JobFlexy

Forward Deployed Detection and Response Consultant – Mandiant (Google) – Ottawa, ON

Location: Ottawa, ON | Company: Google

Mandiant, part of Google Cloud, is looking for a Forward Deployed Detection and Response Consultant to join its National Security team in Ottawa, Ontario. This is a high-impact, client-embedded role at the intersection of cyber defence, incident response, and agentic AI — built for security professionals who want to directly contribute to Canada’s national security and resilience.

Sponsored Links

In this position, you’ll work side-by-side with clients in Canada’s national security and defence sector, delivering industry-leading security operations, forensic analysis, threat hunting, and malware triage. From navigating technically complex, high-profile incidents to building autonomous AI-driven detection workflows, the breadth and depth of this role are genuinely uncommon in the industry.

About the Role: Forward Deployed Detection and Response Consultant

As a consultant embedded directly with client organizations, you’ll provide hands-on incident response support covering the full lifecycle — investigation, containment, remediation, and crisis management. You’ll work across cloud, endpoint, and network-based evidence sources, and develop agentic AI solutions to enhance autonomous detection and response capabilities. This is a role that demands both deep technical expertise and the ability to translate complex findings clearly for executive stakeholders.

Collaboration is central to the work. You’ll partner with internal Mandiant teams and client personnel alike, contributing to a secure operating environment while codifying attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) that strengthen current and future investigations. Bilingual communication (English and French) is an asset given the national security context.

Sponsored Links

Benefits and Salary

This role offers a competitive compensation package. The salary range in Canada is $134,000 – $137,000 CAD per year, plus a 15% bonus target, equity, and a comprehensive benefits package. For more details on Google’s benefits offerings, visit Google’s benefits page.

Job Details

🏢 Company: Mandiant (part of Google Cloud)

📍 Location: Ottawa, ON, Canada

💰 Pay: $134,000 – $137,000 CAD/year + 15% bonus target + equity + benefits

Responsibilities

Day-to-day, this role places you at the front lines of cyber defence for some of Canada’s most sensitive organizations. You’ll be expected to respond decisively under pressure, communicate clearly across technical and executive audiences, and continuously improve detection and response capabilities through both human expertise and AI-driven tooling.

  • Detect, respond to, and contain cyber security incidents in collaboration with internal and customer teams
  • Design and build agentic AI solutions to support autonomous detection, response, and remediation workflows
  • Recognize and codify attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) applicable to current and future investigations
  • Support and contribute to complex client-facing investigations, examining cloud, endpoint, and network-based sources of evidence
  • Develop and present comprehensive and accurate reports for both technical staff and executive leadership
  • Perform forensic analysis, threat hunting, and malware triage on high-profile engagements
  • Assist clients in navigating technically complex incidents including investigation, containment, remediation, and crisis management

Requirements / Skills

Mandiant is seeking a security professional with a strong foundation in SOC operations, incident response, and threat intelligence. The ideal candidate combines hands-on technical skill with the communication ability to present findings to both technical teams and executive decision-makers — and holds, or is eligible to obtain, a valid Personnel Security Clearance.

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent practical experience
  • 3+ years of experience in SOC analyst, malware research, threat hunting, or similar roles, including work with EDR and SIEM technologies
  • Incident response experience — direct participation in IR activities is required
  • Personnel Security Clearance — candidates must hold or be eligible to obtain a valid clearance as a condition of employment
  • Cloud platform certifications are considered an asset
  • Experience with agentic AI workflows for detection, response, and remediation is preferred
  • Security competition experience (CTFs, Hack the Box, TryHackMe, Overthewire, etc.) is an asset
  • Bilingual communication (English and French) is an asset for working with internal partners and customer teams
  • Strong time and project management skills, with the ability to manage complex, concurrent engagements

How to Apply

To apply, visit the official job posting using the link below. Make sure your resume is up to date and tailored to reflect your incident response and security operations experience before submitting.

Share This Opportunity

Know someone who might be interested? Share this job posting and help them join Mandiant in Ottawa.

Job Summary & Tips for Applying

AI-generated summary and tips to help you highlight your strengths effectively.

Quick Summary & What to Highlight: This Forward Deployed Detection and Response Consultant role at Mandiant in Ottawa is perfect for candidates who excel in incident response, threat hunting, and security operations. On your resume, emphasize any experience with EDR and SIEM technologies, forensic analysis, and your ability to work in a fast-paced, high-stakes environment. If you’ve previously worked in SOC, malware research, or national security contexts, make sure to highlight specific achievements and responsibilities that align with this position.

Resume & Application Tips: Before applying, tailor your resume to match the job description. Include keywords like incident response, threat hunting, and agentic AI that appear in the posting. Quantify your achievements where possible (e.g., “led containment of 15+ security incidents annually” or “reduced mean time to detect by 40% through SIEM tuning”). Write a brief cover letter expressing your genuine interest in Mandiant and why you’re drawn to contributing to national security work in Ottawa. Double-check your application for spelling errors and ensure your contact information is current.

Interview Preparation: If selected for an interview, research Mandiant‘s threat intelligence capabilities, recent incident response case studies, and Google Cloud’s security portfolio beforehand. Prepare specific examples using the STAR method (Situation, Task, Action, Result) to demonstrate your incident response and forensic analysis skills. Common questions may include scenarios about handling high-profile breaches, communicating findings to executive stakeholders, and managing competing priorities during active incidents. Dress appropriately for a professional cybersecurity consulting environment, arrive 10–15 minutes early, and bring copies of your resume. Prepare thoughtful questions about the role, the national security client environment, and growth opportunities. After the interview, send a thank-you email within 24 hours reiterating your interest in the position.

Recommended Job Offers

More Google openings near Ottawa, ON