← Browse all jobs
ST

Hiring Cybersecurity Consultant - SME Security Specialist in Toronto

SecureNorth Technologies
Toronto, ONOn-site$110k – $140kJul 4
Apply Now →

About this role

SecureNorth Technologies is a Canadian managed security service provider (MSSP) headquartered in Toronto, serving small and medium enterprises across North America and Southeast Asia. Founded in 2018 by former incident responders from major financial institutions, we bridge the gap between enterprise-grade security and SME budgets. Our team of 45 professionals protects over 300 clients across manufacturing, professional services, healthcare, and fintech sectors. We operate a 24/7 Security Operations Center (SOC) powered by Microsoft Sentinel, SentinelOne, and CrowdStrike, delivering managed detection and response (MDR), vulnerability management, and compliance automation for SOC 2, ISO 27001, and PIPEDA requirements. We are hiring a Cybersecurity Consultant with a focus on SME security transformation. This role sits at the intersection of technical delivery and client advisory. You will onboard new clients, design practical security roadmaps, and lead implementation of controls that reduce risk without disrupting operations. Your work directly addresses the challenges highlighted in recent threat intelligence: SMEs facing 30,000+ new vulnerabilities annually, phishing campaigns enhanced by generative AI, and supply chain attacks targeting smaller vendors to reach larger partners. Key responsibilities include: - Conducting comprehensive asset discovery and attack surface mapping for new clients using automated scanning (Nessus, Qualys) and manual enumeration, delivering prioritized remediation plans within 10 business days of engagement start. - Designing and deploying multi-factor authentication (MFA) rollouts across Microsoft 365, Google Workspace, VPNs, and critical SaaS applications, achieving 100% enrollment for privileged accounts within 30 days. - Configuring and tuning email security gateways (Microsoft Defender for Office 365, Proofpoint) to block phishing, business email compromise, and malware, targeting a 99.5% catch rate with less than 0.1% false positive impact on legitimate business mail. - Implementing Zero Trust network segmentation using Microsoft Entra ID Conditional Access, Intune compliance policies, and Cisco Meraki or FortiGate firewalls, ensuring least-privilege access for remote and hybrid workforces. - Establishing automated patch management workflows via Intune, Jamf, or Action1 for endpoints, and Azure Update Manager for servers, maintaining 95% patch compliance within 14 days of critical CVE release. - Building and testing 3-2-1 backup strategies using Veeam, Azure Backup, or Rubrik, with quarterly restore drills documented for compliance evidence. - Delivering monthly security awareness training campaigns via KnowBe4 or Huntress SAT, including simulated phishing exercises, tracking click rates below 5% and reporting rates above 80%. - Performing quarterly vulnerability assessments and annual penetration tests (internal, external, web application) using Burp Suite, Nmap, and BloodHound, presenting executive-ready reports with CVSS-scored findings and remediation timelines. - Assisting clients with cyber insurance questionnaire completion and control evidence collection for renewals, reducing premium increases through documented risk reduction. - Collaborating with our SOC analysts to refine detection rules in Microsoft Sentinel (KQL) for client-specific threats, reducing mean time to detect (MTTD) from hours to minutes. Our work environment emphasizes autonomy, continuous learning, and measurable impact. You will join a team of 12 consultants and engineers who hold certifications including CISSP, CCSP, OSCP, and Microsoft Security Operations Analyst. We allocate 10% of billable time for research, certification study, and internal tool development. Our stack is modern and cloud-native: Azure, Microsoft 365 Defender stack, SentinelOne, CrowdStrike Falcon, Terraform for infrastructure-as-code, GitHub Actions for CI/CD, and IT Glue for documentation. Candidate requirements: - 4+ years hands-on experience in cybersecurity operations, consulting, or managed services, with at least 2 years serving SME or mid-market clients. - Deep practical knowledge of Microsoft security ecosystem: Microsoft 365 Defender, Entra ID, Intune, Sentinel, Purview, and Defender for Cloud. - Proven ability to translate technical risk into business language for non-technical stakeholders (owners, CFOs, COOs). - Experience with compliance frameworks: SOC 2 Type II, ISO 27001, NIST CSF, CIS Controls v8, PIPEDA, and/or provincial privacy laws. - Scripting proficiency in PowerShell and/or Python for automation of security tasks (user provisioning, log parsing, API integrations). - Relevant certifications: SC-200, AZ-500, CISSP, CISM, or equivalent experience. OSCP or CRTO a strong plus. - Canadian citizenship or permanent residency required; eligibility for Controlled Goods Program (CGP) clearance preferred for defense-adjacent clients. We offer a competitive compensation package: base salary CAD 110,000–140,000 plus performance bonus (10–15%), comprehensive benefits (health, dental, vision, paramedical, mental health), RRSP matching 5%, annual training budget CAD 5,000, paid conference attendance (Black Hat, BSides, SecTor), flexible hybrid schedule (3 days Toronto office, 2 remote), and 25 vacation days plus statutory holidays. Career progression paths lead to Senior Consultant, Practice Lead, or vCISO roles within 18–36 months. Our hiring process: initial 30-minute screening call with Talent team, followed by a 60-minute technical interview with two senior consultants (scenario-based, no whiteboard coding), a 45-minute client-facing simulation (presenting a mock security roadmap), and a final 30-minute conversation with the VP of Consulting. We aim to complete all stages within three weeks and provide detailed feedback regardless of outcome. If you are ready to help Canadian and international SMEs build resilient security programs, apply through our careers portal at securenorth.ca/careers with your resume and a brief note on a security challenge you solved for a resource-constrained organization.
Want to see how well you match this job?
Get AI-scored for free →