Senior Cyber Defence Analyst
About Us
Nesto Cloud is Canada's cloud-native and AI driven, end-to-end mortgage technology platform, helping financial institutions modernize lending through AI intelligent automation, AI & Cloud proprietary technology, and business process outsourcing (BPO) solutions.
Powered by the Nesto Group ecosystem, we transform decades of mortgage expertise into cutting-edge technology that reduces mortgage operation costs, accelerates lending, strengthens compliance, and delivers exceptional experiences for lenders and borrowers alike.
Nesto Group
Nesto Group is Canada's leading provider of mortgage technology and financing solutions, with more than CAD $80 billion in residential and commercial mortgages under administration. Trusted by many of the country's leading financial institutions, we combine over 50 years of mortgage expertise with proprietary cloud and AI technology to transform the future of lending.
Powered by our proprietary cloud and AI technology, nesto has become one of Canada's fastest-growing mortgage lenders, gaining market share across direct-to-consumer (D2C) residential lending, the broker channel, and multi-family commercial lending. Recognized as one of Deloitte's Fast 50 companies for three consecutive years, we continue to push the industry forward through innovation, technology, and customer-focused solutions.
Operating through our family of brands—CMLS, nesto, and Nesto Cloud—our mission is to build Canada's mortgage ecosystem of the future and create a true Canadian champion in lending technology and financial services. Learn more at:
Life at Nesto Cloud
At Nesto Cloud, you'll build the future of lending alongside some of the country's top developers, AI engineers, and mortgage experts. You'll work with a modern tech stack and AI-driven development frameworks designed to help you innovate, grow your skills, and accelerate your career.
About the team
We're looking for a Senior Cyber Defence Analyst reporting to the Cyber Defence Director. This role is ideal for someone who thrives on hands-on investigation, detection engineering, and building innovative AI-driven defence capabilities in a 100% cloud, dev-centric environment. You'll collaborate within the Cyber Defence team to shape how we leverage AI and ML to defend against an increasingly AI-enabled threat landscape, experimenting with new detection approaches, building AI-augmented investigations, and staying ahead of adversaries doing the same.
What you'd be accomplishing in that role :
- Lead triage-to-remediation on critical/high investigations
- Conduct proactive threat hunts; operationalize findings into detections and playbooks
- Operate and optimize Google SecOps SIEM, SOAR and SentinelOne, building detection content, dashboards, and playbooks
- Design, code, and deploy detection rules across cloud, endpoint, application layers with minimal false positive rate
- Implement Blue Team coverage beyond endpoints/servers into cloud infrastructure (Azure, GCP), MS365/Entra ID, containers, CI/CD pipelines, and application layers
- Tune existing detections, close coverage gaps; maintain detection knowledge base
- Partner with DevOps/engineering teams to embed detection and response capability into cloud-native and application architectures
- Consume threat intelligence (IOCs, TTPs) and translate into hunts and detections
- Participate in purple team exercises; document findings and build detections from gaps
- Validate detection coverage against Red Team scenarios
- Evaluate and pilot AI/ML tools for detection augmentation, anomaly detection, alert triage
- Implement selected tools into SIEM/SOAR workflows; measure effectiveness
Who we are looking for :
- 7+ years of experience in a SOC / Cyber Defence / Blue Team role, with demonstrated seniority in investigations
- Strong hands-on experience with SOAR, SIEM data ingestion, use case development, and tuning
- Proven threat hunting and threat intelligence experience
- Experience with sandboxing / malware analysis tools
- Deep experience securing cloud environments (Azure, GCP) and MS365/Entra and endpoint/server security
- Hands-on experience with Google SecOps SIEM and SentinelOne or equivalent technologies.
- Experience defending application/dev-centric environments (containers, CI/CD, cloud-native apps) in addition to traditional endpoint/server defence
- Purple teaming experience
- Familiarity with using AI/ML tools for defensive security, and awareness of emerging AI-driven attack techniques
- Relevant certifications (GCIA, GCIH, GCFA, GCTI, CySA+, OSCP, or Azure/GCP security certs) are an additional plus.
- Scripting/automation experience (Python, SOAR platforms) is a strong plus
- **English is required for writing and documentation. French speaking and reading is a strong plus.**
The Reward
- The A-Team: Work alongside high-performing talent in the industry.
- Accelerated Growth: The slope of your learning curve here will be vertical. You will touch more production systems in one year than you would in five years at a bank.
- Top-Tier Coverage: Premium benefits plan fully paid by nesto, including comprehensive insurance and unlimited access to telemedicine and mental health services for you and your family.
- Rest & Recharge: 4 weeks of vacation to ensure you stay at peak performance.
- Best-in-Class Tools: Access to the resources and tech you need to execute without friction.
- Working framework: The environment that makes you productive and enables teamwork (Hybrid model).
Diversity and Inclusion
At nesto, we believe that creativity and collaboration are the result of a diverse team. We are committed to fostering a culture of diversity, equity, inclusion, and belonging, and we strongly encourage women, people of color, LGBTQIA+ individuals, and individuals with disabilities to apply. We are committed to creating a workplace that is inclusive and welcoming to all.
#nestocloud
#neso
Required Skills
Required Languages
🇬🇧 English