Job Description
What is the Opportunity?
The Senior Incident Response Analyst, will serve as the primary point of contact for Security Operations Centre management regarding security incidents as part of Blue team operations. You will support team members with critical incidents impacting RBC users, systems, infrastructure, and resources.
You’ll play a key role in safeguarding RBC through detailed investigations, coordinating remediation efforts across multiple teams, and drive security incidents to timely and effective resolution while prioritizing accuracy and thoroughness.
In this role, after hours on call support (rotational basis) is required.
What will you do?
-
Global accountability to respond to critical security incidents/events providing accurate and timely reporting to Global Security Leadership.
-
Provide 24/7 support for security incidents impacting mission critical business and IT infrastructure, including supporting global incident management and response, remediation, and reporting
-
Perform log review and analysis, examining both direct and collector-sourced logs
-
Assess the effectiveness of secondary security controls and determine the scope, impact, and urgency of cyber incidents
-
Address common attack vectors, particularly email based threats (phishing, malicious links, software installation)
-
Collaborate with DevOps and other technical teams to execute complex remediation activities, including software patching and system re-imaging
-
Provide postmortem reporting for leadership detailing security vulnerabilities, technology gaps, shortcomings or miscellaneous security issues.
-
Conduct distributed security incident reviews with teams as determined by management
-
Responsible for driving to resolution security incidents in a timely and effective manner.
-
Maintain timely communication with the Computer Security Incident Response Team (CSIRT) extended teams
-
Ensure global compliance with Enterprise standards regarding security incident response and related findings
-
Drive security incidents to timely and effective resolution while prioritizing accuracy over speed
What do you need to succeed?
Must have
-
Bachelor's degree in Computer Science, IT, or related discipline
-
2+ years of cyber security incident response experience / Blue Team experience
-
Demonstrated experience conducting investigations for security-related events in a complex Incident Management or Security Operations Center environment
-
Advanced log analysis and SIEM query capabilities
-
Experience investigating security incidents across complex network environments
-
Strong operating system platform knowledge: Windows, Mac, UNIX, and Linux
-
Excellent written and verbal communication skills
-
Ability to work effectively across multiple teams and departments
-
Thorough understanding of Security Information and Incident Management methodologies
-
Strong problem solving and analytical skills
Nice to Have
-
Information security certifications (CISSP, GCIA, GCIH, GREM, CEH)
-
Malware analysis and digital forensics experience
-
Penetration testing experience or adjacent security testing background
-
Vulnerability assessment experience
What’s in it for you?
We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.
-
A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable
-
Leaders who support your development through coaching and managing opportunities
-
Ability to make a difference and lasting impact
-
Work in a dynamic, collaborative, progressive, and high-performing team
-
Opportunities to do challenging work
-
Opportunities to take on progressively greater accountabilities
#LI-POST
#TECHPJ
Job Skills
Business Perspective, Critical Thinking, Decision Making, Detail-Oriented, Forensic Computing, Group Problem Solving, Information Security Operation Center (ISOC), IT Incident Management, Security Information and Event Management (SIEM), Threat Management
Additional Job Details
Address:
16 YORK ST:TORONTO
City:
Toronto
Country:
Canada
Work hours/week:
37.5
Employment Type:
Full time
Platform:
TECHNOLOGY AND OPERATIONS
Job Type:
Regular
Pay Type:
Salaried
Posted Date:
2026-09-11
Application Deadline:
2026-09-25
Note: Applications will be accepted until 11:59 PM on the day prior to the application deadline date above
Our Employment Opportunities
At RBC, we are guided by living shared values of Client First, Integrity, Collaboration, Respect and Excellence and winning together as One RBC. We believe an inclusive workplace that has diverse perspectives is core to our continued growth as one of the largest and most successful banks in the world. Maintaining a workplace where our employees feel supported to perform at their best, effectively collaborate, drive innovation, and grow professionally helps to bring our Purpose to life and create value for our clients and communities. RBC strives to deliver this through policies and programs intended to foster a workplace based on respect, belonging and opportunity for all.
Join our Talent Community
Stay in-the-know about great career opportunities at RBC. Sign up and get customized info on our latest jobs, career tips and Recruitment events that matter to you.
Expand your limits and create a new future together at RBC. Find out how we use our passion and drive to enhance the well-being of our clients and communities at jobs.rbc.com.
RBC is presently inviting candidates to apply for this existing vacancy. Applying to this posting allows you to express your interest in this current career opportunity at RBC. Qualified applicants may be contacted to review their resume in more detail.