nesto Logo

nesto

Senior Cyber Defence Analyst

Posted 6 Days Ago
Be an Early Applicant
Remote
Hiring Remotely in Canada
Senior level
Remote
Hiring Remotely in Canada
Senior level
Leads cyber defense investigations from triage through remediation, conducts threat hunting, and develops detections, dashboards, playbooks, and SIEM/SOAR workflows. Secures Azure, GCP, Microsoft 365, endpoints, containers, CI/CD pipelines, and cloud-native applications. Partners with engineering teams, consumes threat intelligence, supports purple-team exercises, validates red-team coverage, and evaluates AI/ML tools for detection and alert triage.
The summary above was generated by AI
About Us

Nesto Cloud is Canada's cloud-native and AI driven, end-to-end mortgage technology platform, helping financial institutions modernize lending through AI intelligent automation, AI & Cloud proprietary technology, and business process outsourcing (BPO) solutions.

Powered by the Nesto Group ecosystem, we transform decades of mortgage expertise into cutting-edge technology that reduces mortgage operation costs, accelerates lending, strengthens compliance, and delivers exceptional experiences for lenders and borrowers alike.

Nesto Group

Nesto Group is Canada's leading provider of mortgage technology and financing solutions, with more than CAD $80 billion in residential and commercial mortgages under administration. Trusted by many of the country's leading financial institutions, we combine over 50 years of mortgage expertise with proprietary cloud and AI technology to transform the future of lending.

Powered by our proprietary cloud and AI technology, nesto has become one of Canada's fastest-growing mortgage lenders, gaining market share across direct-to-consumer (D2C) residential lending, the broker channel, and multi-family commercial lending. Recognized as one of Deloitte's Fast 50 companies for three consecutive years, we continue to push the industry forward through innovation, technology, and customer-focused solutions.

Operating through our family of brands—CMLS, nesto, and Nesto Cloud—our mission is to build Canada's mortgage ecosystem of the future and create a true Canadian champion in lending technology and financial services. Learn more at: https://nestogroup.ca/   

Life at Nesto Cloud

At Nesto Cloud, you'll build the future of lending alongside some of the country's top developers, AI engineers, and mortgage experts. You'll work with a modern tech stack and AI-driven development frameworks designed to help you innovate, grow your skills, and accelerate your career.

About the team

We're looking for a Senior Cyber Defence Analyst reporting to the Cyber Defence Director. This role is ideal for someone who thrives on hands-on investigation, detection engineering, and building innovative AI-driven defence capabilities in a 100% cloud, dev-centric environment. You'll collaborate within the Cyber Defence team to shape how we leverage AI and ML to defend against an increasingly AI-enabled threat landscape, experimenting with new detection approaches, building AI-augmented investigations, and staying ahead of adversaries doing the same.


What you'd be accomplishing in that role :

  • Lead triage-to-remediation on critical/high investigations
  • Conduct proactive threat hunts; operationalize findings into detections and playbooks
  • Operate and optimize Google SecOps SIEM, SOAR and SentinelOne, building detection content, dashboards, and playbooks
  • Design, code, and deploy detection rules across cloud, endpoint, application layers with minimal false positive rate
  • Implement Blue Team coverage beyond endpoints/servers into cloud infrastructure (Azure, GCP), MS365/Entra ID, containers, CI/CD pipelines, and application layers
  • Tune existing detections, close coverage gaps; maintain detection knowledge base
  • Partner with DevOps/engineering teams to embed detection and response capability into cloud-native and application architectures
  • Consume threat intelligence (IOCs, TTPs) and translate into hunts and detections
  • Participate in purple team exercises; document findings and build detections from gaps
  • Validate detection coverage against Red Team scenarios
  • Evaluate and pilot AI/ML tools for detection augmentation, anomaly detection, alert triage
  • Implement selected tools into SIEM/SOAR workflows; measure effectiveness

Who we are looking for :

