Computer Security Incident Response Team Analyst Various Roles and Levels

Communications Security Establishment Canada
Communications Security Establishment Canada

IT

Posted on Aug 5, 2026

Reference number: RF-16804

About CSE

The Communications Security Establishment (CSE) is Canada’s agency responsible for foreign signals intelligence, cyber operations and cyber security. Learn more about our mission, and what it means to work in a security and intelligence field.

CSE is committed to fostering a culture of equity, diversity and inclusion. This isn’t just an ideal, it’s crucial to our mission. Find out about our workplace culture, including our diversity and inclusion initiatives.

Become part of our team and you’ll understand why CSE is the most important organization you’ve never heard of (YouTube).

Job summary

CSE is currently looking to fulfill various roles within a Computer Security Incident Response Team (CSIRT). As a CSIRT Analyst, you’ll work in partnership with many cyber defender communities. You’ll use your skills and apply your knowledge to guard and protect critical Government of Canada systems as well as provide advice, guidance, and services to organizations within Canada’s Critical Infrastructure sectors.

This selection process will be used to fill a variety of positions within the CSIRT. These positions include:

  • Incident Handler: You will identify, assess, investigate and manage cyber incidents by providing technical advice, threat intelligence and recovery support in close partnerships with internal and external stakeholders.
  • Digital Forensics and Incident Responder: You will analyze digital evidence and investigate computer security incidents to derive useful information in support of system/network vulnerability mitigation.
  • Vulnerability Analyst: You will synthesize data from technical scans and intelligence sources to prioritize critical vulnerabilities and produce public advisories that support mitigation across Canada.
  • Cyber Threat Analyst: You will analyze multi-source intelligence to identify emerging cyber threats, produce actionable threat assessments, and continuously evaluate outcomes to enhance national cybersecurity.
  • Cyber Threat Intelligence Analyst: You will collect data and analyze trends to perform proactive threat discovery. You’ll also share cyber threat intelligence to internal and external organizations through engagement channels and automation.
  • Cyber Defenders and Community Engagement Analyst: You will lead key engagements with external stakeholders on cyber threat information and recommendations to ensure the partner’s cyber resilience.

In the application form, you will be asked to select which positions you would like to be considered for. You will be matched to a position based on a combination of your interests and our organizational needs.

Salary

To find out more about our salary scale, vacation allowances and benefits (health, dental and pension plans, etc.) visit the Compensation page on our website.

Area of selection

Open to Canadian citizens.

Location

The majority of our jobs are in Ottawa, Ontario. CSE has two accessible facilities. Flexible work arrangements, including telework for a portion of the work week, may be possible.

Conditions of employment

A valid Enhanced Top Secret (ETS) security clearance is a condition of employment that must be met before an offer can be made.

More information about our hiring and security processes can be found on our website.

Essential qualifications

In order to be considered, your cover letter must clearly explain how you meet the following education and experience requirements.

Education

You must have either one of the following:

  • A university degree in a field related to the position, such as (but not limited to) computer science, information technology; or
  • A combination of experience and education (college diploma) in a field related to the position (as above).

Note: The educational program must be recognized in Canada, and you must be able to provide proof of education credentials. Students graduating within the next twelve months are eligible to apply.

Experience

Recent experience in at least one of the following Information technology (IT) practices:

  • IT security technology
  • Application security
  • Network security
  • IT security architecture and design
  • Cyber security analysis
  • IT system development and/or maintenance
  • IT Security incident handling
  • IT system vulnerability assessment
  • System Administration and Cloud
  • Digital Forensics and Incident Response
  • Software development
  • Data analysis

Note: For the purposes of this hiring process, “recent” is defined as experience having normally been acquired within the last five years.

Official language requirements

English essential or bilingual imperative: Language profile: BBB

  • English essential means that the position is unilingual English.
  • Bilingual means that knowledge of both official languages (English and French) is required for the position.
    • Imperative means that you must possess the knowledge of both official languages before a job offer can be made.
  • The profile (e.g. CBC/CBC) represent the proficiency level you must demonstrate in each of the language skills (reading, writing and oral interaction) for the bilingual position. For bilingual positions, second language evaluations will be offered to candidates who don’t have valid language test results issued by the Government of Canada.

Find out more about the language requirements of positions.

Competencies

The following technical, behavioural and leadership competencies will be assessed at a later date. You do not need to include information about them in your application.

Technical competencies

  • Knowledge of IT
  • Cyber security
  • Knowledge of malicious internet activity

Behavioural competencies

  • Cognitive thinking skills
  • Interactive communication

Leadership competencies

  • Collaboration
  • Change and innovation
  • Achieving results

Assets

Assets are “nice-to-have” expertise and skills we’re interested in. They may be used to identify which team you could best complement, or they may be invoked as a volume management strategy.

Please demonstrate on your application if you meet or possess the asset experience listed below.

Asset experience

  • Experience in cloud technologies
  • Experience in scripting or automation
  • Experience in python development
  • Experience in data processing and analysis
  • Experience in malware reverse engineering
  • Experience in detection engineering.
  • Experience in a Government of Canada cyber security role
  • Experience engaging with international partners in the realm of cyber security

Asset competencies

The following asset technical, behavioural and leadership competencies may be assessed at a later date. You do not need to include information about them in your application.

Asset technical competencies

  • Cyber Forensic Analysis
  • Application Development
  • Network Analysis

Operational requirements

Overtime and standby duty may be required.

How to apply

You may submit your candidacy online by selecting “Apply” at the top or bottom of this page.

If you cannot apply online or have a disability preventing you from applying online, please inform us by email at careers-carrieres@cse-cst.gc.ca prior to the closing date of this hiring process.

Important information

Assessments of candidates are conducted in the official language of their choice.

We ask you to not discuss your application with others (including on social media) besides your partner, or close family members - who should also be reminded about the need to be discreet.

To address CSE’s current representation gaps, priority may be given to persons who self-declare as belonging to one, or more, designated employment equity groups: women; Indigenous peoples, including First Nations who are status, or registered and non-status, or non-registered, Inuit and Métis; persons with disabilities, including people with a mental health condition and neurodivergent people; and persons from racial or ethnic groups.

Please note the Employment Equity Act, which is under review, uses the terminology Aboriginal peoples and visible minorities.

CSE offers an assessment process that will accommodate any reasonable measures you require to be assessed in a fair and equitable manner. Those measures are available to all candidates during our processes. Information you provide will be addressed confidentially.

The level of competence demonstrated in the various assessments will be used to determine your qualifications for the UNMA-07, UNMA-08, or UNMA-09 levels.

All communications with CSE relating to this process, including email messages and telephone conversations, may be used in the assessment of qualifications.

The intent of this process is to fill vacant positions at CSE. The process may also be used to establish a pool of qualified candidates which could be used to staff similar or identical positions with various tenures.

Due to the nature of CSE’s mandate certain roles may expose employees to content that is difficult to process. Mental health is a priority at CSE and if any personnel feel they require assistance to preserve their mental wellbeing, they have access to services, tools and other resources to help them in both their personal and professional lives.

Please note that in an effort to maintain balance between employee development and business needs, candidates who are hired at CSE must remain in their substantive position for a minimum of twelve (12) months subject to operational requirements.

We thank you for your interest in CSE. However, only those selected for further consideration will be contacted.