Forward Deployed Detection and Response Consultant – Mandiant (Google) – Ottawa, ON
Location: Ottawa, ON | Company: Google
Mandiant, part of Google Cloud, is looking for a Forward Deployed Detection and Response Consultant to join its Cyber Defence, National Security team based in Ottawa, Ontario. This is a rare opportunity to embed directly with clients in Canada’s national security and defence sector, working at the forefront of cyber threat detection and incident response.
In this role, you’ll contribute to building a more secure and resilient Canada — helping organizations detect and respond to sophisticated threats before, during, and after an incident. From forensic analysis and threat hunting to developing agentic AI solutions, the work is technically complex, high-impact, and deeply meaningful.
About the Role: Forward Deployed Detection and Response Consultant
As a core member of Mandiant’s National Security team, you’ll provide industry-leading security operations, incident response, and managed detection and response services to some of Canada’s most sensitive organizations. You’ll work directly alongside client teams and internal partners to navigate technically demanding situations, from high-profile breaches to proactive threat hunting exercises. Your ability to move quickly, think critically, and communicate clearly — to both technical staff and executive leadership — will be central to success in this position.
Mandiant’s reputation is built on frontline experience responding to some of the world’s most complex breaches, combined with nation-state grade threat intelligence, machine intelligence, and rigorous security validation. As part of the Google Cloud ecosystem, you’ll have access to exceptional tools, talent, and resources. A valid Personnel Security Clearance is required as a condition of employment, reflecting the sensitivity of the clients you’ll serve.
Benefits and Salary
This position offers a salary range of $134,000 – $137,000 CAD, plus a 15% bonus target, equity, and a comprehensive benefits package. Google is well-known for its competitive total compensation, which typically includes health and wellness coverage, retirement support, and professional development resources. More details are available through Google’s benefits page.
Job Details
🏢 Company: Google / Mandiant
📍 Location: Ottawa, ON, Canada
📌 Job Type: Mid-level
💰 Pay: $134,000 – $137,000 CAD + 15% bonus target + equity + benefits
Responsibilities
This role sits at the intersection of hands-on incident response, threat intelligence, and emerging AI-driven security tooling. Every engagement is different — you might be containing an active breach one day and building automated detection workflows the next. Here’s what the day-to-day looks like:
- Collaborate with internal and customer teams to detect, respond to, and contain cybersecurity incidents in real time
- Design and build agentic AI solutions to support autonomous detection, response, and remediation workflows
- Recognize and codify attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) applicable to current and future investigations
- Support and lead complex client-facing investigations, examining cloud, endpoint, and network-based sources of evidence
- Develop and present comprehensive reports and presentations tailored for both technical staff and executive audiences
Requirements / Skills
Mandiant is looking for someone who combines deep technical expertise in cybersecurity operations with the communication skills to work effectively across all levels of an organization. Experience in national security or defence contexts is a significant asset, and a security clearance — or the eligibility to obtain one — is essential.
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related technical field (or equivalent practical experience)
- 3+ years of experience as a SOC analyst, malware researcher, threat hunter, or in a similar role using EDR and SIEM technologies
- Incident response experience — hands-on participation in real-world investigations is required
- Personnel Security Clearance — candidates must hold or be eligible to obtain a valid clearance as a condition of employment
- Cloud platform certifications and experience deploying agentic AI workflows for detection and response (preferred)
- Bilingual (English and French) communication ability is a strong asset for working with national clients and internal partners
- Excellent time and project management skills, with the ability to manage multiple complex engagements simultaneously
How to Apply
To apply, visit the official job posting using the link below. Make sure your resume is up to date and reflects relevant experience in cybersecurity operations, incident response, and any security clearance history before submitting.
Share This Opportunity
Know someone who might be interested? Share this job posting and help them join Google / Mandiant in Ottawa.
Job Summary & Tips for Applying
Quick Summary & What to Highlight: This Forward Deployed Detection and Response Consultant role at Mandiant (Google) in Ottawa is ideal for candidates who excel in incident response, threat hunting, and security operations. On your resume, emphasize hands-on experience with EDR and SIEM platforms, any malware analysis or forensic investigation work, and familiarity with cloud security environments. If you’ve previously held a security clearance or worked in a government or defence-adjacent role, make sure to highlight those credentials prominently.
Resume & Application Tips: Before applying, tailor your resume to match the job description. Include keywords like incident response, threat hunting, and IOCs/TTPs that appear in the posting. Quantify your achievements where possible (e.g., “led containment of 10+ incidents annually” or “reduced mean time to detect by 30% through SIEM tuning”). Write a brief cover letter expressing your genuine interest in Mandiant’s National Security team and why you’re well-suited for this client-embedded role in Ottawa. Double-check your application for spelling errors and ensure your contact information is current.
Interview Preparation: If selected for an interview, research Mandiant‘s history, threat intelligence reports, and Google Cloud’s security portfolio beforehand. Prepare specific examples using the STAR method (Situation, Task, Action, Result) to demonstrate your incident response and investigative skills. Common questions may include scenarios about handling high-pressure breaches, communicating findings to executives, and building detection workflows. Dress professionally for a cybersecurity consulting environment, arrive 10–15 minutes early (or join the virtual call with time to spare), and bring copies of your resume. Prepare thoughtful questions about the types of national security engagements, team structure, and opportunities to grow within Mandiant and Google Cloud. After the interview, send a thank-you email within 24 hours reiterating your interest in the position.