  • 7+ years of experience in a SOC / Cyber Defence / Blue Team role, with demonstrated seniority in investigations
  • Strong hands-on experience with SOAR, SIEM data ingestion, use case development, and tuning
  • Proven threat hunting and threat intelligence experience
  • Experience with sandboxing / malware analysis tools
  • Deep experience securing cloud environments (Azure, GCP) and MS365/Entra and endpoint/server security
  • Hands-on experience with Google SecOps SIEM and SentinelOne or equivalent technologies.
  • Experience defending application/dev-centric environments (containers, CI/CD, cloud-native apps) in addition to traditional endpoint/server defence
  • Purple teaming experience
  • Familiarity with using AI/ML tools for defensive security, and awareness of emerging AI-driven attack techniques
  • Relevant certifications (GCIA, GCIH, GCFA, GCTI, CySA+, OSCP, or Azure/GCP security certs) are an additional plus.
  • Scripting/automation experience (Python, SOAR platforms) is a strong plus
  •  **English is required for writing and documentation. French speaking and reading is a strong plus.**
The Reward
  • The A-Team: Work alongside high-performing talent in the industry.
  • Accelerated Growth: The slope of your learning curve here will be vertical. You will touch more production systems in one year than you would in five years at a bank.
  • Top-Tier Coverage: Premium benefits plan fully paid by nesto, including comprehensive insurance and unlimited access to telemedicine and mental health services for you and your family.
  • Rest & Recharge: 4 weeks of vacation to ensure you stay at peak performance.
  • Best-in-Class Tools: Access to the resources and tech you need to execute without friction.
  • Working framework: The environment that makes you productive and enables teamwork (Hybrid model).
Diversity and Inclusion

At nesto, we believe that creativity and collaboration are the result of a diverse team. We are committed to fostering a culture of diversity, equity, inclusion, and belonging, and we strongly encourage women, people of color, LGBTQIA+ individuals, and individuals with disabilities to apply. We are committed to creating a workplace that is inclusive and welcoming to all.


#nestocloud

#nestoposition


Similar Jobs

19 Minutes Ago
Easy Apply
Remote or Hybrid
CA
Easy Apply
Senior level
Senior level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Conduct AI-driven security assessments across software, hardware, and firmware; develop AI-enabled offensive and defensive security tooling; identify and remediate vulnerabilities; test LLMs, agentic workflows, and cloud environments; and guide organization-wide AI security strategy. Partner with engineering and leadership, lead threat-modeling sessions, and communicate security findings and recommendations to senior stakeholders.
Top Skills: Adversarial TestingAgentic WorkflowsAIApplication SecurityAWSEmbedded SystemsFirmwareGitGoLlmsOffensive SecurityPrompt InjectionRagThreat ModelingVulnerability Management
An Hour Ago
Easy Apply
Remote or Hybrid
2 Locations
Easy Apply
Senior level
Senior level
Big Data • Cloud • Software • Database
Build core MongoDB distributed database infrastructure focused on data partitioning, data movement, dynamic scaling, cluster elasticity, workload execution, and performance. Design reliable distributed protocols, solve complex scalability problems, review code, participate in architecture decisions, lead feature development, and mentor engineers. The role requires production-quality C++ development and strong expertise in distributed systems, computer architecture, performance, networking, observability, and resiliency.
Top Skills: C++MongoDB
2 Hours Ago
Easy Apply
Remote or Hybrid
CA
Easy Apply
Senior level
Senior level
Artificial Intelligence • Cloud • Computer Vision • Hardware • Internet of Things • Software
Leads legal operations initiatives, including metrics, dashboards, reporting, workflow redesign, intake management, and AI-assisted automation. The role improves scalable legal processes, manages team queues, supports contract review workflows, and partners cross-functionally to deliver operational efficiencies. It requires 5+ years of relevant operations, analytical, or technical experience, strong project management and communication skills, and hands-on experience with generative AI and legal operations tools.
Top Skills: Agentic AiAi ModelsBrightflagGenerative AiIroncladIvoZendesk

What you need to know about the Vancouver Tech Scene

Raincouver, Vancity, The Big Smoke — Vancouver is known by many names, and in recent years, it has gained a reputation as a growing hub for both tech and sustainability. Renowned for its natural beauty, the city has become a magnet for professionals eager to create environmental solutions, and with an emphasis on clean technology, renewable energy and environmental innovation, it's attracted companies across various industries, all working toward a shared goal: advancing clean technology.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account