Back to job search
AD
act digitalVerified Job Source

Cybersecurity Detection Engineer / Purple Team

Develop and validate cybersecurity detection capabilities using behavioral analytics and offensive testing. Collaborate with SOC and Incident Response teams to reduce false positives and close detection gaps across various environments.

  • On-site
  • Montréal, QC
  • Posted Jul 28, 2026
  • Apply by Aug 27, 2026
  • 1 position

More jobs you can apply to directly

Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.

Job summary

About the Company Act Digital is an international technology and cybersecurity consulting company supporting major organizations across digital transformation, cyber defense and security operations. Within our cybersecurity activities, we support large enterprise and financial-sector clients on topics including: Detection engineering SOC operations Incident response Offensive security Purple teaming Threat-driven defense improvement We are currently looking for a Detection Engineer to join a major financial-sector environment in Montreal. About the Role As a Detection Engineer, you will help improve and validate cybersecurity detection capabilities against modern attacker techniques. This role combines detection engineering, purple teaming and offensive validation activities. The objective is not only to create detections, but also to continuously test and improve their effectiveness against realistic attack scenarios. You will work closely with SOC, Incident Response and Security Engineering teams to strengthen detection coverage and defensive maturity across the environment. Main responsibilities include: Reviewing and improving existing detection use cases Developing new detection logic and behavioral analytics Validating detections through offensive testing and adversary simulation Identifying detection gaps across endpoint, identity, network and cloud environments Simulating attacker techniques mapped to MITRE ATT&CK Improving detection quality and reducing false positives Supporting continuous improvement of monitoring and response capabilities Qualifications 3+ years of experience in cybersecurity Experience in Detection Engineering, Threat Detection, SOC or Purple Teaming Hands-on experience with offensive security techniques or adversary simulation Experience working in enterprise or regulated environments Strong understanding of modern attack techniques and intrusion methodologies Required Skills SIEM and EDR technologies Detection use case development and tuning MITRE ATT&CK framework Log analysis and event correlation Threat detection methodologies Offensive security fundamentals Scripting skills (Python, PowerShell and/or Bash) Windows security and Active Directory knowledge Strong analytical and investigation capabilities Preferred Skills Experience in financial or highly regulated environments Experience with purple teaming or adversary simulation Experience with detection-as-code methodologies Knowledge of threat hunting methodologies Familiarity with Windows internals, Active Directory and cloud environments Knowledge of modern attack chains, lateral movement and privilege escalation techniques

What you’ll do

Develop and validate cybersecurity detection capabilities using behavioral analytics and offensive testing. Collaborate with SOC and Incident Response teams to reduce false positives and close detection gaps across various environments.

Requirements

Requires over 3 years of experience in cybersecurity with a focus on detection engineering or purple teaming. Candidates must be proficient in SIEM/EDR technologies, scripting, and modern attack methodologies.

Other relevant skills

Identified from the job description. Confirm important requirements above.

  • SIEM
  • EDR
  • Detection Use Case Development
  • MITRE ATT&CK
  • Log Analysis
  • Event Correlation
  • Offensive Security
  • Python
  • PowerShell
  • Bash
  • Windows Security
  • Active Directory
  • Purple Teaming
  • Adversary Simulation
  • Threat Hunting
  • Detection-as-Code

Job areas

  • Security & Safety
  • Technology
  • Consulting
  • Software
  • Engineering

Additional details

Minimum experience
3+ years
Apply by
Aug 27, 2026
Posting language
English
Working hours
40 hours per week
Seniority
Associate
Application method
Direct apply is available