Vista previa generada por IA
Senior Security Detection Engineer role at RBC – drive automation & SIEM detection development across global operations.
Apply by July 17 for a full‑time opportunity in Toronto, Canada with flexible benefits and competitive compensation.
What is the Opportunity?
The role of the Senior Security Detection Engineer is to provide specialized subject matter expertise for the Detection Engineering & Automation (DEA) team, for RBC's Global Cyber Security. This is a key technical role supporting mission critical enterprise network security operations and IT services protection. This role will drive development using automation to new or existing security use cases to reduce the overall mean time to detect and respond to incidents.
With your proven experience, collaboratively lead our RBC technology and application partners to develop and implement mission critical cyber use cases for security monitoring supporting security operations and Security Operations Centre capabilities.
What will you do?
Provide global accountability to provide technical and subject matter expertise supporting cyber uses cases developed from security systems and infrastructure for security monitoring.
Work with RBC technology and/or application partners (Cybersecurity, Technology Infrastructure, SOC) to develop and strengthen use cases for continuous security monitoring.
Develop runbooks for those use cases that align with security operations processes and streamline the incident investigation and response tasks.
Work with Defensive Threat Operations Correlation Engineering to facilitate log ingestion and use case development in our SIEM platforms.
Periodically review use case library, perform attestation on existing use cases, participate in tuning discussions/activities and provide improvement recommendations where necessary/possible.
Develop and maintain lines of communication with various security groups, Security Operations Centre leadership and technology stakeholders
Develop processes to support a maturing program
Provide operational metrics and reports as needed
What do you need to succeed?
Must have:
- 2 to 5 years of industry experience.
- Experience in cloud environments (AWS, Azure, GCP, OCP)
- Intermediate experience with Python.
- Experience with building detections in SIEM.
- Experience with automation in SOAR.
- Educational background in IT, Engineering, Cybersecurity and/or equivalent relevant experience
- Demonstrated technical leadership ability
- In-depth understanding of Security Operations and Security Technologies, with previous experience working in a SOC environment
- Understanding of common exploitation techniques and awareness of new threats
- Strong analytical and complex problem-solving skills
- Expert understanding of SIEM technology and operations
- Strong Networking and Enterprise IT Infrastructure knowledge with TCP/IP packet level knowledge
Nice-to-have :
- Certifications in information security (GCIH, GCSA, GPCS, GCTD, GCFR)
- Certifications in cloud platforms (AWS, Azure, GCP, or OCP)
- Experience in working within a large, global financial services company.
- A good understanding of modern, cloud centric architectures and DevOps principles.
What’s in it for you?
We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.
A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable
Leaders who support your development through coaching and managing opportunities
Ability to make a difference and lasting impact
Work in a dynamic, collaborative, progressive, and high-performing team
A world‑class training program in financial services
Flexible work/life balance options
Opportunities to do challenging work
#techpj
#LI-post
Job Skills
Automatización de seguridad, Colaboración interdepartamental, Comunicación, Comunicación de alto impacto, Detección de amenazas, Documentación de casos de uso, Gestión de seguridad cibernética, Gestión de seguridad de la información, Herramientas SIEM, Monitorización de amenazas, Operaciones cibernéticas, Operaciones de Seguridad, Operaciones de seguridad de red, Orientado al detalle, Pensamiento estratégico, Resolución de problemas en grupo, Seguridad de tecnologia de la información, Software de la nube, Toma de decisiones
Additional Job Details
Address:
16 YORK ST:TORONTO
City:
Toronto
Country:
Canadá
Work hours/week:
37.5
Employment Type:
Full time
Platform:
TECHNOLOGY AND OPERATIONS
Job Type:
Regular
Pay Type:
Salaried
Posted Date:
2026-03-25
Application Deadline:
2026-07-17
Note : Applications will be accepted until 11:59 PM on the day prior to the application deadline date above
Our Employment Opportunities
At RBC, we are guided by living shared values of Client First, Integrity, Collaboration, Respect and Excellence and winning together as One RBC. We believe an inclusive workplace that has diverse perspectives is core to our continued growth as one of the largest and most successful banks in the world. Maintaining a workplace where our employees feel supported to perform at their best, effectively collaborate, drive innovation, and grow professionally helps to bring our Purpose to life and create value for our clients and communities.
Join our Talent Community
Stay in-the-know about great career opportunities at RBC. Sign up and get customized info on our latest jobs, career tips and Recruitment events that matter to you.
Expand your limits and create a new future together at RBC. Find out how we use our passion and drive to enhance the well‑being of our clients and communities at jobs.rbc.com .
RBC is presently inviting candidates to apply for this existing vacancy. Applying to this posting allows you to express your interest in this current career opportunity at RBC. Qualified applicants may be contacted to review their resume in more detail.