Search
Header navigation
Sr Specialist, Adversary Detection,Cyber Threat Intelligence & Threat Hunting

Sr Specialist, Adversary Detection,Cyber Threat Intelligence & Threat Hunting

locationCanada
PublishedPublished: 8/13/2026
Automation & Technology Roles
Ready to build a rewarding career in an industry that is growing?

Who We Are
We are a global mining company dedicated to safely delivering nickel, copper, cobalt, and platinum group metals essential for the world's energy transition.

Our mission is to improve lives and shape a better future together.

From utensils to cellphones to satellites, our operations simplify daily life and enhance connectivity. Our metals are integral to life-saving medical equipment and the electric vehicles driving the fight against climate change - our work truly matters.

Join our diverse team of 15,000 talented individuals committed to transforming critical minerals into prosperity and sustainable development in countries like Canada, Brazil, Indonesia, the United Kingdom, and Japan. We invite you to use your skills with us and contribute to something meaningful and enduring.

The Opportunity

We are currently seeking a Sr. Specialist, Adversary Detection, Cyber Threat Intelligence & Threat Hunting Lead to join our Cyber Defense & Incident Response team in Toronto, Ontario.

Combining expertise in Adversary Detection, Cyber Threat Intelligence, and Threat Hunting, you will transform intelligence into proactive security controls and advanced detection capabilities. Working across corporate IT, cloud environments, identities, endpoints, applications, and operational technology environments, will help strengthen cyber resilience across our global operations.

Reporting to the Senior Manager, Cyber Defense & Incident Response, this role serves as the technical cornerstone of our Cyber Defense program. You will be responsible for ensuring our organization can identify, detect, and respond to adversarial activity before it impacts business operations.

Key Responsibilities



Adversary Detection
  • Develop, test, and deploy advanced detection content mapped to MITRE ATT&CK techniques relevant to mining and critical infrastructure threats.
  • Continuously tune and optimize detection logic to improve effectiveness and reduce false positives.
  • Build and maintain a comprehensive detection catalog, including ATT&CK mappings, data sources, confidence levels, and review cycles.
  • Collaborate with Security Operations teams to design and improve investigation playbooks and response procedures.
  • Review managed detection and response (MDR) provider outputs, identify coverage gaps, and drive improvements in detection quality and performance.
  • Establish and maintain detection engineering standards, documentation, testing methodologies, and operational processes.







Cyber Threat Intelligence
  • Consume, analyze, and operationalize threat intelligence from industry, government, commercial, and open-source sources.
  • Produce regular threat intelligence reporting highlighting emerging threats, adversary activity, exploited vulnerabilities, and recommended defensive actions.
  • Maintain detailed adversary profiles focused on actors targeting mining, critical infrastructure, energy, and global industrial organizations.
  • Translate intelligence findings into actionable detections, threat hunts, risk advisories, and executive briefings.
  • Manage and optimize threat intelligence feeds integrated with security monitoring and XDR platforms.



Threat Hunting
  • Design and execute hypothesis-driven threat hunting campaigns using frameworks such as MITRE ATT&CK and the Diamond Model.
  • Identify malicious behaviors and attack techniques that may not be detected through automated controls.
  • Develop new detection logic and analytical techniques based on hunting results.
  • Partner with MDR providers and internal stakeholders on collaborative hunting initiatives and security investigations.
  • Maintain comprehensive hunting documentation, findings, lessons learned, and recommendations.



Technical Leadership & Governance
  • Act as the primary technical liaison for the MDR provider's detection and threat hunting capabilities.
  • Participate in operational reviews focused on detection coverage, false positive reduction, hunt outcomes, and emerging threats.
  • Maintain and prioritize detection enhancement roadmaps and coverage gap remediation plans.
  • Contribute to the ongoing maturity and effectiveness of the Cyber Defense program.
  • Promote best practices, continuous improvement, and knowledge sharing across cybersecurity teams.



About You

Experience
  • Minimum 8 years of cybersecurity experience with significant expertise in one or more of the following domains:
  • Adversary Detection
  • Threat Hunting
  • Cyber Threat Intelligence
  • Security Operations
  • Experience supporting enterprise or critical infrastructure environments.
  • Proven hands-on experience developing SIEM, XDR, EDR, or detection content.
  • Experience operationalizing cyber threat intelligence and converting intelligence into defensive actions.
  • Demonstrated experience conducting structured, hypothesis-driven threat hunting activities.
  • Experience working with managed detection and response providers and security operations teams.




Education
  • Undergraduate degree in Cybersecurity, Computer Science, Information Technology, Engineering, or related discipline.





Skills & Competencies

  • Strong knowledge of MITRE ATT&CK, adversary emulation, threat modeling, and detection engineering.
  • Experience with Cortex XDR, Microsoft Sentinel, Splunk, or equivalent security platforms.
  • Understanding modern attack techniques targeting cloud, identity, endpoint, and enterprise environments.
  • Ability to analyze threat intelligence from structured and unstructured sources.
  • Strong analytical and investigative skills with a proactive, hypothesis-driven mindset.
  • Excellent written and verbal communication skills.
  • Ability to communicate technical findings effectively to both technical and business audiences.
  • Highly organized with strong documentation and reporting discipline.



Preferred Qualifications
  • GIAC certifications such as GCTI, GDAT, GCIA, or GCIH.
  • Palo Alto Networks XDR or XSIAM certifications.
  • FOR578 Cyber Threat Intelligence training or equivalent.
  • Experience in mining, energy, utilities, manufacturing, or other critical infrastructure sectors.
  • Familiarity with OT/ICS cybersecurity environments.
  • Experience with Python, PowerShell, XSOAR/XSIAM automation, OpenCTI, MISP, or similar platforms.



What We Offer You
  • Competitive compensation including a variable annual incentive plan
  • Participation in a competitive Defined Contribution Pension package
  • Comprehensive benefits package (company paid core coverage, health and dental coverage, flex accounts, disability plans, and optional insurances)
  • Leave for all of life's reasons (vacation, personal, sick, parental)
  • Work culture dedicated to safety, diversity & inclusion, and career growth
  • Employee Family Assistance Program
  • Virtual Healthcare online
  • Online training and career development opportunities


Why Toronto
Vale's Toronto office, nestled in the heart of Canada's largest city, serves as a pivotal hub for the company's operations. This office is central to Vale's finance, strategic planning, commercial (marketing and sales), and sustainability teams, driving key initiatives that support the company's global mission. Toronto's vibrant, diverse, and dynamic environment enhances Vale's ability to innovate and excel in these critical areas, reflecting the city's status as a leading international business center.

Include to Transform
At Vale Base Metals, we are committed to ensuring an inclusive work environment where people feel comfortable to be themselves. Vale encourages everyone to express their ideas and opinions and values the plurality of individual profiles. We want our people to feel that all voices are heard, all cultures respected and that a variety of perspectives are not only welcome - they are critical to our success. We treat each other fairly and with dignity regardless of race, gender, nationality, ethnic origin, religion, age, sexual orientation, or any other personal consideration that makes us different.

Vale is an equal opportunity employer seeking to increase diversity across our operations and improve equal opportunity at Vale and in the mining industry.

In accordance with the Accessibility for Ontarians with Disabilities Act, accommodation is available throughout our recruitment process for applicants with disabilities.

#ValeBaseMetals

Image gallery

Video gallery

Consent to this service

Targeting

Consent to this service

Targeting