Senior Forward Deployed Detection and Response Consultant – Google Mandiant – Ottawa, ON
Location: Ottawa, ON | Company: Google
Mandiant, part of Google Cloud, is seeking a Senior Forward Deployed Detection and Response Consultant to join its National Security team in Ottawa, Ontario. This is a high-impact, client-embedded role at the intersection of cybersecurity operations, threat intelligence, and agentic AI — working directly with Canada’s national security and defence sector to build a more resilient country.
In this role, you won’t be working from the sidelines. You’ll be on the ground with clients, helping them detect and respond to threats in real time, conducting forensic analysis, threat hunting, malware triage, and developing cutting-edge autonomous AI-driven solutions for detection and remediation. If you thrive under pressure and want your work to genuinely matter at a national scale, this position is worth a close look.
About the Role: Senior Forward Deployed Detection and Response Consultant
Embedded directly with clients across Canada’s national security and defence ecosystem, you’ll provide industry-leading security operations, incident response, managed detection and response (MDR), and training services. Your mandate is to help organizations reduce mission risk — before, during, and after a cyber incident. From navigating technically complex, high-profile breaches to codifying attacker Tools, Tactics, and Procedures (TTPs), your expertise will shape how Canada’s most critical institutions defend themselves.
You’ll also play a pivotal role in developing agentic AI workflows to support autonomous detection and remediation — a forward-looking capability that sets Mandiant apart in the global cybersecurity landscape. Collaboration is central to this position: you’ll work alongside internal teams, executive leadership, legal counsel, and client stakeholders, communicating complex findings clearly to both technical and non-technical audiences.
Benefits and Salary
This role offers a competitive compensation package. The salary range is $166,000 – $170,000 CAD annually, plus a 15% bonus target, equity, and a comprehensive benefits package. Google is well known for offering strong employee benefits — learn more on their official benefits page.
Job Details
📌 Job Type: Full-Time
🏢 Company: Google (Mandiant)
📍 Location: Ottawa, ON, Canada
📊 Level: Mid (Senior)
💰 Pay: $166,000 – $170,000 CAD/year + 15% bonus target + equity + benefits
Responsibilities
This role demands a hands-on practitioner who can operate in dynamic, high-stakes environments. From leading complex client investigations to building next-generation AI-powered security tools, your day-to-day responsibilities are as varied as they are critical. Here’s what you’ll be doing:
- Collaborate with internal and customer teams to detect, respond to, and contain cybersecurity incidents in real time
- Design and build agentic AI solutions to support autonomous detection, response, and remediation
- Recognize and codify attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) applicable to current and future investigations
- Lead and contribute to complex client-facing investigations, examining cloud, endpoint, and network-based evidence
- Develop and present comprehensive, accurate reports and presentations for both technical and executive audiences
- Perform forensic analysis, threat hunting, and malware triage within national security contexts
- Support crisis management as part of complete incident response cycles including investigation, containment, and remediation
Requirements / Skills
Mandiant is looking for a seasoned cybersecurity professional who combines deep technical expertise with strong communication skills and a proactive mindset. Given the national security context of this role, candidates must also meet specific security clearance requirements.
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent practical experience
- 5+ years of experience in SOC analysis, malware research, threat hunting, or similar roles using EDR and SIEM technologies
- Incident response leadership experience, with a track record of managing complex security events
- Personnel Security Clearance — candidates must hold or be eligible to obtain a valid clearance as a condition of employment
- Cloud platform certifications are considered a strong asset
- Agentic AI experience — demonstrable ability to build and deploy AI workflows supporting detection, response, and remediation
- Bilingualism (English and French) is preferred to work effectively with internal and client teams
- Strong communication skills to convey investigative findings to audiences ranging from technical staff to executive leadership and legal counsel
- Excellent time and project management skills, particularly in high-pressure, fast-moving environments
How to Apply
To apply, visit the official Google Careers posting using the link below. Ensure your resume is up to date and reflects your experience in incident response, threat detection, and any relevant security clearances before submitting.
Share This Opportunity
Know someone who might be interested? Share this job posting and help them join Google Mandiant in Ottawa.
Job Summary & Tips for Applying
Quick Summary & What to Highlight: This Senior Forward Deployed Detection and Response Consultant role at Google Mandiant in Ottawa is ideal for candidates who excel in incident response leadership, threat hunting, and SOC operations. On your resume, emphasize hands-on experience with EDR and SIEM platforms, any agentic AI or automation work in security contexts, and your ability to manage high-stakes investigations from detection through remediation. If you’ve previously worked in national security, defence, or government cybersecurity environments, make sure to highlight specific incidents managed and measurable outcomes achieved.
Resume & Application Tips: Before applying, tailor your resume to mirror the language in this posting. Include keywords like incident response, threat intelligence, malware analysis, TTPs, IOCs, and agentic AI. Quantify your achievements where possible — for example, “led response to 20+ high-severity incidents annually” or “reduced mean time to contain by 40%”. A concise cover letter noting your interest in Canada’s national security sector and your security clearance eligibility will strengthen your application. Verify your contact information and proofread carefully before submitting.
Interview Preparation: Research Google Mandiant‘s threat intelligence reports, recent high-profile breach investigations, and their public cybersecurity resources before your interview. Prepare STAR-method examples (Situation, Task, Action, Result) that demonstrate your experience in complex incident response, forensic analysis, and cross-functional communication. Be ready to discuss scenarios involving nation-state threats, cloud-based investigations, and executive-level briefings. Dress professionally, arrive 10–15 minutes early if in person, and bring copies of your resume. Prepare thoughtful questions about the team structure, current client challenges, and opportunities to grow within the national security practice. Send a thank-you email within 24 hours of your interview.