Principal Consultant, Adversarial Resilience and Cyber Defence
As a Principal Consultant, Adversarial Resilience and Cyber Defence within Mandiant's National Security team, you will embed with clients in Canada's national security and defence sector and directly contribute to building a secure and resilient Canada.
In this role, you will operate at the intersection of adversarial tradecraft and resilient engineering, delivering a unified hybrid capability across cyber defence, security engineering, detection and response, validation testing, and offensive security services. You will design robust defensive architectures and engineer high-fidelity detection and response pipelines. Leveraging offensive tradecraft and security validation testing, you will simulate sophisticated threat actors to stress-test controls, uncover systemic exposures, and quantify defensive efficacy. By bridging direct defence engineering with proactive offensive validation, you will directly contribute to the design, hardening, and resilience of networks critical to national security and defence.
Part of Google Cloud, Mandiant is a recognized leader in dynamic cyber defence, threat intelligence and incident response services. Mandiant's cybersecurity expertise has earned the trust of security professionals and company executives around the world. Our unique combination of renowned frontline experience responding to some of the most complex breaches, nation-state grade threat intelligence, machine intelligence, and the industry's best security validation ensures that Mandiant knows more about today's advanced threats than anyone.
Canada: $198000 - $202000 (CAD) + 20% bonus target + equity + benefits
Learn more about benefits at Google.
Responsibilities
- Lead multi-disciplinary engagements across cyber defence, security engineering, detection and response, and offensive security for Canadian national security and defence clients.
- Execute adversary emulation and security validation testing, simulating advanced tradecraft and threat actor techniques to stress-test defensive controls, expose systemic weaknesses, and quantify mitigation efficacy.
- Design and engineer robust defensive architectures and automated detection and response pipelines across sovereign, cloud, and on-premises mission-critical environments.
- Serve as a trusted advisor to client executives and operational commanders, translating offensive findings, defensive metrics, and cyber threat intelligence into actionable resilience strategies and risk-reduction roadmaps.
- Develop custom tooling, automation, and purple-teaming playbooks using modern scripting, agentic frameworks, and Mandiant telemetry to scale detection engineering and validation testing capabilities.
Minimum qualifications:
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, related technical field, or equivalent practical experience.
- 8 years of experience in SOC analyst, malware research, threat hunting, or similar roles, working with EDR and SIEM technologies.
- Experience leading incident response activities and working with executive stakeholders.
- Candidates must hold or be eligible to obtain a valid Personnel Security Clearance as a condition of employment.
Preferred qualifications:
- Certifications in offensive security, security engineering, cyber defence, or cloud platforms.
- Demonstrable experience building and deploying agentic AI workflows to support detection, response, and remediation.
- Experience in security competitions, Capture the Flags (CTFs) or testing platforms such as Hack the Box, TryHackMe, Overthewire, etc.
- Ability to communicate technical findings and strategies to technical staff, executive leadership, legal counsel, and internal and external clients.
- Ability to communicate in English and French fluently, to work with internal partners and customer teams.
- Excellent time and project management skills.