nesto

Cyber Defence Director

Canada full-time Executive Salary not listed
full-time Executive level Technology & IT Curated
Sign in to apply Free account — we bring you straight back to this role.

About the role

Join nesto — proudly named Canadian Rocketship 2025*. A Deloitte Fast 50 company evolving alongside Canada’s top tech innovators and disrupting a 2.1 Trillion-dollar mortgage industry at light speed by building the mortgage ecosystem of the future.

BUILD lending technology with the best developers, AI engineers, and mortgage experts in the country. Work on a modern tech stack and a development framework designed to unlock your full potential and accelerate your career.

Why join us

Hypergrowth: Deloitte Fast 50 — 3 years in a row

Tech community credibility: TechTO Canadian Rocketship 2025*

Industry leadership: CLA Lending Company of the Year — 4 consecutive years

Talent magnet: CMP Top Mortgage Employer 2025

Trusted technology: powering major financial institutions across Canada

An entrepreneurial culture built on trust, speed, uncomfortable ambition, being stronger together, and a relentless obsession with our clients.

About the role

We're looking for a cyber defence leader to lead our security operations team and continue to grow our cyber defence practice alongside it. This is a hands-on leadership role for someone who can build operational excellence in detection and response while also elevating our security program's maturity through proactive testing, risk management, and cross-functional collaboration.

Your day-to-day in that role :

Mentor, and develop a team of security professionals, defining career paths and skill development plans, and fostering a culture of excellence, curiosity, and continuous improvement.

Own the full incident response lifecycle: triage, scoping, containment, eradication, recovery, and post-incident improvement.

Act as senior technical and operational escalation point during high-severity incidents, partnering with Legal, Privacy, Fraud

Own detection engineering, converting incident observations into higher-fidelity detections, tuning opportunities, and response automation.

Own log source governance: telemetry coverage across our systems, periodic reviews as the environment and partners change, and log volume managed against detection value.

Keep detection and response at machine speed as nesto adopts AI, on both sides: our own cycle, and the agents themselves.

Drive continuous improvement of playbooks, enrichment, and orchestration that improve response speed and consistency.

Champion a purple team approach that combines offensive and defensive collaboration: attack surface analysis, threat modelling, and adversarial simulation to identify and close gaps, with threat hunting and operationalized threat intelligence feeding the work.

Own exposure and vulnerability management, prioritizing on asset criticality and exploitability, and driving remediation to closure with system owners.

Own the strategy, selection, deployment, and ongoing management of core security tooling including EDR and SIEM, keeping it tuned, integrated, and generating actionable intelligence for the team.

Serve as an active member of the risk management committee, translating business risk priorities into concrete defence strategies

What you bring

10+ years in cyber security, including people leadership in incident response, security operations, threat investigation, or digital forensics.

Track record building, leading, and maturing a security operations function, including standing up new capability.

Proven experience leading a security operations, blue team, or incident response function, ideally in a regulated or financial services environment.

Deep expertise in incident response, digital forensics, EDR and SIEM platforms, threat modeling, and attack surface management.

Experience selecting and managing SOC / MSSP providers, including contract negotiation and ongoing performance governance.

Experience with a purple team or adversarial testing methodologies.

Strong track record of engaging with executive stakeholders and contributing to enterprise risk management programs.

Excellent leadership, communication, and team-building skills.

Nice to have

Relevant certifications (such as GCIH, GCFA, OSCP, or CISSP) are an asset.

AI security literacy: both AI-enabled attacker behaviour and AI-accelerated defence workflows.

Experience managing an MSSP

Diversity and Inclusion

At nesto, we believe that creativity and collaboration are the result of a diverse team. We are committed to fostering a culture of diversity, equity, inclusion, and belonging, and we strongly encourage women, people of color, LGBTQIA+ individuals, and individuals with disabilities to apply. We are committed to creating a workplace that is inclusive and welcoming to all.

#nestoposition

#nestocloud

Originally posted on Himalayas

Interview prep

Walk in with sharper answers.

Use this as a quick practice sheet before you speak with the employer.

Executive
Technology & IT Operations Cyber Defence Director Technology Executive level

Likely questions

  1. Tell us about work you have done that is close to the Cyber Defence Director role.
  2. How would you approach your first 30 days at nesto?
  3. Which of Operations, Cyber and Defence have you used recently, and what did it help you achieve?
  4. How have you led people, improved a process, or made a hard decision in a previous role?
  5. How do you handle busy days, changing priorities, or pressure at work?

Prepare before the call

  • A recent example that proves your experience with Operations, Cyber and Defence.
  • One short story with a problem, your action, and the result.
  • Two examples that show the strengths listed on your CV.
  • A clear reason why this role and company interest you.
  • Your availability, preferred work style, and salary expectations.

Ask them

  • What would success look like in the first 90 days?
  • What are the main problems this hire should help solve?
  • How does the team give feedback and measure good work?
  • What does a normal working week look like for this role?
Practice line

I am interested in the Cyber Defence Director role because I can bring practical experience in Operations, Cyber and Defence, learn the team quickly, and contribute to the outcomes nesto needs from this hire.

Related jobs.

More roles from this company or category.