Cybersecurity Incident Response Commander
About the Role:
The Cybersecurity Incident Response (IR) Commander is the technical and operational authority for ISA Cybersecurity 's Digital Forensics & Incident Response (DFIR) function and holds expert-level command of the Security Incident Response (SIR) service during client engagements. The role is structured as a Subject Matter Expert and Incident Commander rather than a line-management position: technical authority, judgment under pressure, and external-grade SME presence are the primary contributions.
The IR Commander leads the Response side of ISA's Protect-Detect-Respond operating model through influence, process and playbook ownership, and direct command on every Emergency and IR Retainer engagement. People-leadership behaviors including coaching analysts, championing career pathways, and modelling composure under stress are valued and expected to grow over time, but formal direct reports are not a requirement of the role at hire. Development and ongoing evolution of the Incident Response program is subject to the final authority of the Senior Director, DFIR Services who provides strategic direction and ultimate accountability for the program's scope, structure, and priorities.
This role reports to the Senior Director, DFIR Services. The successful candidate will have extensive experience in personally commanding and leading ransomware, business email compromise, data exfiltration, and complex multi-vector engagements, and will be recognized externally as a subject-matter expert in incident response and digital forensics.
About Us:
We are proud to be recognized as a top employer for multiple years in a row, we currently hold the distinctions of Canada’s Top Small and Medium Employers 2025, Greater Toronto’s Top Employers 2025 and are Certified Great Place to Work 2026-2027.
ISA Cybersecurity is a proudly Canadian cyber and AI services and solutions provider. Trusted by over 500 clients from SMB to global enterprise, we empower organizations to safeguard their most critical assets and adopt AI securely. Through our highly customizable Cyber 360 and AI 360 offerings, we deliver a comprehensive range of governance, assurance, engineering protection, detection, and response services for the public and private sectors. Backed by over three decades of operational experience and a vast network of highly specialized and certified experts, we leverage cutting-edge technologies and AI to ensure that clients achieve their privacy, security, and business goals.
We operate in a remote-first environment. Office presence is typically less than 20% of the time, varying by role and work requirements. Our office space, located at Bloor and Islington, is a collaborative space designed for in-person meetings and drop-ins. We enjoy hosting in-person quarterly townhalls and social events throughout the year to encourage teambuilding and collaboration.
Responsibilities:
- Serve as Incident Commander for all IR Retainer engagements and Emergency IRs delivered by ISA Cybersecurity .
- Lead digital forensic investigations across endpoint, server, network, mobile, and cloud sources.
- Ensure chain-of-custody discipline suitable for legal proceedings.
- Develop, manage, and continuously refine DFIR processes, procedures, playbooks, and runbooks (DFIR policy authorship is out of scope and sits with other functions).
- Conduct regular reviews and updates to DFIR people, processes, and technologies to ensure alignment with organizational objectives and the evolving threat landscape.
- Present incident and digital evidence reports to key stakeholders including law enforcement, legal counsel, and clients; Lead post-incident reporting and client walk-throughs and translate lessons learned into process, playbook, tooling, and training improvements.
- Educate internal and external stakeholders on incident identification and response best practices.
- Support presales activities including proposals, Statements of Work (SOWs), an