Lead Security Engineer

Posted 3 Days Ago
Be an Early Applicant
Toronto, ON
Senior level
Enterprise Web • Fintech • Financial Services
The Role
The Lead Security Engineer will lead security detection and response initiatives, develop security detections across SIEM, SOAR, and EDR platforms, and optimize automation workflows. The engineer will collaborate with SOC and IT teams, research new technologies, perform security assessments, and mentor junior engineers.
Summary Generated by Built In

About the role:
We are seeking a Lead Security Engineer to help drive our security detection and response efforts. In this role, you will be responsible for designing, implementing, and improving security monitoring, automation, and response capabilities. You will work closely with security engineers, analysts, and cross-functional teams to strengthen our security posture.
This position is based in our Toronto office. We follow a hybrid policy of 3 days onsite and 2 days remote work.
Key Responsibilities

  • Lead security detection and response initiatives, ensuring effective threat monitoring, investigation, and mitigation.
  • Develop and maintain security detections across SIEM, SOAR, and EDR platforms.
  • Architect and optimize security automation workflows to enhance threat response efficiency.
  • Collaborate with our in-house SOC and IT teams to refine detection and preventative capabilities and reduce false positives.
  • Research and implement new security technologies and best practices to enhance monitoring and response effectiveness.
  • Perform security assessments, tuning detection rules, and developing playbooks for security incidents.
  • Mentor junior engineers and contribute to security strategy and roadmap planning.


Requirements

  • 5+ years of hands-on experience in security engineering, threat detection, and response.
  • Strong expertise with SIEM, SOAR, and EDR.
  • Experience developing and tuning detections using logs, telemetry, and threat intelligence.
  • Proficiency in scripting and automation (Python, PowerShell, Bash, etc.).
  • Strong understanding of attack techniques (MITRE ATT&CK framework) and incident response methodologies.
  • Ability to analyze security telemetry, investigate threats, and develop effective mitigation strategies.
  • Excellent communication skills and ability to collaborate across teams.


Preferred Qualifications

  • Experience with cloud security monitoring (AWS, Azure, GCP).
  • Familiarity with security frameworks (NIST, CIS, ISO 27001).
  • Certifications such as GIAC (GCDA, GCIH, GCFA), OSCP, CISSP, or relevant credentials.


If you are passionate about security, automation, and detection engineering, we'd love to hear from you! Apply today to be a part of our growing security team.
Morningstar's hybrid work environment gives you the opportunity to work remotely and collaborate in-person each week. We've found that we're at our best when we're purposely together on a regular basis, at least three days each week. A range of other benefits are also available to enhance flexibility as needs change. No matter where you are, you'll have tools and resources to engage meaningfully with your global colleagues.

Top Skills

AWS
Azure
Bash
Edr
GCP
Powershell
Python
SIEM
Soar

What the Team is Saying

Raaghavendar
Saurabh
Anna
Wendell
Jeff
Upasna
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
12,700 Employees
Hybrid Workplace
Year Founded: 1984

What We Do

At Morningstar, we believe in building great products in-house in a highly collaborative, agile environment where we focus on technical excellence, the user experience, and continuous improvement. Our technologists represent a range of skills and experience levels, but they all view their work as a craft and push technology’s boundaries.

Why Work With Us

Imagining big things is in our blood -- it's transformed us from a company with just a few employees in 1984 to a leading independent investment research company with a worldwide presence today. As of April 2020, we acquired Sustainalytics to drive long-term meaningful outcomes for investors in the ESG space. Join us on this exciting journey!

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Morningstar Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

Typical time on-site: 3 days a week
HQGlobal Headquarters
Santiago Province
LU
NSW
Amsterdam, NL
Bangkok, TH
Cape Town, ZA
Dubai, Dubai
Frankfurt am Main, DE
Frederiksberg, DK
London, GB
Madrid, ES
Mexico City, Mexico City
Milano, IT
Navi Mumbai, Maharashtra
New York, NY
Oakland, MD
Oslo, NO
Paris, FR
São Paulo, São Paulo
PitchBook US Headquarters
Stockholm, SE
Tokyo, JP
Toronto, ON
Toronto, Ontario
Zürich, CH
Learn more

Similar Jobs

Morningstar Logo Morningstar

Senior Application Security Architect

Enterprise Web • Fintech • Financial Services
Hybrid
Toronto, ON, CAN
12700 Employees

Morningstar Logo Morningstar

Senior Application Security Architect

Enterprise Web • Fintech • Financial Services
Hybrid
Toronto, ON, CAN
12700 Employees

Morningstar Logo Morningstar

Software Engineer

Enterprise Web • Fintech • Financial Services
Hybrid
Toronto, ON, CAN
12700 Employees

Morningstar Logo Morningstar

Manager, Client Relations

Enterprise Web • Fintech • Financial Services
Toronto, ON, CAN
12700 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account