Incident Response Security Consultant – Google (Mandiant) – Remote, Canada
Mandiant, part of Google Cloud, is looking for an Incident Response Security Consultant to join their team — and this role is fully remote across several Canadian provinces, including Alberta, British Columbia, Nova Scotia, Ontario, and Quebec. If you’re a cybersecurity professional who thrives under pressure and has hands-on experience navigating complex breaches, this is a high-impact opportunity with one of the most respected names in cyber defence and threat intelligence.
This isn’t a passive monitoring role — you’ll be working directly with clients during some of their most critical moments, helping them detect, contain, and recover from active security incidents. Expect to dig deep into forensic analysis, threat hunting, and malware triage, while also communicating findings clearly to executives, legal teams, and technical staff.
About the Role: Incident Response Security Consultant
As an Incident Response Consultant at Mandiant, you’ll lead end-to-end incident response engagements — from initial investigation through containment, remediation, and crisis management. You’ll work with client teams on technically complex, high-profile incidents and apply your deep expertise in host forensics, network forensics, log analysis, and cloud forensics to understand exactly what happened and how to stop it.
Collaboration is central to this role — both with internal Mandiant teams and directly with customer stakeholders. You’ll be expected to recognize and document attacker tools, tactics, and procedures (TTPs) and contribute intelligence that improves future investigations. Roughly 30% travel may be required, and fluency in English is essential for day-to-day communication with partners and clients.
Benefits and Salary
This role offers a competitive compensation package with a salary range of $134,000 – $137,000 CAD, plus a 15% bonus target, equity, and a comprehensive benefits package. Google is well known for offering strong employee benefits — visit the Google careers page to learn more about what’s included.
Job Details
📌 Job Type: Remote eligible
🏢 Company: Google (Mandiant)
📍 Location: Remote — Alberta, British Columbia, Nova Scotia, Ontario, or Quebec
💰 Pay: $134,000 – $137,000 CAD + 15% bonus target + equity + benefits
⏱️ Schedule: Up to 30% travel required
Responsibilities
Day-to-day, this role puts you at the centre of active cyber incident response. You’ll be the person clients rely on when things go wrong — bringing technical expertise and calm, methodical thinking to high-pressure situations. Here’s what the work actually looks like:
- Collaborate with internal Mandiant teams and customer stakeholders to investigate and contain security incidents efficiently and at scale
- Recognize and codify attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) to strengthen current and future investigations
- Conduct host forensics, network forensics, log analysis, and malware triage in direct support of incident response engagements
- Perform threat hunting and forensic analysis across complex, high-profile incidents involving technically sophisticated adversaries
- Communicate investigative findings and strategies clearly to technical staff, executive leadership, legal counsel, and external clients
- Support crisis management throughout the incident lifecycle — from initial detection through remediation and post-incident review
Requirements / Skills
Mandiant is looking for candidates with real, hands-on experience in incident response and forensic investigation — not just theoretical knowledge. The right person is someone who’s comfortable operating in ambiguous, high-stakes environments and can translate technical findings into clear, actionable insights for a range of audiences.
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related technical field — or equivalent practical experience
- 3+ years of end-to-end incident response experience, including investigation, analysis, and containment actions
- 3+ years of investigative experience in at least one of: network forensics, malware triage, cloud forensics, or disk and memory forensics
- English fluency required for effective communication with internal partners and customer teams
- Ability to travel up to 30% as engagements require
- Cloud platform certifications are an asset (preferred)
- Experience with security competitions or CTFs (Hack the Box, TryHackMe, Overthewire, etc.) is a strong differentiator
- French fluency is an asset for working with Francophone clients and partners
How to Apply
To apply, visit the official Google Careers posting using the link below. Make sure your resume is up to date and reflects your hands-on incident response and forensics experience before submitting.
Share This Opportunity
Know someone who might be interested? Share this job posting and help them join Google (Mandiant) in this remote role across Canada.
Job Summary & Tips for Applying
Quick Summary & What to Highlight: This Incident Response Security Consultant role at Google (Mandiant) in Canada (Remote) is perfect for candidates who excel in forensic investigation, malware triage, and incident containment. On your resume, emphasize any experience with end-to-end incident response engagements, threat hunting, and your ability to work across network, cloud, and host forensics. If you’ve previously worked in a cybersecurity consulting or SOC environment, make sure to highlight specific cases, tools used, and outcomes achieved.
Resume & Application Tips: Before applying, tailor your resume to match the job description. Include keywords like incident response, threat hunting, and indicators of compromise (IOCs) that appear in the posting. Quantify your achievements where possible (e.g., “led containment for 15+ enterprise-level incidents” or “reduced mean time to containment by 40% through improved forensic workflows”). Write a brief cover letter expressing your interest in Mandiant’s mission and the value you’d bring to client-facing investigations in Canada. Double-check your application for errors and ensure your contact information is current.
Interview Preparation: If selected for an interview, research Mandiant‘s history, threat intelligence reports, and Google Cloud’s cybersecurity strategy beforehand. Prepare specific examples using the STAR method (Situation, Task, Action, Result) to demonstrate your forensic analysis and incident response skills. Common questions may include scenarios about handling a live breach, communicating findings to non-technical executives, or triaging an unknown malware sample. Dress professionally, arrive (or log in) 10–15 minutes early, and bring copies of your resume. Prepare thoughtful questions about the types of engagements, team structure, and professional development. After the interview, send a thank-you email within 24 hours reiterating your interest in the position.