Senior Incident Response Security Consultant – Google (Mandiant) – Remote, Canada
Mandiant, part of Google Cloud, is looking for a Senior Incident Response Security Consultant to join its world-class cybersecurity team. This is a fully remote role open to candidates based in Ontario, Alberta, British Columbia, or New Brunswick. If you’re drawn to investigating complex, high-profile breaches and want to work alongside some of the sharpest minds in cyber defence, this position puts you at the centre of the action.
Day to day, you’ll be leading and contributing to incident response investigations for organizations navigating serious security events — from forensic analysis and threat hunting to malware triage and containment. You’ll work directly with both internal Google teams and client stakeholders, translating technical findings into clear, actionable intelligence for audiences ranging from security engineers to C-suite executives.
About the Role: Senior Incident Response Security Consultant
As part of Mandiant’s customer-focused Computer Incident Response team, you’ll be deployed on engagements that require a high degree of technical precision and composure under pressure. Your work will span cloud forensics, network forensics, disk and memory analysis, and malware triage — helping clients investigate, contain, and recover from some of the most technically complex incidents in the industry. Recognizing and codifying attacker Tools, Tactics, and Procedures (TTPs) and Indicators of Compromise (IOCs) will be a key part of how you contribute to both active and future investigations.
You’ll also be responsible for developing and delivering comprehensive reports and presentations tailored to both technical teams and executive leadership. Collaboration is at the heart of this role — you’ll partner closely with client teams, legal counsel, and internal Mandiant and Google Cloud specialists. Some travel (up to 30%) is expected as part of certain engagements.
Benefits and Salary
This role offers a competitive compensation package. The salary range for Canada is $166,000 – $170,000 CAD, with a 15% bonus target, equity, and a comprehensive benefits package through Google. For a full breakdown of what Google offers its employees, visit the Google benefits page.
Job Details
🏢 Company: Google (Mandiant, Google Cloud)
📍 Location: Remote — Ontario, Alberta, British Columbia, or New Brunswick, Canada
💻 Work Type: Remote eligible
📊 Level: Mid / Senior
💰 Pay: $166,000 – $170,000 CAD + 15% bonus target + equity + benefits
Responsibilities
In this role, you’ll be on the front lines of some of the most complex and consequential cybersecurity incidents organizations face today. Your responsibilities will require both deep technical expertise and the ability to communicate clearly with a wide range of stakeholders — from IT security teams to executive leadership and legal counsel.
- Investigate and contain security incidents in collaboration with internal Google/Mandiant teams and client organizations
- Recognize and codify attacker TTPs and Indicators of Compromise (IOCs) applicable to current and future investigations
- Lead complex engagements examining cloud, endpoint, and network-based sources of evidence
- Conduct forensic analysis across network forensics, malware triage, cloud forensics, and disk and memory forensics
- Perform threat hunting to proactively identify attacker presence within client environments
- Develop and present comprehensive, accurate reports and briefings tailored to both technical and executive audiences
- Provide crisis management support throughout the full incident lifecycle — investigation, containment, remediation, and recovery
Requirements / Skills
Mandiant is looking for a seasoned security professional who thrives under pressure and brings deep investigative experience to high-stakes situations. The ideal candidate combines strong technical foundations in digital forensics and incident response (DFIR) with the communication skills to guide clients through complex, high-profile events.
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, a related technical field, or equivalent practical experience
- 5+ years of end-to-end incident response experience, including investigation, analysis, and containment actions
- 5+ years of investigative experience in network forensics, malware triage, cloud forensics, or disk and memory forensics
- Willingness to travel up to 30% as required by client engagements
- Cloud platform certifications are considered an asset (preferred)
- Security competition experience (CTFs, Hack the Box, TryHackMe, etc.) is a plus
- Bilingual English/French proficiency is preferred for working with internal partners and client teams across Canada
- Strong time and project management skills to handle multiple complex engagements simultaneously
How to Apply
To apply, visit the official Google Careers posting using the link below. Make sure your resume is up to date and reflects your relevant incident response and forensics experience before submitting.
Share This Opportunity
Know someone who might be interested? Share this job posting and help them join Google (Mandiant) in this remote role across Canada.
Job Summary & Tips for Applying
Quick Summary & What to Highlight: This Senior Incident Response Security Consultant role at Google (Mandiant) in a remote capacity across Canada is ideal for candidates with deep expertise in digital forensics, incident response, and malware triage. On your resume, emphasize your end-to-end IR experience, any cloud forensics work, and your ability to operate effectively in high-pressure, client-facing environments. If you’ve led investigations involving nation-state actors, ransomware, or advanced persistent threats, highlight those engagements with specific context about your role and the outcomes achieved.
Resume & Application Tips: Before applying, tailor your resume to align with the job description. Incorporate keywords like incident response, threat hunting, network forensics, cloud forensics, and TTPs/IOCs throughout your application materials. Where possible, quantify your impact — for example, “led 20+ IR engagements annually” or “reduced mean time to containment by X%”. A brief cover letter that speaks to your experience with complex, high-profile investigations and your interest in working within the Mandiant/Google Cloud ecosystem will strengthen your application in Canada.
Interview Preparation: Research Google‘s values and Mandiant’s position in the cybersecurity landscape — including their threat intelligence reports, M-Trends, and notable breach investigations. Prepare STAR-method examples that demonstrate your ability to manage complex incident investigations, communicate findings to executive stakeholders, and coordinate containment across multi-disciplinary teams. You may be asked about specific forensic methodologies, cloud environments you’ve worked in, or how you approach malware triage under time constraints. Arrive (virtually) prepared, have copies of your resume ready, and send a follow-up thank-you note within 24 hours of your interview.