Incident Response Analyst, Digital Forensics & Incident Response
Job in
Winnipeg, Manitoba, A3C, Canada
Listed on 2026-10-09
Listing for:
isacybersecurity
Full Time
position Listed on 2026-10-09
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, Network Security
Job Description & How to Apply Below
The Incident Response (IR) Analyst is a hands-on technical responder within ISA Cybersecurity's Digital Forensics & Incident Response (DFIR) function, delivering the Security Incident Response (SIR) service across client engagements. The role executes forensic collection, analysis, and containment work under the direction of the Cyber Incident Response Commander, building the case-based experience and technical depth that lead toward Incident Commander and Senior Analyst career paths.
The IR Analyst supports every stage of active engagements, from triage and evidence acquisition through eradication and post-incident reporting, working alongside the IR Commander, DFIR team members, and SOC teams. Strategic direction rests with the Incident Commander and final accountability for the DFIR program rests with the Senior Director, DFIR Services.
The successful candidate will have practical experience supporting incident response and forensic investigations, strong technical fundamentals across endpoint, network, and cloud environments, and the composure to work effectively under the pressure of active incidents.
About Us:
We are proud to be recognized as a top employer for multiple years in a row, we currently hold the distinctions of Canada’s Top Small and Medium Employers 2025, Greater Toronto’s Top Employers 2025 and are Certified Great Place to Work .
ISA Cybersecurityis a proudly Canadiancyberand AI services and solutions provider.
Trusted by over 500 clients from SMB to global enterprise, we empower organizations to safeguard their most critical assetsand adopt AI securely.
Through ourhighly customizable
Cyber 360and AI 360offerings, we deliver a comprehensive range of governance, assurance,engineeringprotection, detection,and response services for the public and private sectors. Backed by over three decadesof operational experience and a vast network ofhighly specialized and certified experts, weleveragecutting-edge technologies and AI to ensure that clients achieve their privacy,security, and business goals.
We operate in a remote-first environment. Office presence is typically less than 20% of the time, varying by role and work requirements. Our office space, located at Bloor and Islington, is a collaborative space designed for in-person meetings and drop-ins. We enjoy hosting in-person quarterly townhalls and social events throughout the year to encourage teambuilding and collaboration.
Responsibilities:
Support the Incident Commander in the execution of IR Retainer engagements and Emergency IRs, carrying out assigned work streams within the incident.
Perform digital forensic acquisition and analysis across endpoint, server, network, mobile, and cloud sources.
Maintain chain-of-custody discipline suitable for legal proceedings throughout evidence handling.
Gather and analyze evidence from logs, email, endpoint artifacts, and other sources to identify indicators of compromise and attacker activity.
Reconstruct attack timelines from collected evidence to support root-cause analysis and scope determination.
Apply and help refine DFIR playbooks and runbooks in the course of live engagements, flagging gaps or improvements to the IR Commander.
Contribute to incident and digital evidence reports, including drafting technical findings for review by the IR Commander prior to client, legal, or law enforcement delivery.
Participate in post-incident reviews and lessons-learned sessions, translating findings into playbooks, tooling, or training improvements.
Assist with technical scoping input for proposals, Statements of Work (SOWs), and RFP responses as requested.
Correlate threat intelligence and observed TTPs into incident analysis, and feed findings back to detection and threat hunting teams.
Trac…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×