teams.... 
    Long term contract
    Full time
    Contract work

    Cancard Inc.

    Markham, ON
    12 days ago
  •  ..., and setting the tone for their experience, Receptionists are responsible for providing exceptional customer service while upholding a high...  ...This includes recognizing health and safety hazards, reporting incidents, fulfilling responsibilities under the applicable legislation,... 
    Work at office

    Verve Senior Living

    Markham, ON
    6 days ago
  • $23.18 per hour

     ...GardaWorld Postal code L6G 0G1 Uniform provided at no cost Responsibilities for Surveillance Security Guard Monitor security systems to detect any suspicious activity Respond quickly to incidents or potential threats Document observed events and incidents,... 
    Hourly pay
    Casual work
    Flexible hours
    Shift work

    GardaWorld

    Markham, ON
    10 hours ago
  •  ...Job Responsibility: Vice President Finance Founded in 1999, the St Regis Group has grown steadily to become the premier supplier for awards...  ...It should be noted this is an ‘in office' role at our Markham head office. The successful candidate will be responsible for... 
    Long term contract
    Permanent employment
    Full time
    Casual work
    Work at office
    Monday to friday
    Shift work

    St. Regis Group

    Markham, ON
    1 day ago
  • $74.1k - $114.3k per year

     ...not for an existing vacancy within the organization and is open to new applications. (New Head Count) The Manager, Consumer Intelligence Specialist is a senior researcher responsible for delivering the consumer, competitive, market, and dealer understanding that powers... 
    Full time
    Local area
    Work from home

    General Motors

    Markham, ON
    3 days ago
  •  ...Job Responsibility: The Organization Sentient HR aims to enrich lives through the power of connections. Sentient specializes in Supply Staffing...  ...to issues that arise and is a confidant to the Division Head. This role demands a high competency in analyzing and making... 
    Permanent employment
    Full time
    Temporary work
    Work at office
    Shift work

    Sentient HR Services Inc.

    Markham, ON
    1 day ago
  • $50k - $60k per year

     ...reports to Accounts Payable Specialist / Project Accountant. Key Responsibilities Invoice Processing & Data Entry Receive, sort, and date-...  ...Route invoices to appropriate project managers or department heads for approval Follow up on outstanding invoice approvals to... 
    Full time
    For subcontractor
    Internship
    Work at office

    JD Development Group

    Markham, ON
    4 days ago
  • $73.9k - $110.9k per year

     ...within the organization and is open to new applications. (New Head Count) AI Disclosure As part of the application process, Artificial...  ...with ZERO Crashes, ZERO Emissions, and ZERO Congestion. Key Responsibilities Deliver high-quality software solutions for Software Defined... 
    Full time

    General Motors

    Markham, ON
    22 days ago
  • $60k per year

     ...Scheduling  Location : Markham, ON (Head Office)  Salary : $60,000 annually, full...  ...to high-quality patient care.  Key Responsibilities:   Coordinate daily staffing schedules...  ...experience to both clients and staff through responsive and professional communication... 
    Long term contract
    Full time
    Work at office
    Monday to friday
    Shift work

    RhynoCare

    Markham, ON
    26 days ago
  • $18.5 per hour

     ...rooms, office, cafeterias, boardrooms and Executive offices. Responsibilities ~ Clean offices, washrooms, locker rooms, office, cafeterias...  ...and report any Environmental, Health & Safety hazards, incidents and concerns to the immediate supervisor/manager. Management will... 
    Hourly pay
    Permanent employment
    Contract work
    Work at office
    Immediate start
    Shift work
    Rotating shift

    Giesecke+Devrient

    Markham, ON
    24 days ago
  •  .... This position will be based at our Head Office in Markham, Ontario. Extendicare...  ...offers a hybrid working environment. Key Responsibilities Include Manage general ledger...  ...analyzing resumes, or assessing candidate responses. These tools assist our recruitment team... 
    Long term contract
    Full time
    Internship
    Work at office

    Extendicare

    Markham, ON
    1 day ago
  •  ...initiatives. This position will be based at our Head Office in Markham, Ontario. Extendicare...  ...a hybrid working environment. Key Responsibilities Include Provide coordination and...  ...analyzing resumes, or assessing candidate responses. These tools assist our recruitment team... 
    Long term contract
    Remplacement
    Full time
    Internship
    Work at office

    Extendicare

    Markham, ON
    16 days ago
  •  ...will collaborate with technical teams, leaders, vendors, and stakeholders to identify risks, implement security solutions, support incident response activities, and help foster a strong culture of cybersecurity. Key Responsibilities Lead and support the end-to-end... 
    Monday to friday

    Oak Valley Health

    Markham, ON
    8 days ago
  • $21.42 per hour

     ...visitors, staff, and community members. Responsibilities Leadership & Scheduling Supervise...  ...daily security administration and incident documentation Track and coordinate security...  ...development within the team Incident Response Serve as the primary point of contact... 
    Daily paid
    Full time
    Immediate start
    Shift work

    Classet

    Markham, ON
    16 days ago
  •  ...vacancy within the organisation and is open to new applications (New Head Count) AI Disclosure: As part of the application...  ...Crashes, Zero Emissions and Zero Congestion and we embrace the responsibility to lead the change that will make our world better, safer and more... 
    Full time
    Work at office
    Local area
    Work from home

    General Motors

    Markham, ON
    4 days ago
  • $21 - $24 per hour

     ...2026 Schedule: Monday to Saturday, 8:30AM - 4:30PM Key Responsibilities Coordinate and oversee diverse daily activities, creating an...  ...to maintain a positive and engaging environment. Complete incident reports in Microsoft Teams within 24 hours as per regional requirements... 
    Hourly pay
    Daily paid
    Full time
    Part time
    Work from home
    Flexible hours

    Monarch House

    Markham, ON
    4 days ago
  • $17.6 per hour

     ...and thorough record-keeping (Memo book, incident reports, etc.) Keen observation and attentiveness...  ...exceptional judgment Job Duties and Responsibilities Provide outstanding and personalized...  ...emergency protocols are completed in response to Fire Alarms and other Site... 
    Hourly pay
    Full time
    Work at office
    Trial period
    Night shift
    Weekend work
    Afternoon shift

    Regal Security Inc.

    Markham, ON
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Head of Cyber Defence & Incident Response. Be the first to apply!